Lately my anti virus program has been going crazy about a Genetik Trojan. It reports that .exe files in the temp folders are infected and that they've been moved to quarantine.
All of these very similar, some "good" program creating a .exe file with some generic random name.
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Time Module Object Name Threat Action User Information
2008-08-01 09:26:29 AMON file C:\DOCUME~1\K\LOCALS~1\Temp\026G17gB.exe probably a variant of Win32/Genetik trojan quarantined - deleted KIRKEN\K Event occurred on a new file created by the application: C:\Program Files\Mozilla Firefox\firefox.exe. The file was moved to quarantine. You may close this window.
2008-08-01 01:05:57 AMON file C:\DOCUME~1\K\LOCALS~1\Temp\i6gc0NYi.exe probably a variant of Win32/Genetik trojan quarantined - deleted KIRKEN\K Event occurred on a new file created by the application: C:\WINDOWS\system32\ctfmon.exe. The file was moved to quarantine. You may close this window.
2008-07-31 23:00:53 AMON file C:\DOCUME~1\K\LOCALS~1\Temp\Myj7bl1W.exe probably a variant of Win32/Genetik trojan quarantined - deleted KIRKEN\K Event occurred on a new file created by the application: C:\WINDOWS\system32\ctfmon.exe. The file was moved to quarantine. You may close this window.
2008-07-31 20:58:27 AMON file C:\DOCUME~1\K\LOCALS~1\Temp\CbeFwjqk.exe probably a variant of Win32/Genetik trojan quarantined - deleted KIRKEN\K Event occurred on a new file created by the application: C:\WINDOWS\system32\ctfmon.exe. The file was moved to quarantine. You may close this window.
2008-07-31 18:50:42 AMON file C:\DOCUME~1\K\LOCALS~1\Temp\2347BTJ8.exe probably a variant of Win32/Genetik trojan quarantined - deleted KIRKEN\K Event occurred on a new file created by the application: C:\WINDOWS\system32\ctfmon.exe. The file was moved to quarantine. You may close this window.
2008-07-31 13:36:18 AMON file C:\DOCUME~1\K\LOCALS~1\Temp\NBNORJnc.exe probably a variant of Win32/Genetik trojan quarantined - deleted KIRKEN\K Event occurred on a new file created by the application: C:\Program Files\MSN Messenger\MsnMsgr.Exe. The file was moved to quarantine. You may close this window.
2008-07-31 11:29:51 AMON file C:\DOCUME~1\K\LOCALS~1\Temp\uJd7dBoU.exe probably a variant of Win32/Genetik trojan quarantined - deleted KIRKEN\K Event occurred on a new file created by the application: C:\Program Files\Logitech\SetPoint\SetPoint.exe. The file was moved to quarantine. You may close this window.
2008-07-31 03:06:53 AMON file C:\DOCUME~1\K\LOCALS~1\Temp\162E3DAS.exe probably a variant of Win32/Genetik trojan quarantined - deleted KIRKEN\K Event occurred on a new file created by the application: C:\Program Files\Rainlendar2\Rainlendar2.exe. The file was moved to quarantine. You may close this window.
2008-07-31 01:29:36 AMON file C:\DOCUME~1\K\LOCALS~1\Temp\U00BuK44.exe probably a variant of Win32/Genetik trojan quarantined - deleted KIRKEN\K Event occurred on a new file created by the application: C:\Program Files\Rainlendar2\Rainlendar2.exe. The file was moved to quarantine. You may close this window.
2008-07-31 01:29:35 AMON file C:\DOCUME~1\K\LOCALS~1\Temp\07K5tE4i.exe probably a variant of Win32/Genetik trojan quarantined - deleted KIRKEN\K Event occurred on a new file created by the application: C:\Program Files\Rainlendar2\Rainlendar2.exe. The file was moved to quarantine. You may close this window.
2008-07-30 22:15:57 AMON file C:\DOCUME~1\K\LOCALS~1\Temp\55vdrxRH.exe probably a variant of Win32/Genetik trojan quarantined - deleted KIRKEN\K Event occurred on a new file created by the application: C:\Program Files\Rainlendar2\Rainlendar2.exe. The file was moved to quarantine. You may close this window.
2008-07-30 22:15:56 AMON file C:\DOCUME~1\K\LOCALS~1\Temp\2fhMpQm3.exe probably a variant of Win32/Genetik trojan quarantined - deleted KIRKEN\K Event occurred on a new file created by the application: C:\Program Files\MSN Messenger\MsnMsgr.Exe. The file was moved to quarantine. You may close this window.
2008-07-30 16:31:20 AMON file C:\DOCUME~1\K\LOCALS~1\Temp\B8ccjE02.exe probably a variant of Win32/Genetik trojan quarantined - deleted KIRKEN\K Event occurred on a new file created by the application: C:\WINDOWS\system32\wscntfy.exe. The file was moved to quarantine. You may close this window.
2008-07-30 14:39:44 AMON file C:\DOCUME~1\K\LOCALS~1\Temp\77AyTuG2.exe probably a variant of Win32/Genetik trojan quarantined - deleted KIRKEN\K Event occurred on a new file created by the application: C:\WINDOWS\system32\wuauclt.exe. The file was moved to quarantine. You may close this window.
2008-07-30 14:39:42 AMON file C:\DOCUME~1\K\LOCALS~1\Temp\61mtrxDY.exe probably a variant of Win32/Genetik trojan quarantined - deleted KIRKEN\K Event occurred on a new file created by the application: C:\Program Files\MSN Messenger\MsnMsgr.Exe. The file was moved to quarantine. You may close this window.
2008-07-30 05:55:55 AMON file C:\DOCUME~1\K\LOCALS~1\Temp\62K2647r.exe probably a variant of Win32/Genetik trojan quarantined - deleted KIRKEN\K Event occurred on a new file created by the application: c:\program files\internet explorer\iexplore.exe. The file was moved to quarantine. You may close this window.
2008-07-30 05:55:53 AMON file C:\DOCUME~1\K\LOCALS~1\Temp\Yiu0o7L0.exe probably a variant of Win32/Genetik trojan quarantined - deleted KIRKEN\K Event occurred on a new file created by the application: c:\program files\internet explorer\iexplore.exe. The file was moved to quarantine. You may close this window.
2008-07-30 01:19:04 AMON file C:\DOCUME~1\K\LOCALS~1\Temp\QhOx41mQ.exe probably a variant of Win32/Genetik trojan quarantined - deleted KIRKEN\K Event occurred on a new file created by the application: c:\program files\internet explorer\iexplore.exe. The file was moved to quarantine. You may close this window.
2008-07-29 23:18:45 AMON file C:\DOCUME~1\K\LOCALS~1\Temp\3803IL71.exe probably a variant of Win32/Genetik trojan quarantined - deleted KIRKEN\K Event occurred on a new file created by the application: C:\Program Files\Mozilla Firefox\firefox.exe. The file was moved to quarantine. You may close this window.
2008-07-29 21:18:49 AMON file C:\DOCUME~1\K\LOCALS~1\Temp\2HFU11XB.exe probably a variant of Win32/Genetik trojan quarantined - deleted KIRKEN\K Event occurred on a new file created by the application: c:\program files\internet explorer\iexplore.exe. The file was moved to quarantine. You may close this window.
2008-07-29 19:19:32 AMON file C:\DOCUME~1\K\LOCALS~1\Temp\8dSY0sku.exe probably a variant of Win32/Genetik trojan quarantined - deleted KIRKEN\K Event occurred on a new file created by the application: C:\WINDOWS\system32\wscntfy.exe. The file was moved to quarantine. You may close this window.
2008-07-29 17:12:45 AMON file C:\DOCUME~1\K\LOCALS~1\Temp\22BFu0Ap.exe probably a variant of Win32/Genetik trojan quarantined - deleted KIRKEN\K Event occurred on a new file created by the application: C:\Program Files\Mozilla Firefox\firefox.exe. The file was moved to quarantine. You may close this window.
2008-07-29 15:22:46 AMON file C:\DOCUME~1\K\LOCALS~1\Temp\xlqnBb1X.exe probably a variant of Win32/Genetik trojan quarantined - deleted KIRKEN\K Event occurred on a new file created by the application: C:\Program Files\Mozilla Firefox\firefox.exe. The file was moved to quarantine. You may close this window.
2008-07-29 14:24:02 AMON file C:\DOCUME~1\K\LOCALS~1\Temp\NDk4Y3S8.exe probably a variant of Win32/Genetik trojan quarantined - deleted KIRKEN\K Event occurred on a new file created by the application: C:\Program Files\Internet Explorer\IEXPLORE.EXE. The file was moved to quarantine. You may close this window.
2008-07-29 14:24:00 AMON file C:\DOCUME~1\K\LOCALS~1\Temp\0O1MBEEw.exe probably a variant of Win32/Genetik trojan quarantined - deleted KIRKEN\K Event occurred on a new file created by the application: C:\Program Files\Internet Explorer\IEXPLORE.EXE. The file was moved to quarantine. You may close this window.
2008-07-29 02:21:27 AMON file C:\DOCUME~1\K\LOCALS~1\Temp\7534ewy0.exe probably a variant of Win32/Genetik trojan quarantined - deleted KIRKEN\K Event occurred on a new file created by the application: C:\Program Files\Mozilla Firefox\firefox.exe. The file was moved to quarantine. You may close this window.
2008-07-29 00:34:14 AMON file C:\DOCUME~1\K\LOCALS~1\Temp\Je5qtC11.exe probably a variant of Win32/Genetik trojan quarantined - deleted KIRKEN\K Event occurred on a new file created by the application: C:\Program Files\Rainlendar2\Rainlendar2.exe. The file was moved to quarantine. You may close this window.
2008-07-28 22:16:13 AMON file C:\DOCUME~1\K\LOCALS~1\Temp\08FUXl53.exe probably a variant of Win32/Genetik trojan quarantined - deleted KIRKEN\K Event occurred on a new file created by the application: C:\Program Files\Mozilla Firefox\firefox.exe. The file was moved to quarantine. You may close this window.
2008-07-28 20:48:53 AMON file C:\DOCUME~1\K\LOCALS~1\Temp\UaXonQ4n.exe probably a variant of Win32/Genetik trojan quarantined - deleted KIRKEN\K Event occurred on a new file created by the application: C:\Program Files\Mozilla Firefox\firefox.exe. The file was moved to quarantine. You may close this window.
2008-07-28 20:48:48 AMON file C:\DOCUME~1\K\LOCALS~1\Temp\QmieoBH0.exe probably a variant of Win32/Genetik trojan quarantined - deleted KIRKEN\K Event occurred on a new file created by the application: C:\Program Files\Mozilla Firefox\firefox.exe. The file was moved to quarantine. You may close this window.
2008-07-28 16:15:51 AMON file C:\DOCUME~1\K\LOCALS~1\Temp\4E0fU0pa.exe probably a variant of Win32/Genetik trojan quarantined - deleted KIRKEN\K Event occurred on a new file created by the application: C:\Program Files\Mozilla Firefox\firefox.exe. The file was moved to quarantine. You may close this window.
2008-07-28 14:34:16 AMON file C:\DOCUME~1\K\LOCALS~1\Temp\iO6LmCCJ.exe probably a variant of Win32/Genetik trojan quarantined - deleted KIRKEN\K Event occurred on a new file created by the application: C:\Program Files\Internet Explorer\iexplore.exe. The file was moved to quarantine. You may close this window.
2008-07-28 14:34:15 AMON file C:\DOCUME~1\K\LOCALS~1\Temp\dw3ypGD4.exe probably a variant of Win32/Genetik trojan quarantined - deleted KIRKEN\K Event occurred on a new file created by the application: C:\Program Files\MSN Messenger\MsnMsgr.Exe. The file was moved to quarantine. You may close this window.
2008-07-27 22:53:44 AMON file C:\DOCUME~1\K\LOCALS~1\Temp\UU86l0y2.exe probably a variant of Win32/Genetik trojan quarantined - deleted KIRKEN\K Event occurred on a new file created by the application: C:\WINDOWS\etMon.exe. The file was moved to quarantine. You may close this window.
2008-07-25 14:28:30 AMON file C:\DOCUME~1\K\LOCALS~1\Temp\h6rd5gxN.exe probably a variant of Win32/Genetik trojan quarantined - deleted KIRKEN\K Event occurred on a new file created by the application: C:\Program Files\Eset\nod32kui.exe. The file was moved to quarantine. You may close this window.
2008-07-20 04:19:27 AMON file C:\DOCUME~1\K\LOCALS~1\Temp\01R3sC4h.exe probably unknown NewHeur_PE virus quarantined - deleted KIRKEN\K Event occurred on a new file created by the application: C:\Program Files\MSN Messenger\MsnMsgr.Exe. The file was moved to quarantine. You may close this window.
2008-07-20 02:34:36 AMON file C:\DOCUME~1\K\LOCALS~1\Temp\LHo83sNa.exe probably unknown NewHeur_PE virus quarantined - deleted KIRKEN\K Event occurred on a new file created by the application: C:\Program Files\Mozilla Firefox\firefox.exe. The file was moved to quarantine. You may close this window.
2008-07-20 01:37:53 AMON file C:\DOCUME~1\K\LOCALS~1\Temp\mC3ITTX6.exe probably unknown NewHeur_PE virus quarantined - deleted KIRKEN\K Event occurred on a new file created by the application: C:\Program Files\Mozilla Firefox\firefox.exe. The file was moved to quarantine. You may close this window.
2008-07-20 01:37:51 AMON file C:\DOCUME~1\K\LOCALS~1\Temp\PI2fE28S.exe probably unknown NewHeur_PE virus quarantined - deleted KIRKEN\K Event occurred on a new file created by the application: C:\Program Files\MSN Messenger\MsnMsgr.Exe. The file was moved to quarantine. You may close this window.
2008-07-19 06:17:25 AMON file C:\DOCUME~1\K\LOCALS~1\Temp\ab8711jX.exe probably unknown NewHeur_PE virus quarantined - deleted KIRKEN\K Event occurred on a new file created by the application: C:\Program Files\Internet Explorer\iexplore.exe. The file was moved to quarantine. You may close this window.
2008-07-19 04:18:15 AMON file C:\DOCUME~1\K\LOCALS~1\Temp\Xmu4f873.exe probably unknown NewHeur_PE virus quarantined - deleted KIRKEN\K Event occurred on a new file created by the application: C:\Program Files\Mozilla Firefox\firefox.exe. The file was moved to quarantine. You may close this window.
2008-07-19 02:12:05 AMON file C:\DOCUME~1\K\LOCALS~1\Temp\3tu8ijvI.exe probably unknown NewHeur_PE virus quarantined - deleted KIRKEN\K Event occurred on a new file created by the application: C:\Program Files\Mozilla Firefox\firefox.exe. The file was moved to quarantine. You may close this window.
2008-07-19 01:34:05 AMON file C:\DOCUME~1\K\LOCALS~1\Temp\Li7y8848.exe probably unknown NewHeur_PE virus quarantined - deleted KIRKEN\K Event occurred on a new file created by the application: C:\WINDOWS\system32\wscntfy.exe. The file was moved to quarantine. You may close this window.
2008-07-18 23:27:54 AMON file C:\DOCUME~1\K\LOCALS~1\Temp\RHXtT13O.exe probably unknown NewHeur_PE virus quarantined - deleted KIRKEN\K Event occurred on a new file created by the application: C:\Program Files\Mozilla Firefox\firefox.exe. The file was moved to quarantine. You may close this window.
2008-07-18 22:10:32 AMON file C:\DOCUME~1\K\LOCALS~1\Temp\E68nIVsT.exe probably unknown NewHeur_PE virus quarantined - deleted KIRKEN\K Event occurred on a new file created by the application: C:\Program Files\Mozilla Firefox\firefox.exe. The file was moved to quarantine. You may close this window.
2008-07-18 22:10:21 AMON file C:\DOCUME~1\K\LOCALS~1\Temp\q5sa6n27.exe probably unknown NewHeur_PE virus quarantined - deleted KIRKEN\K Event occurred on a new file created by the application: C:\WINDOWS\Explorer.EXE. The file was moved to quarantine. You may close this window.
2008-07-18 22:10:15 AMON file C:\DOCUME~1\K\LOCALS~1\Temp\KIrm671c.exe probably unknown NewHeur_PE virus quarantined - deleted KIRKEN\K Event occurred on a new file created by the application: C:\Program Files\Mozilla Firefox\firefox.exe. The file was moved to quarantine. You may close this window.
2008-07-18 15:17:36 AMON file C:\DOCUME~1\K\LOCALS~1\Temp\iAYE0u7s.exe probably unknown NewHeur_PE virus quarantined - deleted KIRKEN\K Event occurred on a new file created by the application: C:\Program Files\MSN Messenger\MsnMsgr.Exe. The file was moved to quarantine. You may close this window.
2008-07-18 01:32:02 AMON file C:\DOCUME~1\K\LOCALS~1\Temp\2GGH70EI.exe probably unknown NewHeur_PE virus quarantined - deleted KIRKEN\K Event occurred on a new file created by the application: C:\Program Files\MSN Messenger\MsnMsgr.Exe. The file was moved to quarantine. You may close this window.
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
After a while a-squared also started noticing that some of those .exes were downloading "invisible" data and I could choose to block that.
Is this something serious or am I just suffering from programs interfering with eachother or themselves??
Thanks in advance
/Kristian
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
My HJT log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:09:56, on 2008-08-01
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\SCardSvr.exe
C:\Program Files\a-squared Anti-Malware\a2service.exe
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Eset\nod32kui.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\ASUS\Ai Suite\AiNap\AiNap.exe
C:\Program Files\a-squared Anti-Malware\a2guard.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Rainlendar2\Rainlendar2.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\Program Files\MSN Messenger\usnsvc.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Adobe\Reader 8.0\Reader\AcroRd32.exe
C:\Program Files\VideoLAN\VLC\vlc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Trend Micro\HijackThis\hajit.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [Ai Nap] "C:\Program Files\ASUS\Ai Suite\AiNap\AiNap.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [a-squared] "C:\Program Files\a-squared Anti-Malware\a2guard.exe" /d=60
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Rainlendar2] C:\Program Files\Rainlendar2\Rainlendar2.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O23 - Service: a-squared Anti-Malware Service (a2AntiMalware) - Emsi Software GmbH - C:\Program Files\a-squared Anti-Malware\a2service.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
--
End of file - 3997 bytes
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~