Hello,
I'm running windows xp sp2 and internet explorer 6.
Have recently been infected with several virus / trojan malware. Several to list but some of them were:
generic3, generic6, zlob, and vundo.
Researched the internet and followed some advice found there. So far I have run:
AVG free
Vundofix
Ad-aware
CounterSpy
Spybot
VirtumundoBeGone
CWshredder
Rogue Remover
Sometimes one of these will find something...sometimes not. I've been running them all and trying to delete things through them, and manually when necessary.
I just found about HijackThis and have run it just now. What I have is this:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:42:50 AM, on 2/25/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.e
xe
C:\WINDOWS\system32\winlog
on.exe
C:\WINDOWS\system32\servic
es.exe
C:\WINDOWS\system32\lsass.
exe
C:\WINDOWS\system32\svchos
t.exe
C:\WINDOWS\System32\svchos
t.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spools
v.exe
C:\WINDOWS\Explorer.EXE
C:\apache2triad\bin\httpd.
exe
C:\PROGRA~1\Grisoft\AVG7\a
vgamsvr.ex
e
C:\PROGRA~1\Grisoft\AVG7\a
vgupsvc.ex
e
C:\PROGRA~1\Grisoft\AVG7\a
vgemc.exe
C:\WINDOWS\System32\spool\
DRIVERS\W3
2X86\3\OPH
ALDCS.EXE
C:\apache2triad\mysql\bin\
mysqld.exe
C:\Program Files\Sunbelt Software\CounterSpy\SBCSSv
c.exe
C:\apache2triad\mail\bin\X
Mail.exe
C:\apache2triad\bin\httpd.
exe
C:\PROGRA~1\Grisoft\AVG7\a
vgcc.exe
C:\WINDOWS\system32\hkcmd.
exe
C:\Program Files\Sunbelt
Software\CounterSpy\SBCSTr
ay.exe
C:\WINDOWS\System32\svchos
t.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThi
s.exe
O2 - BHO: (no name) -
{1633C7B8-5923-0FF0-0211-5
D00BBBD8DC
9} - (no file)
O2 - BHO: Spybot-S&D IE Protection -
{53707962-6F74-2D53-2644-2
06D7942484
F} -
C:\PROGRA~1\SPYBOT~1\SDHel
per.dll
O2 - BHO: (no name) -
{63E1B5B1-99D6-47C1-A839-3
809E790193
F} - (no file)
O2 - BHO: (no name) -
{6E60560C-7993-4EC8-8B9E-4
D0F5A8BFB0
3} - (no file)
O2 - BHO: 0 - {8C52C162-6543-4038-2C9E-A
6EF82107F1
2} -
(no file)
O2 - BHO: (no name) -
{a6d063c2-9787-474c-be1f-a
c594b3d140
3} - (no file)
O2 - BHO: (no name) -
{D85530E8-D39D-49D0-9F36-3
00D594556D
2} - (no file)
O4 - HKLM\..\Run: [IgfxTray]
C:\WINDOWS\system32\igfxtr
ay.exe
O4 - HKLM\..\Run: [HotKeysCmds]
C:\WINDOWS\system32\hkcmd.
exe
O4 - HKLM\..\Run: [SBCSTray] C:\Program Files\Sunbelt
Software\CounterSpy\SBCSTr
ay.exe
O4 - HKLM\..\Run: [KernelFaultCheck]
%systemroot%\system32\dump
rep 0 -k
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run]
C:\PROGRA~1\Grisoft\AVG7\a
vgw.exe /RUNONCE (User
'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run]
C:\PROGRA~1\Grisoft\AVG7\a
vgw.exe /RUNONCE (User
'Default user')
O9 - Extra button: (no name) -
{DFB852A3-47F8-48C4-A200-5
8CAB36FD2A
2} -
C:\PROGRA~1\SPYBOT~1\SDHel
per.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy
Configuration - {DFB852A3-47F8-48C4-A200-5
8CAB36FD2A
2} -
C:\PROGRA~1\SPYBOT~1\SDHel
per.dll
O9 - Extra button: eBay - Homepage -
{EF79EAC5-3452-4E02-B8BD-B
A4C89F1AC7
A} - C:\Program
Files\IrfanView\Ebay\Ebay.
htm
O9 - Extra button: Messenger -
{FB5F1910-F110-11d2-BB9E-0
0C04F79568
3} - C:\Program
Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger -
{FB5F1910-F110-11d2-BB9E-0
0C04F79568
3} - C:\Program
Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.amaena.com
O15 - Trusted Zone: *.avsystemcare.com
O15 - Trusted Zone: *.gomyhit.com
O15 - Trusted Zone: *.imageservr.com
O15 - Trusted Zone: *.imagesrvr.com
O15 - Trusted Zone: *.onerateld.com
O15 - Trusted Zone: *.safetydownload.com
O15 - Trusted Zone: *.storageguardsoft.com
O15 - Trusted Zone: *.trustedantivirus.com
O15 - Trusted Zone: *.virusschlacht.com
O15 - Trusted Zone: *.amaena.com (HKLM)
O15 - Trusted Zone: *.avsystemcare.com (HKLM)
O15 - Trusted Zone: *.gomyhit.com (HKLM)
O15 - Trusted Zone: *.imageservr.com (HKLM)
O15 - Trusted Zone: *.imagesrvr.com (HKLM)
O15 - Trusted Zone: *.onerateld.com (HKLM)
O15 - Trusted Zone: *.safetydownload.com (HKLM)
O15 - Trusted Zone: *.storageguardsoft.com (HKLM)
O15 - Trusted Zone: *.trustedantivirus.com (HKLM)
O15 - Trusted Zone: *.virusschlacht.com (HKLM)
O23 - Service: Ad-Aware 2007 Service (aawservice) -
Lavasoft - C:\Program Files\Lavasoft\Ad-Aware
2007\aawservice.exe
O23 - Service: Apache2Triad Apache2 Service (Apache2) -
Apache Software Foundation -
C:\apache2triad\bin\httpd.
exe
O23 - Service: Apache2Triad Apache2 Service with SSL
(Apache2SSL) - Apache Software Foundation -
C:\apache2triad\bin\httpd.
exe
O23 - Service: Apache2Triad MySql Service (MySql) -
Unknown owner - C:\apache2triad\mysql\bin\
mysqld.exe
O23 - Service: Apache2Triad PostgreSQL Service (PgSql) -
PostgreSQL Global Development Group -
C:\apache2triad\pgsql\bin\
pg_ctl.exe
O23 - Service: Sunbelt CounterSpy Antispyware (SBCSSvc)
- Sunbelt Software - C:\Program Files\Sunbelt
Software\CounterSpy\SBCSSv
c.exe
O23 - Service: Apache2Triad Xmail Service (XMail) -
Unknown owner - C:\apache2triad\mail\bin\X
Mail.exe
O24 - Desktop Component 0: (no name) -
http://www.natlpaintequip.com/images/white.jpg--
End of file - 4626 bytes
All I can say is that I hope this makes sense to someone...because it's unclear to me. The only thing I found odd was the number of entries in "trusted zone". I'm not sure what they are and certainly don't remember adding that many myself.
I appreciate any assistance you can offer.
Regards,
Tony
Start Free Trial