Bullguard Antivirus Forum Download A Free Copy Of Bullguard Antivirus Software
Free Antivirus Forum - Learn about antivirus, firewalls and personal security Free Antivirus Forum - Learn about antivirus, firewalls and personal security
 HomeLog InRegisterCommunity CalendarSearch the ForumView The Member ListHelp
I had 3 firewall requests and then an alert from Windows Security Center, need help
   
BullGuard Antivirus Forum > Virus > Virus Questions > I had 3 firewall requests and then an alert from Windows Security Center, need help  
Forum Quick Jump
 
New Topic Post reply to : I had 3 firewall requests and then an alert from Windows Security Center, need help Printable version of : I had 3 firewall requests and then an alert from Windows Security Center, need help
[ << Previous Thread | Next Thread >> ]

Ryki
New Member


Date Joined Oct 2008
Total Posts : 5
 
   Posted 10-7-2008 6:42 (GMT +1)    Quote: I had 3 firewall requests and then an alert from Windows Security Center, need helpAlert an admin about: I had 3 firewall requests and then an alert from Windows Security Center, need help
Hi,
 
I had 3 requests pop up today from my Bullguard software within around 5 minutes of each other which I sent for analysis and they were checked and confirmed as ok so i carried on browsing as normal.
 
Then I had an alert pop up from Windows Security Center saying that a trojan of some sort (can't remember the name and I can't find a log to get that info) was trying to get through and that Windows couldn't do nothing to stop it.
 
So I ran a full system scan, found 7 problems and rectified them. all good.
 
Then I checked the firewall to check what programs are allowed and what are blocked and I found these 3 previous application requests at the foot of the list.  So I decided to block them all.  Then I explored the folders to see what they were about and found these:
 
1. 'xcnupgfc.exe' found in 'windows/system32' folder
 
2. 'hgzsbgpy.exe' found in 'applications/ripqrspi' folder
 
3. The 3rd I cant remember the name but it was something like 'jqs'
 
Now I did a search on the web to check these out and found No.3 to be a virus so I removed that but I couldn't find anything for the other two.  So I tried removing these both manually but it didn't work.  So I sent them to my bullguard software to be scanned and they came back ok?!?!   So I just removed them from the firewall list to see if they would do something again and no.1 did want to play so I have blocked it with no current further action  (on the details I logged this bit of info 'ev1s-209-62-106-80.theplanet.com' if that means anything to anyone!).  No.2 hasn't reared its ugly head yet but i expect it will soon!
 
Anyways, what I want to know is, what are No.1 and No.2 and do I need to get rid of them?!
 
I have the reports from the individual file scans here:
 
___________________________________________________________
BullGuard Scan Report
Scan Profile: "~10"
___________________________________________________________

----[  System Info  ]------------
OS Version: Microsoft Windows XP Home Edition - Service Pack 3 (Build 2600) [2 * x86 CPUs]
Physical memory: 2040 MB
System up-time: 0 days, 03 hours, 35 minutes, 34 seconds
BullGuard up-time: 0 days, 03 hours, 34 minutes, 15 seconds
TopLayer Version: 8, 5, 0, 16
FileSpy5 Version: N/A
BdFileSpy Version: 3.12.0.62 built by: WinDDK
BsFileScan Version: 8, 5, 0, 65
Reconn Version: 1.1.0.5 built by: WinDDK
MailProxy Version: 8, 5, 0, 20
AntiVirus Version: 8, 5, 0, 47
----[  Scan Parameters  ]------------
Folders to scan:
    None
Excluded folders:
    None
Files to scan:
    C:\WINDOWS\system32\xcnupgfc.exe
Scan type:
    [o] Scan all files
    [ ] Scan program files only
    [ ] Scan custom extensions:
    [ ] Exclude user extensions:
    [X] Scan boot sectors
    [X] Scan packed files
    [X] Scan archives
    [X] Scan emails
    [ ] Scan running processes
    [ ] Scan registry
    [ ] Scan IE cookies
    [X] Enable heuristic detection
    [ ] Scan default action
___________________________________________________________
Scan Statistics
___________________________________________________________
Scan started: Tuesday, October 07, 2008 17:43:35
Scan duration: 0 days, 00 hours, 00 minutes, 01 seconds
Completion status: Successful
Total files scanned: 6
Total files skipped: 0
Identified viruses: 0
Scan speed: 6.00 files/sec
___________________________________________________________
Results after ROUND 0
___________________________________________________________
Scan started: Tuesday, October 07, 2008 17:43:34
Scan duration: 0 days, 00 hours, 00 minutes, 01 seconds
Infections solved: 0
Infections left: 0
Viruses left: 0
 
 
 
___________________________________________________________
BullGuard Scan Report
Scan Profile: "~11"
___________________________________________________________

----[  System Info  ]------------
OS Version: Microsoft Windows XP Home Edition - Service Pack 3 (Build 2600) [2 * x86 CPUs]
Physical memory: 2040 MB
System up-time: 0 days, 03 hours, 35 minutes, 54 seconds
BullGuard up-time: 0 days, 03 hours, 34 minutes, 35 seconds
TopLayer Version: 8, 5, 0, 16
FileSpy5 Version: N/A
BdFileSpy Version: 3.12.0.62 built by: WinDDK
BsFileScan Version: 8, 5, 0, 65
Reconn Version: 1.1.0.5 built by: WinDDK
MailProxy Version: 8, 5, 0, 20
AntiVirus Version: 8, 5, 0, 47
----[  Scan Parameters  ]------------
Folders to scan:
    None
Excluded folders:
    None
Files to scan:
    C:\Documents and Settings\All Users\Application Data\ripqrspi\hgzsbgpy.exe
Scan type:
    [o] Scan all files
    [ ] Scan program files only
    [ ] Scan custom extensions:
    [ ] Exclude user extensions:
    [X] Scan boot sectors
    [X] Scan packed files
    [X] Scan archives
    [X] Scan emails
    [ ] Scan running processes
    [ ] Scan registry
    [ ] Scan IE cookies
    [X] Enable heuristic detection
    [ ] Scan default action
___________________________________________________________
Scan Statistics
___________________________________________________________
Scan started: Tuesday, October 07, 2008 17:43:55
Scan duration: 0 days, 00 hours, 00 minutes, 00 seconds
Completion status: Successful
Total files scanned: 3
Total files skipped: 0
Identified viruses: 0
Scan speed: 3.00 files/sec
___________________________________________________________
Results after ROUND 0
___________________________________________________________
Scan started: Tuesday, October 07, 2008 17:43:55
Scan duration: 0 days, 00 hours, 00 minutes, 00 seconds
Infections solved: 0
Infections left: 0
Viruses left: 0
 
Back to Top
 

Ryki
New Member


Date Joined Oct 2008
Total Posts : 5
 
   Posted 10-8-2008 8:08 (GMT +1)    Quote: I had 3 firewall requests and then an alert from Windows Security Center, need helpAlert an admin about: I had 3 firewall requests and then an alert from Windows Security Center, need help
nobody can help me? :(
Back to Top
 

Rysav
New Member


Date Joined Oct 2008
Total Posts : 1
 
   Posted 10-8-2008 11:11 (GMT +1)    Quote: I had 3 firewall requests and then an alert from Windows Security Center, need helpAlert an admin about: I had 3 firewall requests and then an alert from Windows Security Center, need help
I also have a suspicious application requesting network access. I have never seen it before and cannot find anything on the internet about it.

Its file name is 'dozenitg.exe'. It is located in 'C:\WINDOWS\system32\dozenitg.exe'
Its parent process is C:\WINDOWS\Explorer.exe

Lastly, the intersting part, its remote host is "ev1s-209-62-106-80.theplanet.com" - the same as yours as listed above. Theplanet.com is a hosting website, so obviously this file is doing something via a remote host.

I have a feeling this is a malicious application, but am not sure.
Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 16319
 
   Posted 10-9-2008 5:15 (GMT +1)    Quote: I had 3 firewall requests and then an alert from Windows Security Center, need helpAlert an admin about: I had 3 firewall requests and then an alert from Windows Security Center, need help
Hello smile
 
 
Sorry for late reply.
 
 
 
 
 
and save it on the desktop. Then double click on it (Fix_download.exe).
You may have to allow the program to download files from the web! 

The program download the necessary cleaning programs. Once the program 
is downloaded, there will be a folder on your desktop named 
Fix.   – if the instructions not automatically opens, so 
double-click "FIX_manual.htm" in Fix folder. 

Please follow the instructions and copy the logs here,
in this Topic:
 
Note : Fix_download.exe is detected by some antivirus programs  as a "RiskTool" /infection; it is not a virus. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user.

 

 If necessary, temporarily disable your anti-virus, real-time protection before downloading


Do NOT post your problem in someone elses thread.
A non-profit, volunteer network.

Back to Top
 

Ryki
New Member


Date Joined Oct 2008
Total Posts : 5
 
   Posted 10-9-2008 9:12 (GMT +1)    Quote: I had 3 firewall requests and then an alert from Windows Security Center, need helpAlert an admin about: I had 3 firewall requests and then an alert from Windows Security Center, need help
just had some action from No.1. Bullguard had this pop up:

virus: Trojan.AgentAKLT from xcnupgfc.exe

path: windows/system32
Back to Top
 

Ryki
New Member


Date Joined Oct 2008
Total Posts : 5
 
   Posted 10-9-2008 9:17 (GMT +1)    Quote: I had 3 firewall requests and then an alert from Windows Security Center, need helpAlert an admin about: I had 3 firewall requests and then an alert from Windows Security Center, need help
I have since zapped it! One more to go, I'll give that thing you suggested a whirl :D
Back to Top
 

Ryki
New Member


Date Joined Oct 2008
Total Posts : 5
 
   Posted 10-15-2008 8:37 (GMT +1)    Quote: I had 3 firewall requests and then an alert from Windows Security Center, need helpAlert an admin about: I had 3 firewall requests and then an alert from Windows Security Center, need help
all fixed, bullguard found them in the end!
Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 16319
 
   Posted 10-15-2008 9:53 (GMT +1)    Quote: I had 3 firewall requests and then an alert from Windows Security Center, need helpAlert an admin about: I had 3 firewall requests and then an alert from Windows Security Center, need help
Sounds good, it sounds like your problems are fixed ?


Do NOT post your problem in someone elses thread.
A non-profit, volunteer network.

Back to Top
 
New Topic Post reply to : I had 3 firewall requests and then an alert from Windows Security Center, need help Printable version of : I had 3 firewall requests and then an alert from Windows Security Center, need help
 
Forum Information
Currently it is Saturday, November 21, 2009 5:11 PM (GMT +1)
There are a total of 73.034 posts in 17.116 threads.
In the last 3 days there were 14 new threads and 69 reply posts. View Active Threads
Who's Online
This forum has 30334 registered members. Please welcome our newest member, sushil.
40 Guest(s), 0 Registered Member(s) are currently online.  Details
5 Latest Threads
Constant scanning andskipped files? (3)21-11-2009 14:33:51 (Dickens)
Cannot install anti-virus softeware or do window updates... need help (17)21-11-2009 13:46:11 (superjesse)
Michael Vick jerseys (1)21-11-2009 09:42:37 (Dickens)
Arizona Cardinals Jerseys (1)21-11-2009 09:37:23 (Dickens)
How to remove this Malware/Virus (0)21-11-2009 06:54:16 (bozzack)