PDA

View Full Version : System Startup in Spybot shows worms/trojans



ColoradoHermit
2007-10-29, 22:38
HELP! I'm all lost and confused here.:scratch: I'm running Window XP on a old Dell Optiplex GX240. Here's the problem running Spybot.
In advanced mode, tools, system startup it shows that I have an assortment of worms and trojans. There's one program listed that doesn't have a value or comand line and in the info for it there's a list of 7 different worms and trojans. But when I run a scan it doens't find anything. So is there something infecting my computer or not? The file listed is;
HK_LM;RunOnceEx and in the info it shows this list of file names that are trojans or worms; system32.exe AGOBOT-KU WORM, pathex.exe MKMOOSE-A WORM, svchost.exe DELF-UX TROJAN, MSPF.EXE SDBOT WORM, dllvirtual.exe DADOBRA-IW TROJAN, dllvirtual.dll DADOBRA-IW TROJAN, dllvirtual.js DADOBRA-IW TROJAN.
So em I infected? If so, since the Spybot program didn't find anything in the scan how do I get rid of them or fix things?
My computer has been acting funky and slow for about a week. Ever since I test drove the new Window Live OneCare Antivirus and Firewall program. I thought I would try there free 3 month test drive. And that screwed things up big time. It took me 3 days to get rid of it and get things running again but something still isn't right. And that new Windows program said that it found a big list of worms too that my McAfee and AVG and Spybot missed. Here's the list of what the Windows OneCare said it found, Win32/Netsky.C@mm worm, Win32/Bagle.O@mm worm, Win32/Netsky.P@mm worm, Win32/Netsky.K@mm worm, Win32/Netsky.D@mm worm, Win32/Netsky.Z@mm worm, Bagle.J@mm worm, Sober.G@mm worm.
Now the windows onecare said it fix all those, but I don't know. So any one got any idea what this thing is doing?

spybotsandra
2007-10-29, 23:02
Hello,

When nothing is found in a scan then you are not infected. The startup should show you that also windows files could be infected if the exe or dll files are stored at the wrong place.
But yours seem to be usual windows files.
For example: The Svchost.exe file is located in the %SystemRoot%\System32 folder. At startup, Svchost.exe checks the services part of the registry to construct a list of services that it must load:
http://support.microsoft.com/?scid=kb%3Ben-us%3B314056&x=15&y=7

The information from Paul Collins' Startup list is static information to help you decide the validity of the entry.
There is no scan involved to actually determine if your particular entry is good or bad.

You can find Paul Collins' Startup list here:
Startup Applications List
http://www.sysinfo.org/startuplist.php

Best regards
Sandra
Team Spybot