Welcome to Tech Support Forum home to more then 136,000 problems solved. Issues have included: Spyware, Malware, Virus Issues, Windows, Microsoft, Linux, Networking, Security, Hardware, and Gaming Getting your problem solved is as easy as:
1. Registering for a free account
2. Asking your question
3. Receiving an answer

Registered members:
* Get free support
* Communicate privately with other members (PM).
* Removal of this message
* See fewer ads.
* And much more..

 



Want to know how to post a question? click here Having problems with spyware and pop-ups? First Steps
Go Back   Tech Support Forum > Security Center > Virus/Trojan/Spyware Help > HijackThis Log Help (Inactive)
User Name
Password
Site Map Register Donate Rules Blogs Mark Forums Read


 
 
LinkBack Thread Tools
Old 08-26-2008, 03:50 AM   #1 (permalink)
Registered User
 
Join Date: May 2008
Posts: 25
OS: Windows Vista Service Pack 1


Bagle.gen infection (I think?)

Came back from holiday switched on the pc and began having internittant problems. It crashed after five minutes surfing the web, just switched itself off. It did this three times, ran ok for 10 minutes or so then just switched off with a blue screen saying windows was closing to save the computer from serious damage (words to that effect) I noticed after this that my windows defender was no longer updating as it should I ran a panda scan and it showed some virus exists (Panda Log attached) My Pc appears to be running ok right now......but it obviously has something going on that is sinister......Hopefully a tech here can check it out for me and let me know what the problem could be and direct me how to fix it, if possible. Thanks in advance.

HijackThis Log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:34, on 2008-08-26
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Lexmark 4300 Series\lxcemon.exe
C:\Program Files\Lexmark 4300 Series\ezprint.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Yahoo!\YOP\yop.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\BillP Studios\WinPatrol\WinPatrol.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\dvd43\DVD43_Tray.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\eMule\emule.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\System32\mobsync.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\PROGRA~1\Yahoo!\YOP\SSDK02.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.realdealmafia.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [LXCECATS] rundll32 C:\Windows\system32\spool\DRIVERS\W32X86\3\LXCEtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [lxcemon.exe] "C:\Program Files\Lexmark 4300 Series\lxcemon.exe"
O4 - HKLM\..\Run: [EzPrint] "C:\Program Files\Lexmark 4300 Series\ezprint.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [BTHelena_McciTrayApp] C:\Program Files\BBDesktopHelpUpgradeAdvisor\McciTrayApp.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [YOP] C:\PROGRA~1\Yahoo!\YOP\yop.exe /autostart
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe -expressboot
O4 - HKLM\..\Run: [Skytel] Skytel.exe
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [dvd43] C:\Program Files\dvd43\dvd43_tray.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [eMuleAutoStart] C:\Program Files\eMule\emule.exe -AutoStart
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &ieSpell Options - res://C:\Program Files\ieSpell\iespell.dll/SPELLOPTION.HTM
O8 - Extra context menu item: Check &Spelling - res://C:\Program Files\ieSpell\iespell.dll/SPELLCHECK.HTM
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Lookup on Merriam Webster - file://C:\Program Files\ieSpell\Merriam Webster.HTM
O8 - Extra context menu item: Lookup on Wikipedia - file://C:\Program Files\ieSpell\wikipedia.HTM
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~3.0_0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~3.0_0\bin\ssv.dll
O9 - Extra button: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra 'Tools' menuitem: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra button: (no name) - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra 'Tools' menuitem: ieSpell Options - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: SmartWhois - {FD9DE2B4-C926-4460-81C4-FC58C6F1062E} - C:\PROGRA~1\SMARTW~1\swmsiehlp.exe
O9 - Extra button: (no name) - {FF983118-58C7-4AD4-B5A7-691C39CB7B42} - C:\PROGRA~1\SMARTW~1\swmsiehlp.exe
O9 - Extra 'Tools' menuitem: SmartWhois - {FF983118-58C7-4AD4-B5A7-691C39CB7B42} - C:\PROGRA~1\SMARTW~1\swmsiehlp.exe
O13 - Gopher Prefix:
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://appldnld.apple.com.edgesuite....x/qtplugin.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/par...an_unicode.cab
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/actives.../as2stubie.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {3860DD98-0549-4D50-AA72-5D17D200EE10} (Windows Live OneCare safety scanner control) - http://cdn.scan.onecare.live.com/res.../wlscctrl2.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/reso...PUplden-gb.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {71057C18-0507-4747-86BC-E11CE7512C5F} (mailhelper Class) - https://register.btinternet.com/temp...control013.cab
O16 - DPF: {EC5A4E7B-02EB-451D-B310-D5F2E0A4D8C3} (webhelper Class) - https://register.btinternet.com/temp...control028.cab
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktopManager.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\PROGRA~1\Symantec\isPwdSvc.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: lxce_device - - C:\Windows\system32\lxcecoms.exe
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: X10 Device Network Service (x10nets) - X10 - C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe

--
End of file - 13168 bytes

=========================

Panda Scan Log

;***********************************************************************************************************************************************************************************
ANALYSIS: 2008-08-26 09:51:00
PROTECTIONS: 1
MALWARE: 48
SUSPECTS: 0
;***********************************************************************************************************************************************************************************
PROTECTIONS
Description Version Active Updated
;===================================================================================================================================================================================
Windows Defender 1.1.3807.0 No No
;===================================================================================================================================================================================
MALWARE
Id Description Type Active Severity Disinfectable Disinfected Location
;===================================================================================================================================================================================
00034347 dialer.su Dialers No 0 Yes No hkey_local_machine\software\microsoft\windows\currentversion\uninstall\switch
00055522 Eicar.Mod Virus No 0 No No C:\Windows\System32\config\systemprofile\AppData\Local\Temp\Av-test.txt
00139060 Cookie/Casalemedia TrackingCookie No 0 Yes No C:\Users\Kenny\AppData\Roaming\Microsoft\Windows\Cookies\Low\kenny@casalemedia[1].txt
00139061 Cookie/Doubleclick TrackingCookie No 0 Yes No C:\Users\Kenny\AppData\Roaming\Microsoft\Windows\Cookies\Low\kenny@doubleclick[1].txt
00139064 Cookie/Atlas DMT TrackingCookie No 0 Yes No C:\Users\Kenny\AppData\Roaming\Microsoft\Windows\Cookies\Low\kenny@atdmt[2].txt
00145405 Cookie/RealMedia TrackingCookie No 0 Yes No C:\Users\Kenny\AppData\Roaming\Microsoft\Windows\Cookies\Low\kenny@247realmedia[2].txt
00145453 Cookie/Bfast TrackingCookie No 0 Yes No C:\Users\Kenny\AppData\Roaming\Microsoft\Windows\Cookies\Low\kenny@bfast[2].txt
00145457 Cookie/FastClick TrackingCookie No 0 Yes No C:\Users\Kenny\AppData\Roaming\Microsoft\Windows\Cookies\Low\kenny@fastclick[2].txt
00145731 Cookie/Tribalfusion TrackingCookie No 0 Yes No C:\Users\Kenny\AppData\Roaming\Microsoft\Windows\Cookies\Low\kenny@tribalfusion[1].txt
00145738 Cookie/Mediaplex TrackingCookie No 0 Yes No C:\Users\Kenny\AppData\Roaming\Microsoft\Windows\Cookies\Low\kenny@mediaplex[1].txt
00145881 Cookie/NewMedia TrackingCookie No 0 Yes No C:\Users\Kenny\AppData\Roaming\Microsoft\Windows\Cookies\Low\kenny@anm.co[1].txt
00147824 Cookie/Clickbank TrackingCookie No 0 Yes No C:\Users\Kenny\AppData\Roaming\Microsoft\Windows\Cookies\Low\kenny@clickbank[1].txt
00149104 Cookie/Date TrackingCookie No 0 Yes No C:\Users\Kenny\AppData\Roaming\Microsoft\Windows\Cookies\Low\kenny@date[2].txt
00159564 Cookie/WUpd TrackingCookie No 0 Yes No C:\Users\Kenny\AppData\Roaming\Microsoft\Windows\Cookies\Low\kenny@revenue[1].txt
00167642 Cookie/Com.com TrackingCookie No 0 Yes No C:\Users\Kenny\Documents\Firefox 2.0.0.7 (en-US) - 2007-10-14.pcv[cookies.txt][.com.com/]
00167642 Cookie/Com.com TrackingCookie No 0 Yes No C:\Users\Kenny\AppData\Roaming\Microsoft\Windows\Cookies\Low\kenny@com[1].txt
00167647 Cookie/Yadro TrackingCookie No 0 Yes No C:\Users\Kenny\AppData\Roaming\Microsoft\Windows\Cookies\Low\kenny@yadro[2].txt
00167704 Cookie/Xiti TrackingCookie No 0 Yes No C:\Users\Kenny\AppData\Roaming\Microsoft\Windows\Cookies\Low\kenny@xiti[1].txt
00167704 Cookie/Xiti TrackingCookie No 0 Yes No C:\Users\Kenny\Documents\Firefox 2.0.0.7 (en-US) - 2007-10-14.pcv[cookies.txt][.xiti.com/]
00167724 Cookie/HotLog TrackingCookie No 0 Yes No C:\Users\Kenny\AppData\Roaming\Microsoft\Windows\Cookies\Low\kenny@hotlog[1].txt
00167749 Cookie/Toplist TrackingCookie No 0 Yes No C:\Users\Kenny\AppData\Roaming\Microsoft\Windows\Cookies\Low\kenny@toplist[1].txt
00167753 Cookie/Statcounter TrackingCookie No 0 Yes No C:\Users\Kenny\Documents\Firefox 2.0.0.7 (en-US) - 2007-10-14.pcv[cookies.txt][.statcounter.com/]
00167753 Cookie/Statcounter TrackingCookie No 0 Yes No C:\Users\Kenny\Documents\Firefox 2.0.0.7 (en-US) - 2007-10-14.pcv[cookies.txt][.statcounter.com/]
00167753 Cookie/Statcounter TrackingCookie No 0 Yes No C:\Users\Kenny\Documents\Firefox 2.0.0.7 (en-US) - 2007-10-14.pcv[cookies.txt][.statcounter.com/]
00167753 Cookie/Statcounter TrackingCookie No 0 Yes No C:\Users\Kenny\Documents\Firefox 2.0.0.7 (en-US) - 2007-10-14.pcv[cookies.txt][.statcounter.com/]
00167753 Cookie/Statcounter TrackingCookie No 0 Yes No C:\Users\Kenny\Documents\Firefox 2.0.0.7 (en-US) - 2007-10-14.pcv[cookies.txt][.statcounter.com/]
00167753 Cookie/Statcounter TrackingCookie No 0 Yes No C:\Users\Kenny\Documents\Firefox 2.0.0.7 (en-US) - 2007-10-14.pcv[cookies.txt][.statcounter.com/]
00167753 Cookie/Statcounter TrackingCookie No 0 Yes No C:\Users\Kenny\Documents\Firefox 2.0.0.7 (en-US) - 2007-10-14.pcv[cookies.txt][.statcounter.com/]
00167753 Cookie/Statcounter TrackingCookie No 0 Yes No C:\Users\Kenny\Documents\Firefox 2.0.0.7 (en-US) - 2007-10-14.pcv[cookies.txt][.statcounter.com/]
00167753 Cookie/Statcounter TrackingCookie No 0 Yes No C:\Users\Kenny\Documents\Firefox 2.0.0.7 (en-US) - 2007-10-14.pcv[cookies.txt][.statcounter.com/]
00167753 Cookie/Statcounter TrackingCookie No 0 Yes No C:\Users\Kenny\Documents\Firefox 2.0.0.7 (en-US) - 2007-10-14.pcv[cookies.txt][.statcounter.com/]
00167753 Cookie/Statcounter TrackingCookie No 0 Yes No C:\Users\Kenny\Documents\Firefox 2.0.0.7 (en-US) - 2007-10-14.pcv[cookies.txt][.statcounter.com/]
00167753 Cookie/Statcounter TrackingCookie No 0 Yes No C:\Users\Kenny\Documents\Firefox 2.0.0.7 (en-US) - 2007-10-14.pcv[cookies.txt][.statcounter.com/]
00167753 Cookie/Statcounter TrackingCookie No 0 Yes No C:\Users\Kenny\AppData\Roaming\Microsoft\Windows\Cookies\Low\kenny@statcounter[2].txt
00167753 Cookie/Statcounter TrackingCookie No 0 Yes No C:\Users\Kenny\Documents\Firefox 2.0.0.7 (en-US) - 2007-10-14.pcv[cookies.txt][.statcounter.com/]
00167753 Cookie/Statcounter TrackingCookie No 0 Yes No C:\Users\Kenny\Documents\Firefox 2.0.0.7 (en-US) - 2007-10-14.pcv[cookies.txt][.statcounter.com/]
00167753 Cookie/Statcounter TrackingCookie No 0 Yes No C:\Users\Kenny\Documents\Firefox 2.0.0.7 (en-US) - 2007-10-14.pcv[cookies.txt][.statcounter.com/]
00167753 Cookie/Statcounter TrackingCookie No 0 Yes No C:\Users\Kenny\Documents\Firefox 2.0.0.7 (en-US) - 2007-10-14.pcv[cookies.txt][.statcounter.com/]
00167753 Cookie/Statcounter TrackingCookie No 0 Yes No C:\Users\Kenny\Documents\Firefox 2.0.0.7 (en-US) - 2007-10-14.pcv[cookies.txt][.statcounter.com/]
00167753 Cookie/Statcounter TrackingCookie No 0 Yes No C:\Users\Kenny\Documents\Firefox 2.0.0.7 (en-US) - 2007-10-14.pcv[cookies.txt][.statcounter.com/]
00168061 Cookie/Apmebf TrackingCookie No 0 Yes No C:\Users\Kenny\AppData\Roaming\Microsoft\Windows\Cookies\Low\kenny@apmebf[2].txt
00168076 Cookie/BurstNet TrackingCookie No 0 Yes No C:\Users\Kenny\Documents\Firefox 2.0.0.7 (en-US) - 2007-10-14.pcv[cookies.txt][.burstnet.com/]
00168076 Cookie/BurstNet TrackingCookie No 0 Yes No C:\Users\Kenny\AppData\Roaming\Microsoft\Windows\Cookies\Low\kenny@burstnet[1].txt
00168090 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Users\Kenny\AppData\Roaming\Microsoft\Windows\Cookies\Low\kenny@serving-sys[2].txt
00168093 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Users\Kenny\AppData\Roaming\Microsoft\Windows\Cookies\Low\kenny@bs.serving-sys[1].txt
00168097 Cookie/BurstBeacon TrackingCookie No 0 Yes No C:\Users\Kenny\AppData\Roaming\Microsoft\Windows\Cookies\Low\kenny@www.burstbeacon[2].txt
00168109 Cookie/Adtech TrackingCookie No 0 Yes No C:\Users\Kenny\AppData\Roaming\Microsoft\Windows\Cookies\Low\kenny@adtech[1].txt
00168110 Cookie/Server.iad.Liveperson TrackingCookie No 0 Yes No C:\Users\Kenny\Documents\Firefox 2.0.0.7 (en-US) - 2007-10-14.pcv[cookies.txt][server.iad.liveperson.net/hc/53476089]
00168110 Cookie/Server.iad.Liveperson TrackingCookie No 0 Yes No C:\Users\Kenny\Documents\Firefox 2.0.0.7 (en-US) - 2007-10-14.pcv[cookies.txt][server.iad.liveperson.net/]
00168110 Cookie/Server.iad.Liveperson TrackingCookie No 0 Yes No C:\Users\Kenny\AppData\Roaming\Microsoft\Windows\Cookies\Low\kenny@server.iad.liveperson[2].txt
00168113 Cookie/fe.lea.lycos TrackingCookie No 0 Yes No C:\Users\Kenny\Documents\Firefox 2.0.0.7 (en-US) - 2007-10-14.pcv[cookies.txt][fe.lea.lycos.de/]
00168114 Cookie/onestat.com TrackingCookie No 0 Yes No C:\Users\Kenny\AppData\Roaming\Microsoft\Windows\Cookies\Low\kenny@stat.onestat[1].txt
00169190 Cookie/Advertising TrackingCookie No 0 Yes No C:\Users\Kenny\AppData\Roaming\Microsoft\Windows\Cookies\Low\kenny@advertising[1].txt
00170495 Cookie/PointRoll TrackingCookie No 0 Yes No C:\Users\Kenny\AppData\Roaming\Microsoft\Windows\Cookies\Low\kenny@ads.pointroll[1].txt
00170550 Cookie/Humanclick TrackingCookie No 0 Yes No C:\Users\Kenny\Documents\Firefox 2.0.0.7 (en-US) - 2007-10-14.pcv[cookies.txt][hc2.humanclick.com/]
00170554 Cookie/Overture TrackingCookie No 0 Yes No C:\Users\Kenny\AppData\Roaming\Microsoft\Windows\Cookies\Low\kenny@overture[1].txt
00170556 Cookie/RealMedia TrackingCookie No 0 Yes No C:\Users\Kenny\Documents\Firefox 2.0.0.7 (en-US) - 2007-10-14.pcv[cookies.txt][.realmedia.com/]
00170556 Cookie/RealMedia TrackingCookie No 0 Yes No C:\Users\Kenny\Documents\Firefox 2.0.0.7 (en-US) - 2007-10-14.pcv[cookies.txt][.realmedia.com/]
00171633 Cookie/Cgi-bin TrackingCookie No 0 Yes No C:\Users\Kenny\AppData\Roaming\Microsoft\Windows\Cookies\Low\kenny@www5.addfreestats[2].txt
00172221 Cookie/Zedo TrackingCookie No 0 Yes No C:\Users\Kenny\AppData\Roaming\Microsoft\Windows\Cookies\Low\kenny@zedo[1].txt
00172221 Cookie/Zedo TrackingCookie No 0 Yes No C:\Users\Kenny\Documents\Firefox 2.0.0.7 (en-US) - 2007-10-14.pcv[cookies.txt][.zedo.com/]
00184846 Cookie/Adrevolver TrackingCookie No 0 Yes No C:\Users\Kenny\AppData\Roaming\Microsoft\Windows\Cookies\Low\kenny@adrevolver[2].txt
00187950 Cookie/bravenetA TrackingCookie No 0 Yes No C:\Users\Kenny\AppData\Roaming\Microsoft\Windows\Cookies\Low\kenny@bravenet[2].txt
00194327 Cookie/Go TrackingCookie No 0 Yes No C:\Users\Kenny\AppData\Roaming\Microsoft\Windows\Cookies\Low\kenny@go[2].txt
00194327 Cookie/Go TrackingCookie No 0 Yes No C:\Users\Kenny\Documents\Firefox 2.0.0.7 (en-US) - 2007-10-14.pcv[cookies.txt][.go.com/]
00199984 Cookie/Searchportal TrackingCookie No 0 Yes No C:\Users\Kenny\Documents\Firefox 2.0.0.7 (en-US) - 2007-10-14.pcv[cookies.txt][searchportal.information.com/]
00199984 Cookie/Searchportal TrackingCookie No 0 Yes No C:\Users\Kenny\AppData\Roaming\Microsoft\Windows\Cookies\Low\kenny@searchportal.information[2].txt
00249874 application/alfacleaner HackTools No 0 Yes No c:\users\kenny\appdata\roaming\skinux
00262020 Cookie/Atwola TrackingCookie No 0 Yes No C:\Users\Kenny\AppData\Roaming\Microsoft\Windows\Cookies\Low\kenny@atwola[2].txt
00273339 Cookie/Smartadserver TrackingCookie No 0 Yes No C:\Users\Kenny\AppData\Roaming\Microsoft\Windows\Cookies\Low\kenny@smartadserver[1].txt
00286732 Cookie/Cgi-bin TrackingCookie No 0 Yes No C:\Users\Kenny\AppData\Roaming\Microsoft\Windows\Cookies\Low\kenny@www3.addfreestats[1].txt
00286738 Cookie/Cgi-bin TrackingCookie No 0 Yes No C:\Users\Kenny\AppData\Roaming\Microsoft\Windows\Cookies\Low\kenny@www1.addfreestats[2].txt
00286739 Cookie/Hitbox TrackingCookie No 0 Yes No C:\Users\Kenny\AppData\Roaming\Microsoft\Windows\Cookies\Low\kenny@ehg-dig.hitbox[1].txt
01176994 Bck/VB.XB Virus/Trojan No 0 Yes No C:\Combo-Fix\NirCmdC.cfexe
01176994 Bck/VB.XB Virus/Trojan No 0 No No C:\Windows\System32\config\systemprofile\Desktop\Combo-Fix.exe[327882R2FWJFW\NirCmdC.cfexe]
01606636 Cookie/Adserver TrackingCookie No 0 Yes No C:\Users\Kenny\Documents\Firefox 2.0.0.7 (en-US) - 2007-10-14.pcv[cookies.txt][.adserver.easyad.info/]
01606636 Cookie/Adserver TrackingCookie No 0 Yes No C:\Users\Kenny\Documents\Firefox 2.0.0.7 (en-US) - 2007-10-14.pcv[cookies.txt][.adserver.easyad.info/]
;===================================================================================================================================================================================
SUSPECTS
Sent Location :it’(ò(s5
;===================================================================================================================================================================================
;===================================================================================================================================================================================
VULNERABILITIES
Id Severity Description :it’(ò(s5
;===================================================================================================================================================================================
;===================================================================================================================================================================================
Scots-Nats is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
Sponsored Links
Old 08-28-2008, 07:40 AM   #2 (permalink)
Registered User
 
Join Date: May 2008
Posts: 25
OS: Windows Vista Service Pack 1


Re: Bagle.gen infection (I think?)

*72 Hour bump*
Scots-Nats is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Bookmark on Thread SoupReddit!
 


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off




All times are GMT -7. The time now is 07:36 PM.



Copyright 2001 - 2009, Tech Support Forum
Home Tips Plus | Outdoor Basecamp | Automotive Support Forum

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84