1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

XP Security Center again? Kaspersky Log

Discussion in 'Malware and Virus Removal Archive' started by Dion, 2008/08/09.

  1. 2008/08/09
    Dion

    Dion Inactive Thread Starter

    Joined:
    2005/01/07
    Messages:
    53
    Likes Received:
    0
    Hi all, Im trying to post the Kaspersky log but the thread wont open so here I go again.. I had to update Windows to SP4 to get Java/Kasp to work. On exit fm Kasp, Norton said it blocked XP Sec Center? Ran MBam and it found trojan Ias? here is log too. Need to get to thread for removal link again.
    Thanks for the help.
    KASPERSKY ONLINE SCANNER 7 REPORTKASPERSKY ONLINE SCANNER 7 REPORT
    Saturday, August 9, 2008
    Operating System: Microsoft Windows 2000 Professional Service Pack 4
    (build 2195)
    Kaspersky Online Scanner 7 version: 7.0.25.0
    Program database last update: Saturday, August 09, 2008 14:00:16
    Records in database: 1074871


    Scan settings
    Scan using the following databaseextended
    Scan archivesyes
    Scan mail databasesyes

    Scan areaMy Computer
    C:\
    D:\
    E:\

    Scan statistics
    Files scanned60410
    Threat name10
    Infected objects2406
    Suspicious objects0
    Duration of the scan02:38:36

    File nameThreat nameThreats count
    C:\Documents and Settings\All Users\Application Data\Symantec\Norton
    AntiVirus\Quarantine\0002015F.datInfected: Backdoor.Win32.Small.ejx1

    C:\Documents and Settings\All Users\Application Data\Symantec\Norton
    AntiVirus\Quarantine\00052B5C.datInfected: Backdoor.Win32.Small.ejx1

    C:\Documents and Settings\All Users\Application Data\Symantec\Norton
    AntiVirus\Quarantine\00095558.datInfected: Backdoor.Win32.Small.ejx1

    C:\Documents and Settings\All Users\Application Data\Symantec\Norton
    AntiVirus\Quarantine\000C7F54.datInfected: Backdoor.Win32.Small.ejx1

    C:\Documents and Settings\All Users\Application Data\Symantec\Norton
    AntiVirus\Quarantine\000F2951.datInfected: Backdoor.Win32.Small.ejx1

    C:\Documents and Settings\All Users\Application Data\Symantec\Norton
    AntiVirus\Quarantine\0012534D.datInfected: Backdoor.Win32.Small.ejx1

    C:\Documents and Settings\All Users\Application Data\Symantec\Norton
    AntiVirus\Quarantine\00167D4A.datInfected: Backdoor.Win32.Small.ejx1

    C:\Documents and Settings\All Users\Application Data\Symantec\Norton
    AntiVirus\Quarantine\00192746.datInfected: Backdoor.Win32.Small.ejx1

    C:\Documents and Settings\All Users\Application Data\Symantec\Norton
    AntiVirus\Quarantine\001C5142.datInfected: Backdoor.Win32.Small.ejx1

    C:\Documents and Settings\All Users\Application Data\Symantec\Norton
    AntiVirus\Quarantine\001F7B3F.datInfected: Backdoor.Win32.Small.ejx1

    C:\Documents and Settings\All Users\Application Data\Symantec\Norton
    AntiVirus\Quarantine\0023253B.datInfected: Backdoor.Win32.Small.ejx1

    C:\Documents and Settings\All Users\Application Data\Symantec\Norton
    AntiVirus\Quarantine\00264F38.datInfected: Backdoor.Win32.Small.ejx1

    C:\Documents and Settings\All Users\Application Data\Symantec\Norton
    AntiVirus\Quarantine\00297934.datInfected: Backdoor.Win32.Small.ejx1

    C:\Documents and Settings\All Users\Application Data\Symantec\Norton
    AntiVirus\Quarantine\002D2330.datInfected: Backdoor.Win32.Small.ejx1

    C:\Documents and Settings\All Users\Application Data\Symantec\Norton
    AntiVirus\Quarantine\002E3D33.datInfected: Backdoor.Win32.Small.ejx1


    This goes on the same until this last three:


    C:\Documents and Settings\All Users\Application Data\Symantec\Norton
    AntiVirus\Quarantine\7FFC2D66.datInfected: Backdoor.Win32.Small.ejx1

    C:\Documents and Settings\All Users\Application Data\Symantec\Norton
    AntiVirus\Quarantine\7FFF5763.datInfected: Backdoor.Win32.Small.ejx1

    C:\Program Files\Symantec\LiveUpdate\DISreboot.exeInfected:
    not-a-virus:AdWare.Win32.Alibabar.t1

    The selected area was scanned.
     
    Dion,
    #1
  2. 2008/08/09
    Geri Lifetime Subscription

    Geri Inactive Alumni

    Joined:
    2003/03/02
    Messages:
    4,580
    Likes Received:
    7
    Hi Dion
    Most of that is in Nortons quarantine folder, Please open that folder and delete eveything in there.

    Then do this.

    Please go HERE to run Panda's ActiveScan
    • Once you are on the Panda site click the Scan your PC button
    • A new window will open...click the Check Now button
    • Enter your Country
    • Enter your State/Province
    • Enter your e-mail address and click send
    • Select either Home User or Company
    • Click the big Scan Now button
    • If it wants to install an ActiveX component allow it
    • It will start downloading the files it requires for the scan (Note: It may take a couple of minutes)
    • When download is complete, click on My Computer to start the scan
    • When the scan completes, if anything malicious is detected, click the See Report button, then Save Report and save it to a convenient location. Post the contents of the ActiveScan report

    Thanks
    Geri
     
    Geri,
    #2

  3. to hide this advert.

  4. 2008/08/09
    Dion

    Dion Inactive Thread Starter

    Joined:
    2005/01/07
    Messages:
    53
    Likes Received:
    0
    MBAM log

    Malwarebytes' Anti-Malware 1.24
    Database version: 1015
    Windows 5.0.2195 Service Pack 4

    1:05:34 PM 8/9/2008
    mbam-log-8-9-2008 (13-05-34).txt

    Scan type: Quick Scan
    Objects scanned: 37417
    Time elapsed: 8 minute(s), 57 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 1
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 0

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Ias (Trojan.Agent) -> Quarantined and deleted successfully.

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    (No malicious items detected)

    Should I do anthing else before I shutdown? would not like registry corrupted again! thanks
     
    Dion,
    #3
  5. 2008/08/09
    Geri Lifetime Subscription

    Geri Inactive Alumni

    Joined:
    2003/03/02
    Messages:
    4,580
    Likes Received:
    7
    Hi
    No, you can reboot, then see my post above.

    Geri
     
    Geri,
    #4
  6. 2008/08/09
    Dion

    Dion Inactive Thread Starter

    Joined:
    2005/01/07
    Messages:
    53
    Likes Received:
    0
    Panda does not respond

    I click on the scan now but nothing happens... the hard drive is running ten miles n hour but I dont see no prompts? I'll keep trying.
     
    Dion,
    #5

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.