Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: Trojan.Agent/Gen-Kazy[Ico] found by Superantspyware  (Read 10192 times)

0 Members and 1 Guest are viewing this topic.

lectrocrew

    Topic Starter


    Mentor

  • ole dog learning new tricks
  • Thanked: 21
    • Yes
    • Yes
    • My first self-built computer
  • Certifications: List
  • Computer: Specs
  • Experience: Familiar
  • OS: Windows 10
Trojan.Agent/Gen-Kazy[Ico] found by Superantspyware
« on: January 30, 2011, 11:43:06 PM »
Trojan.Agent/Gen-Kazy[Ico]
   C:\PROGRAM FILES\LAVALYS\EVEREST HOME EDITION\EVEREST_CPL.CPL

I have been using Everest Home edition for a long time with no problems.

What does this mean?

SAS log;
SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 01/30/2011 at 11:23 PM

Application Version : 4.48.1000

Core Rules Database Version : 6304
Trace Rules Database Version: 4116

Scan type       : Complete Scan
Total Scan Time : 00:56:05

Memory items scanned      : 587
Memory threats detected   : 0
Registry items scanned    : 7765
Registry threats detected : 0
File items scanned        : 102216
File threats detected     : 160

Trojan.Agent/Gen-Kazy[Ico]
   C:\PROGRAM FILES\LAVALYS\EVEREST HOME EDITION\EVEREST_CPL.CPL

Adware.Tracking Cookie
   C:\Users\Jim\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txt
   C:\Users\Jim\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txt
   C:\Users\Jim\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txt
   C:\Users\Jim\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
   C:\Users\Jim\AppData\Roaming\Microsoft\Windows\Cookies\Low\jim@advertising[2].txt
   C:\Users\Jim\AppData\Roaming\Microsoft\Windows\Cookies\Low\jim@adxpose[1].txt
   C:\Users\Jim\AppData\Roaming\Microsoft\Windows\Cookies\Low\jim@apmebf[1].txt
   C:\Users\Jim\AppData\Roaming\Microsoft\Windows\Cookies\Low\jim@atdmt[1].txt
   C:\Users\Jim\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
   C:\Users\Jim\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
   C:\Users\Jim\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txt
   C:\Users\Jim\AppData\Roaming\Microsoft\Windows\Cookies\Low\jim@doubleclick[1].txt
   C:\Users\Jim\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
   C:\Users\Jim\AppData\Roaming\Microsoft\Windows\Cookies\Low\jim@fastclick[2].txt
   C:\Users\Jim\AppData\Roaming\Microsoft\Windows\Cookies\Low\jim@interclick[2].txt
   C:\Users\Jim\AppData\Roaming\Microsoft\Windows\Cookies\Low\jim@invitemedia[1].txt
   C:\Users\Jim\AppData\Roaming\Microsoft\Windows\Cookies\Low\jim@legolas-media[1].txt
   C:\Users\Jim\AppData\Roaming\Microsoft\Windows\Cookies\Low\jim@liveperson[1].txt
   C:\Users\Jim\AppData\Roaming\Microsoft\Windows\Cookies\Low\jim@liveperson[3].txt
   C:\Users\Jim\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
   C:\Users\Jim\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][1].txt
   C:\Users\Jim\AppData\Roaming\Microsoft\Windows\Cookies\Low\[email protected][2].txt
   C:\Users\Jim\AppData\Roaming\Microsoft\Windows\Cookies\Low\jim@serving-sys[2].txt
   C:\Users\Jim\AppData\Roaming\Microsoft\Windows\Cookies\Low\jim@statcounter[2].txt
   www.naiadsystems.com [ C:\Users\Mike L\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\5WCVRTQK ]
   .doubleclick.net [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   .pornhub.com [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   .pornhub.com [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   ads.crakmedia.com [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   www.pornhub.com [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   .pornhub.com [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   .pornhub.com [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   .banners.facebookofsex.com [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   .banners.facebookofsex.com [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   .banners.facebookofsex.com [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   .banners.facebookofsex.com [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   .banners.facebookofsex.com [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   .r1-ads.ace.advertising.com [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   .advertising.com [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   .advertising.com [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   .advertising.com [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   .advertising.com [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   .adbrite.com [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   .adbrite.com [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   .adbrite.com [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   .adbrite.com [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   .adbrite.com [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   .specificclick.net [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   .specificclick.net [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   .specificclick.net [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   .specificclick.net [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   .adbrite.com [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   ad.yieldmanager.com [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   ad.yieldmanager.com [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   .advertising.com [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   .ads.pointroll.com [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   .pointroll.com [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   .ads.pointroll.com [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   .pointroll.com [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   .ads.pointroll.com [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   .ads.pointroll.com [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   .ads.pointroll.com [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   .ads.pointroll.com [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   .ads.pointroll.com [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   .ads.pointroll.com [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   .advertising.com [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   .yieldmanager.net [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   .atdmt.com [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   .atdmt.com [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   ad.yieldmanager.com [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   .content.yieldmanager.com [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   ad.yieldmanager.com [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   .apmebf.com [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   .fastclick.net [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   .fastclick.net [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   .fastclick.net [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   .fastclick.net [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   .content.yieldmanager.com [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   .mediaplex.com [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   .mediaplex.com [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   .invitemedia.com [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   .invitemedia.com [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   .invitemedia.com [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   .invitemedia.com [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   .invitemedia.com [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   .invitemedia.com [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   .invitemedia.com [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   ad.yieldmanager.com [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   .adbrite.com [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   .acronis.122.2o7.net [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   .collective-media.net [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   .collective-media.net [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   ad.yieldmanager.com [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   ad.yieldmanager.com [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   .interclick.com [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   .interclick.com [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   .a1.interclick.com [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   .a1.interclick.com [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   .a1.interclick.com [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   .a1.interclick.com [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   .a1.interclick.com [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   .interclick.com [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   .tribalfusion.com [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   .imrworldwide.com [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   .imrworldwide.com [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   .bs.serving-sys.com [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   .serving-sys.com [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   .serving-sys.com [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   .serving-sys.com [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   .serving-sys.com [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   .kontera.com [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   .kontera.com [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   .kontera.com [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   .chitika.net [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   .pro-market.net [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   .statcounter.com [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   .a1.interclick.com [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   ad.yieldmanager.com [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   .invitemedia.com [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   .adbrite.com [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   user.lucidmedia.com [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   .media6degrees.com [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   .media6degrees.com [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   .zedo.com [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   .zedo.com [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   .zedo.com [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   .zedo.com [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   .zedo.com [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   .zedo.com [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   stat.onestat.com [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   stat.onestat.com [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   .realmedia.com [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   network.realmedia.com [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   .casalemedia.com [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   .casalemedia.com [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   .casalemedia.com [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   .casalemedia.com [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   .casalemedia.com [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   .casalemedia.com [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   .casalemedia.com [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   .invitemedia.com [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   .adxpose.com [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   .insightexpressai.com [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   citi.bridgetrack.com [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   citi.bridgetrack.com [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   citi.bridgetrack.com [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   citi.bridgetrack.com [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   .lucidmedia.com [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   .burstnet.com [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   www.burstnet.com [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   .advertising.com [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   .www.burstnet.com [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   .ru4.com [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   .questionmarket.com [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   .a1.interclick.com [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   .a1.interclick.com [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   .a1.interclick.com [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   .questionmarket.com [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]
   .pornhub.com [ C:\Users\Mike L\AppData\Roaming\Mozilla\Firefox\Profiles\wgi0my20.default\cookies.sqlite ]

MBAM log:
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Database version: 5644

Windows 6.0.6002 Service Pack 2
Internet Explorer 8.0.6001.18999

1/31/2011 12:31:56 AM
mbam-log-2011-01-31 (00-31-56).txt

Scan type: Full scan (C:\|)
Objects scanned: 269894
Time elapsed: 33 minute(s), 26 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

HJT Log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:44:19 AM, on 1/31/2011
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18999)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files\COMODO\COMODO Internet Security\cfp.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\ProgramData\U3\U3Launcher\LaunchU3.exe
C:\Program Files\Secunia\PSI\psi_tray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Program Files\Trend Micro\HiJackThis\Sniper run as administrator.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: WOT Helper - {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files\WOT\WOT.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: WOT - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKLM\..\Run: [COMODO Internet Security] "C:\Program Files\COMODO\COMODO Internet Security\cfp.exe" -h
O4 - HKLM\..\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: LaunchU3.exe.lnk = ?
O4 - Global Startup: Secunia PSI Tray.lnk = C:\Program Files\Secunia\PSI\psi_tray.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O10 - Unknown file in Winsock LSP: bmnet.dll
O10 - Unknown file in Winsock LSP: bmnet.dll
O10 - Unknown file in Winsock LSP: bmnet.dll
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Plug-in 1.6.0_23) -
O16 - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} (Java Plug-in 1.6.0_23) -
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = toshiba
O17 - HKLM\Software\..\Telephony: DomainName = toshiba
O17 - HKLM\System\CCS\Services\Tcpip\..\{0913D5A8-EAAD-4D04-821E-DF2C6404AAB0}: NameServer = 156.154.70.22,156.154.71.22
O17 - HKLM\System\CCS\Services\Tcpip\..\{9D493B71-F767-4098-8252-DAA7B357177C}: NameServer = 156.154.70.22,156.154.71.22
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = toshiba
O17 - HKLM\System\CS1\Services\Tcpip\..\{0913D5A8-EAAD-4D04-821E-DF2C6404AAB0}: NameServer = 156.154.70.22,156.154.71.22
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = toshiba
O17 - HKLM\System\CS2\Services\Tcpip\..\{0913D5A8-EAAD-4D04-821E-DF2C6404AAB0}: NameServer = 156.154.70.22,156.154.71.22
O18 - Protocol: wot - {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files\WOT\WOT.dll
O23 - Service: Acronis OS Selector Reinstall Service (AcronisOSSReinstallSvc) - Unknown owner - C:\Program Files\Common Files\Acronis\Acronis Disk Director\oss_reinstall_svc.exe
O23 - Service: AT&T RcAppSvc (ATTRcAppSvc) - SmithMicro Inc. - C:\Program Files\AT&T\Communication Manager\RcAppSvc.exe
O23 - Service: AT&T Con App Svc (CAATT) - SmithMicro Inc. - C:\Program Files\AT&T\Communication Manager\ConAppsSvc.exe
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
O23 - Service: ConfigFree Service - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: pinger - Unknown owner - C:\TOSHIBA\IVP\ISM\pinger.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: Secunia PSI Agent - Secunia - C:\Program Files\Secunia\PSI\PSIA.exe
O23 - Service: Secunia Update Agent - Secunia - C:\Program Files\Secunia\PSI\sua.exe
O23 - Service: Swupdtmr - Unknown owner - c:\TOSHIBA\IVP\swupdate\swupdtmr.exe
O23 - Service: TMachInfo - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
O23 - Service: TOSHIBA Navi Support Service (TNaviSrv) - TOSHIBA Corporation - C:\Program Files\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe
O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe

--
End of file - 6925 bytes


SuperDave

  • Malware Removal Specialist
  • Moderator


  • Genius
  • Thanked: 1020
  • Certifications: List
  • Experience: Expert
  • OS: Windows 10
Re: Trojan.Agent/Gen-Kazy[Ico] found by Superantspyware
« Reply #1 on: January 31, 2011, 01:14:06 PM »
Hello and welcome to Computer Hope Forum. My name is Dave. I will be helping you out with your particular problem on your computer.

1. I will be working on your Malware issues. This may or may not solve other issues you have with your machine.
2. The fixes are specific to your problem and should only be used for this issue on this machine.
3. If you don't know or understand something, please don't hesitate to ask.
4. Please DO NOT run any other tools or scans while I am helping you.
5. It is important that you reply to this thread. Do not start a new topic.
6. Your security programs may give warnings for some of the tools I will ask you to use. Be assured, any links I give are safe.
7. Absence of symptoms does not mean that everything is clear.

If you can't access the internet with your infected computer you will have to download and transfer any programs to the computer you're using now and transfer them to the infected computer with a CD-RW or a USB storage device. I prefer a CD because a storage device can get infected. If you use a storage device hold the shift key down while inserting the USB storage device for about 10 secs. You will also have to transfer the logs you receive back to the good computer using the same method until we can get the computer back on-line.
****************************************************

Download ComboFix by sUBs from one of the below links.  Be sure to save it to the Desktop.

link # 1
Link # 2
If you are using Firefox, make sure that your download settings are as follows:

* Tools->Options->Main tab
* Set to "Always ask me where to Save the files".

Close any open web browsers (Firefox, Internet Explorer, etc) before starting ComboFix.

Temporarily disable your anti-virus, and any anti-spyware real-time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.

Right-click combofix.exe and select Run as Administrator and follow the prompts.
When finished, ComboFix will produce a log for you.
Post the ComboFix log and a new HijackThis log in your next reply.

NOTE: Do not mouseclick ComboFix's window while it is running. That may cause it to stall.

Remember to re-enable your anti-virus and anti-spyware protection when ComboFix is complete.
Windows 8 and Windows 10 dual boot with two SSD's