hi all - new install of XP Pro and downloaded SP2 all updates. PC running fine for a week as a media server (aud/vid). Browsing with IE6 and got infected. Used AVG and hijack this repeatedly from safe mode and regular mode to clean - no specific threats named, but a lot of misc named dll and BHO etc.
Currently, pc runs fine, but
1) whenever i try to use IE it throws adware and reinstalls more malware, and
2) two unknown dll's in system32 that i can't stop or remove. They don't show up in services, but they show as in use whenever i try to delete, even in safe mode. no unknown services running.
3) windows update will not run properly (hangs)
4) blocked from running external pc scan (panda etc)
4) IE6 showing "cox" cable icon in upper right (wouldn't mind losing that, and not sure how it's there without being in hijackthis bho)
any thoughts appreciated!!
HijackThis log, with 4 unknown files after (can't delete dlls, ini files keep reappearing)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:17:11 PM, on 4/27/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.e
xe
C:\WINDOWS\system32\winlog
on.exe
C:\WINDOWS\system32\servic
es.exe
C:\WINDOWS\system32\lsass.
exe
C:\WINDOWS\system32\svchos
t.exe
C:\WINDOWS\System32\svchos
t.exe
C:\WINDOWS\system32\spools
v.exe
C:\WINDOWS\Explorer.EXE
C:\program files\powerstrip\pstrip.ex
e
C:\PROGRA~1\Grisoft\AVG7\a
vgcc.exe
C:\Program Files\Belkin\USB F5D7050\Wireless Utility\Belkinwcui.exe
C:\WINDOWS\system32\taskmg
r.exe
C:\PROGRA~1\Grisoft\AVG7\a
vgamsvr.ex
e
C:\PROGRA~1\Grisoft\AVG7\a
vgupsvc.ex
e
C:\PROGRA~1\Grisoft\AVG7\a
vgrssvc.ex
e
C:\PROGRA~1\Grisoft\AVG7\a
vgrssvc.ex
e
C:\PROGRA~1\Grisoft\AVG7\a
vgemc.exe
C:\WINDOWS\system32\wuaucl
t.exe
C:\WINDOWS\system32\wuaucl
t.exe
C:\Program Files\Trend Micro\HijackThis\HijackThi
s.exe
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [PowerStrip] c:\program files\powerstrip\pstrip.ex
e
O4 - HKLM\..\Run: [StormCodec_Helper] "C:\Program Files\Ringz Studio\Storm Codec\StormSet.exe" /S /opti
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\a
vgcc.exe /STARTUP
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\a
vgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\a
vgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\a
vgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\a
vgw.exe /RUNONCE (User 'Default user')
O4 - Global Startup: Belkin Wireless USB Utility.lnk = C:\Program Files\Belkin\USB F5D7050\Wireless Utility\Belkinwcui.exe
O4 - Global Startup: Shortcut to taskmgr.lnk = C:\WINDOWS\system32\taskmg
r.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\a
vgamsvr.ex
e
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\a
vgupsvc.ex
e
O23 - Service: AVG7 Resident Shield Service (AvgCoreSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\a
vgrssvc.ex
e
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\a
vgemc.exe
--
End of file - 2370 bytes
unknown files:
lkUvDjlm.ini
lkUvDjlm.ini2
mlJDvUkl.dll
xxywvWOi.dll
Start Free Trial