PDA

View Full Version : Full o' worms



willywonka
2008-12-13, 17:39
I have read the posts on this and would like to ask for help.....
I have Avast running on my computer but it doesn't rid me of the problems that I have already. I ran the Kaspersky scan and HJT.
Please find the help I need....Multiple infections don't know where to start...

--------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7 REPORT
Saturday, December 13, 2008
Operating System: Microsoft Windows XP Professional Service Pack 2 (build 2600)
Kaspersky Online Scanner 7 version: 7.0.25.0
Program database last update: Friday, December 12, 2008 23:26:44
Records in database: 1456259
--------------------------------------------------------------------------------

Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes

Scan area - My Computer:
C:\
D:\

Scan statistics:
Files scanned: 147436
Threat name: 10
Infected objects: 13
Suspicious objects: 0
Duration of the scan: 02:05:44


File name / Threat name / Threats count
C:\WINDOWS\system\VMwareService.exe/C:\WINDOWS\system\VMwareService.exe Infected: Backdoor.Win32.Rbot.wim 1
C:\Documents and Settings\lindsey\Local Settings\Temp\gettpa223.exe Infected: not-a-virus:AdWare.Win32.Agent.gnd 1
C:\Documents and Settings\lindsey\Local Settings\Temp\n2ewsys.exe Infected: not-a-virus:AdWare.Win32.WebHancer.f 1
C:\Documents and Settings\lindsey\Local Settings\Temp\n2ewsys.exe Infected: not-a-virus:AdWare.Win32.WebHancer.390 1
C:\Documents and Settings\lindsey\My Documents\My Music\instrumental horns.mp3 Infected: Trojan-Downloader.WMA.GetCodec.c 1
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\42HTVVGI\extest[1].jpg Infected: Trojan.Win32.Slefdel.bzg 1
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\42HTVVGI\pzkbucgf[1].jpg Infected: Net-Worm.Win32.Kido.al 1
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\45QROPAZ\y[1].txt Infected: Backdoor.Win32.Rbot.wim 1
C:\Program Files\Alwil Software\Avast4\DATA\moved\csrsc.exe.vir Infected: Worm.Win32.AutoRun.tet 1
C:\WINDOWS\SYSTEM\VMwareService.exe Infected: Backdoor.Win32.Rbot.wim 1
C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\8DARKL23\msusc[1].bin Infected: Trojan-Downloader.Win32.Murlo.uk 1
C:\WINDOWS\SYSTEM32\gqebqc.dll Infected: Net-Worm.Win32.Kido.al 1
C:\WINDOWS\SYSTEM32\wpv173.cpx Infected: not-a-virus:AdWare.Win32.Agent.fyz 1

The selected area was scanned.

--------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7 REPORT
Saturday, December 13, 2008
Operating System: Microsoft Windows XP Professional Service Pack 2 (build 2600)
Kaspersky Online Scanner 7 version: 7.0.25.0
Program database last update: Friday, December 12, 2008 23:26:44
Records in database: 1456259
--------------------------------------------------------------------------------

Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes

Scan area - Critical Areas:
C:\Documents and Settings\All Users\Start Menu\Programs\Startup
C:\Documents and Settings\lindsey\Start Menu\Programs\Startup
C:\Program Files
C:\WINDOWS

Scan statistics:
Files scanned: 105783
Threat name: 5
Infected objects: 5
Suspicious objects: 0
Duration of the scan: 02:25:23


File name / Threat name / Threats count
C:\Program Files\Alwil Software\Avast4\DATA\moved\csrsc.exe.vir Infected: Worm.Win32.AutoRun.tet 1
C:\WINDOWS\SYSTEM\VMwareService.exe Infected: Backdoor.Win32.Rbot.wim 1
C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\8DARKL23\msusc[1].bin Infected: Trojan-Downloader.Win32.Murlo.uk 1
C:\WINDOWS\SYSTEM32\gqebqc.dll Infected: Net-Worm.Win32.Kido.al 1
C:\WINDOWS\SYSTEM32\wpv173.cpx Infected: not-a-virus:AdWare.Win32.Agent.fyz 1

The selected area was scanned.

tashi
2008-12-13, 18:28
Hello,

Please see the stickied procedure for this forum: "BEFORE you POST"(READ this Procedure BEFORE Requesting Assistance) (http://forums.spybot.info/showthread.php?t=288)

Start a new topic providing the HJT log, this one has been closed as helpers look for threads without a response.

Regards.