1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Inactive Virus uploaded from google image

Discussion in 'Malware and Virus Removal Archive' started by spiderpug, 2011/06/30.

  1. 2011/06/30
    spiderpug

    spiderpug Inactive Thread Starter

    Joined:
    2009/07/30
    Messages:
    142
    Likes Received:
    0
    [Inactive] Virus uploaded from google image

    Hi,
    Clicked on a google image and it uploaded a virus. Here is the log here from Avira, as soon as I clicked on the photo Avira picked up it had a virus on it.
    Just wondering if I should do a full check?



    Avira AntiVir Personal
    Report file date: Friday, July 01, 2011 09:32

    Scanning for 2844211 virus strains and unwanted programs.

    The program is running as an unrestricted full version.
    Online services are available:

    Licensee : Avira AntiVir Personal - Free Antivirus
    Serial number : 0000149996-ADJIE-0000001
    Platform : Windows 7
    Windows version : (Service Pack 1) [6.1.7601]
    Boot mode : Normally booted
    Username : SYSTEM
    Computer name : KEITHMOON

    Version information:
    BUILD.DAT : 10.2.0.690 35934 Bytes 6/22/2011 18:07:00
    AVSCAN.EXE : 10.3.0.7 484008 Bytes 6/29/2011 10:30:16
    AVSCAN.DLL : 10.0.5.0 47464 Bytes 6/29/2011 10:30:16
    LUKE.DLL : 10.3.0.5 45416 Bytes 6/29/2011 10:30:16
    LUKERES.DLL : 10.0.0.1 12648 Bytes 2/10/2010 12:40:49
    AVSCPLR.DLL : 10.3.0.7 119656 Bytes 6/29/2011 10:30:16
    AVREG.DLL : 10.3.0.7 90472 Bytes 6/29/2011 10:30:16
    VBASE000.VDF : 7.10.0.0 19875328 Bytes 11/6/2009 22:05:36
    VBASE001.VDF : 7.11.0.0 13342208 Bytes 12/14/2010 04:15:47
    VBASE002.VDF : 7.11.3.0 1950720 Bytes 2/9/2011 04:15:47
    VBASE003.VDF : 7.11.5.225 1980416 Bytes 4/7/2011 10:35:35
    VBASE004.VDF : 7.11.8.178 2354176 Bytes 5/31/2011 23:21:00
    VBASE005.VDF : 7.11.8.179 2048 Bytes 5/31/2011 23:21:00
    VBASE006.VDF : 7.11.8.180 2048 Bytes 5/31/2011 23:21:01
    VBASE007.VDF : 7.11.8.181 2048 Bytes 5/31/2011 23:21:01
    VBASE008.VDF : 7.11.8.182 2048 Bytes 5/31/2011 23:21:02
    VBASE009.VDF : 7.11.8.183 2048 Bytes 5/31/2011 23:21:02
    VBASE010.VDF : 7.11.8.184 2048 Bytes 5/31/2011 23:21:02
    VBASE011.VDF : 7.11.8.185 2048 Bytes 5/31/2011 23:21:03
    VBASE012.VDF : 7.11.8.186 2048 Bytes 5/31/2011 23:21:03
    VBASE013.VDF : 7.11.8.222 121856 Bytes 6/2/2011 02:35:18
    VBASE014.VDF : 7.11.9.7 134656 Bytes 6/4/2011 02:35:20
    VBASE015.VDF : 7.11.9.42 136192 Bytes 6/6/2011 22:54:47
    VBASE016.VDF : 7.11.9.72 117248 Bytes 6/7/2011 22:54:50
    VBASE017.VDF : 7.11.9.107 130560 Bytes 6/9/2011 05:27:03
    VBASE018.VDF : 7.11.9.143 132096 Bytes 6/10/2011 05:27:04
    VBASE019.VDF : 7.11.9.172 141824 Bytes 6/14/2011 22:59:25
    VBASE020.VDF : 7.11.9.214 144896 Bytes 6/15/2011 22:59:27
    VBASE021.VDF : 7.11.9.244 196608 Bytes 6/16/2011 22:59:29
    VBASE022.VDF : 7.11.10.28 152576 Bytes 6/20/2011 00:41:59
    VBASE023.VDF : 7.11.10.53 210432 Bytes 6/21/2011 00:41:59
    VBASE024.VDF : 7.11.10.88 132096 Bytes 6/24/2011 20:32:55
    VBASE025.VDF : 7.11.10.112 138752 Bytes 6/27/2011 10:30:15
    VBASE026.VDF : 7.11.10.113 2048 Bytes 6/27/2011 10:30:15
    VBASE027.VDF : 7.11.10.114 2048 Bytes 6/27/2011 10:30:15
    VBASE028.VDF : 7.11.10.115 2048 Bytes 6/27/2011 10:30:15
    VBASE029.VDF : 7.11.10.116 2048 Bytes 6/27/2011 10:30:15
    VBASE030.VDF : 7.11.10.117 2048 Bytes 6/27/2011 10:30:15
    VBASE031.VDF : 7.11.10.146 161792 Bytes 6/29/2011 10:30:15
    Engineversion : 8.2.5.24
    AEVDF.DLL : 8.1.2.1 106868 Bytes 3/28/2011 04:15:27
    AESCRIPT.DLL : 8.1.3.65 1606010 Bytes 5/29/2011 10:38:38
    AESCN.DLL : 8.1.7.2 127349 Bytes 3/28/2011 04:15:27
    AESBX.DLL : 8.2.1.34 323957 Bytes 6/1/2011 23:21:35
    AERDL.DLL : 8.1.9.9 639347 Bytes 3/25/2011 00:21:38
    AEPACK.DLL : 8.2.6.9 557429 Bytes 6/16/2011 22:59:47
    AEOFFICE.DLL : 8.1.1.25 205178 Bytes 6/1/2011 23:21:32
    AEHEUR.DLL : 8.1.2.132 3567992 Bytes 6/23/2011 06:44:04
    AEHELP.DLL : 8.1.17.2 246135 Bytes 5/29/2011 10:37:37
    AEGEN.DLL : 8.1.5.6 401780 Bytes 5/29/2011 10:37:34
    AEEMU.DLL : 8.1.3.0 393589 Bytes 3/28/2011 04:15:19
    AECORE.DLL : 8.1.21.1 196983 Bytes 5/29/2011 10:37:28
    AEBB.DLL : 8.1.1.0 53618 Bytes 3/28/2011 04:15:19
    AVWINLL.DLL : 10.0.0.0 19304 Bytes 3/28/2011 04:15:31
    AVPREF.DLL : 10.0.3.2 44904 Bytes 6/29/2011 10:30:16
    AVREP.DLL : 10.0.0.10 174120 Bytes 5/29/2011 10:38:52
    AVARKT.DLL : 10.0.26.1 255336 Bytes 6/29/2011 10:30:16
    AVEVTLOG.DLL : 10.0.0.9 203112 Bytes 6/29/2011 10:30:16
    SQLITE3.DLL : 3.6.19.0 355688 Bytes 6/17/2010 03:27:22
    AVSMTP.DLL : 10.0.0.17 63848 Bytes 3/28/2011 04:15:30
    NETNT.DLL : 10.0.0.0 11624 Bytes 3/28/2011 04:15:39
    RCIMAGE.DLL : 10.0.0.35 2589544 Bytes 6/29/2011 10:30:15
    RCTEXT.DLL : 10.0.64.0 97640 Bytes 6/29/2011 10:30:15

    Configuration settings for the scan:
    Jobname.............................: avguard_async_scan
    Configuration file..................: C:\ProgramData\Avira\AntiVir Desktop\TEMP\AVGUARD_4e2ec24f\guard_slideup.avp
    Logging.............................: Default
    Primary action......................: repair
    Secondary action....................: quarantine
    Scan master boot sector.............: on
    Scan boot sector....................: off
    Process scan........................: on
    Scan registry.......................: off
    Search for rootkits.................: off
    Integrity checking of system files..: off
    Scan all files......................: All files
    Scan archives.......................: on
    Recursion depth.....................: 20
    Smart extensions....................: on
    Macro heuristic.....................: on
    File heuristic......................: Complete
    Deviating risk categories...........: +APPL,+GAME,+JOKE,

    Start of the scan: Friday, July 01, 2011 09:32

    The scan of running processes will be started
    Scan process 'avscan.exe' - '1' Module(s) have been scanned
    Scan process 'chrome.exe' - '1' Module(s) have been scanned
    Scan process 'chrome.exe' - '1' Module(s) have been scanned
    Scan process 'rundll32.exe' - '1' Module(s) have been scanned
    Scan process 'CCC.exe' - '1' Module(s) have been scanned
    Scan process 'MOM.exe' - '1' Module(s) have been scanned
    Scan process 'chrome.exe' - '1' Module(s) have been scanned
    Scan process 'chrome.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'iPodService.exe' - '1' Module(s) have been scanned
    Scan process 'wmpnetwk.exe' - '1' Module(s) have been scanned
    Scan process 'SynTPHelper.exe' - '1' Module(s) have been scanned
    Scan process 'DTLite.exe' - '1' Module(s) have been scanned
    Scan process 'sidebar.exe' - '1' Module(s) have been scanned
    Scan process 'iTunesHelper.exe' - '1' Module(s) have been scanned
    Scan process 'SynTPEnh.exe' - '1' Module(s) have been scanned
    Scan process 'avgnt.exe' - '1' Module(s) have been scanned
    Scan process 'RtHDVCpl.exe' - '1' Module(s) have been scanned
    Scan process 'LManager.exe' - '1' Module(s) have been scanned
    Scan process 'SearchIndexer.exe' - '1' Module(s) have been scanned
    Scan process 'Explorer.EXE' - '1' Module(s) have been scanned
    Scan process 'Dwm.exe' - '1' Module(s) have been scanned
    Scan process 'taskhost.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'conhost.exe' - '1' Module(s) have been scanned
    Scan process 'avshadow.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'mDNSResponder.exe' - '1' Module(s) have been scanned
    Scan process 'AppleMobileDeviceService.exe' - '1' Module(s) have been scanned
    Scan process 'avguard.exe' - '1' Module(s) have been scanned
    Scan process 'armsvc.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'sched.exe' - '1' Module(s) have been scanned
    Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'atieclxx.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'atiesrxx.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'winlogon.exe' - '1' Module(s) have been scanned
    Scan process 'lsm.exe' - '1' Module(s) have been scanned
    Scan process 'lsass.exe' - '1' Module(s) have been scanned
    Scan process 'services.exe' - '1' Module(s) have been scanned
    Scan process 'csrss.exe' - '1' Module(s) have been scanned
    Scan process 'wininit.exe' - '1' Module(s) have been scanned
    Scan process 'csrss.exe' - '1' Module(s) have been scanned
    Scan process 'smss.exe' - '1' Module(s) have been scanned

    Starting the file scan:

    Begin scan in 'C:\Users\Spiderpug\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000373'
    HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System\EnableLUA
    C:\Users\Spiderpug\AppData\Local\Google\Chrome\User Data\Default\Cache\f_000373
    [DETECTION] Contains recognition pattern of the HTML/Infected.WebPage.Gen HTML script virus
    [NOTE] The file was moved to the quarantine directory under the name '4b474636.qua'.


    End of the scan: Friday, July 01, 2011 09:32
    Used time: 00:05 Minute(s)

    The scan has been done completely.

    0 Scanned directories
    52 Files were scanned
    1 Viruses and/or unwanted programs were found
    0 Files were classified as suspicious
    0 files were deleted
    0 Viruses and unwanted programs were repaired
    1 Files were moved to quarantine
    0 Files were renamed
    0 Files cannot be scanned
    51 Files not concerned
    0 Archives were scanned
    0 Warnings
    1 Notes
     
  2. 2011/06/30
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Are you having any issues?
     

  3. to hide this advert.

  4. 2011/06/30
    spiderpug

    spiderpug Inactive Thread Starter

    Joined:
    2009/07/30
    Messages:
    142
    Likes Received:
    0
    Hi

    No not at all, as soon as it was detected it was put straight into quarantine
     
  5. 2011/06/30
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Run MBAM for a good measure.
     
  6. 2011/07/02
    spiderpug

    spiderpug Inactive Thread Starter

    Joined:
    2009/07/30
    Messages:
    142
    Likes Received:
    0
    Done scans, nothing found and no problems so it should be ok?
     
  7. 2011/07/02
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Good luck then :)
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.