Well before this happened I have got spyware/viruses or stuff and been able to clean it easily from programs. But whatever I got and how ever I got it which I dont know I cant get rid of no matter what program I use. Scans always find something and then I scan again and more stuff is there already. I get buffer over run things happening alot also from Microsoft Visual C++. The day it started I noticed 2 visual basic program icon things in my Windows Task Manager. I ended there process and since then.. My internet runs 15 times slower and sometimes doesnt work at all. I get loads of popups telling me I got a virus and to download the programs to clean it (I dont do that because a long time ago I tried one of them and it didnt work). Sometimes also while on the internet infinitely number of popups happen at once. The popups keep happening non stop and makes internet explorer take up like 600MB of memory by itself. I scanned with kasper and said 9 viruses found 20 files infected. Then did the search and destroy thing in safe mode and cleaned that and then did HiJack this in normal windows mode.
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Wednesday, April 02, 2008 7:23:49 AM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 2/04/2008
Kaspersky Anti-Virus database records: 677021
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
C:\
D:\
E:\
F:\
G:\
H:\
I:\
Scan Statistics:
Total number of scanned objects: 163513
Number of viruses found: 9
Number of infected objects: 28
Number of suspicious objects: 0
Duration of the scan process: 03:30:22
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\avg7\Log\emc.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log.lck Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinSmallazl.zip/mrofinu572.exe.tmp Infected: Trojan-Downloader.Win32.Homles.as skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinSmallazl.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinSmallazl1.zip/mrofinu572.exe Infected: Trojan-Downloader.Win32.Homles.as skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinSmallazl1.zip ZIP: infected - 1 skipped
C:\Documents and Settings\HP_Owner\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\HP_Owner\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\HP_Owner\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\HP_Owner\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\HP_Owner\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Documents and Settings\HP_Owner\Local Settings\Temporary Internet Files\Content.IE5\4HYOQJQ8\hctp[2] Object is locked skipped
C:\Documents and Settings\HP_Owner\Local Settings\Temporary Internet Files\Content.IE5\GHQ9YUA9\ptch[2] Object is locked skipped
C:\Documents and Settings\HP_Owner\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\HP_Owner\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\HP_Owner\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Program Files\mIRC\mirc.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.621 skipped
C:\Program Files\Mozilla Firefox\plugins\NPNd2fn.dll Infected: not-a-virus:AdTool.Win32.MyWebSearch.o skipped
C:\Program Files\SoftwareRevenue.org\2r_samba.exe/stream/data0006 Infected: not-a-virus:AdWare.Win32.Mostofate.e skipped
C:\Program Files\SoftwareRevenue.org\2r_samba.exe/stream Infected: not-a-virus:AdWare.Win32.Mostofate.e skipped
C:\Program Files\SoftwareRevenue.org\2r_samba.exe NSIS: infected - 2 skipped
C:\Program Files\TBONBin\TBONWnd.EXE Infected: not-a-virus:AdWare.Win32.BetterInternet.bd skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\VundoFix Backups\asnet.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\VundoFix Backups\eulabas.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\VundoFix Backups\ftpvga.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\VundoFix Backups\mfccat.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\system32\aqVreo01\aqVreo011065.exe Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\ddaba.dll Object is locked skipped
C:\WINDOWS\system32\drivers\core.cache.dsk Object is locked skipped
C:\WINDOWS\system32\drivers\vtminii.sys Object is locked skipped
C:\WINDOWS\system32\gebyw.dll Object is locked skipped
C:\WINDOWS\system32\IDME\dimnet201.exe Object is locked skipped
C:\WINDOWS\system32\ijjqmnai.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\WINDOWS\system32\jkkji.dll Object is locked skipped
C:\WINDOWS\system32\LogFiles\WUDF\WUDFTrace.etl Object is locked skipped
C:\WINDOWS\system32\mi1.exe/data0009/stream/data0006 Infected: not-a-virus:AdWare.Win32.Mostofate.e skipped
C:\WINDOWS\system32\mi1.exe/data0009/stream Infected: not-a-virus:AdWare.Win32.Mostofate.e skipped
C:\WINDOWS\system32\mi1.exe/data0009 Infected: not-a-virus:AdWare.Win32.Mostofate.e skipped
C:\WINDOWS\system32\mi1.exe NSIS: infected - 3 skipped
C:\WINDOWS\system32\mljhghh.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.lnz skipped
C:\WINDOWS\system32\mllji.dll Object is locked skipped
C:\WINDOWS\system32\mllmj.dll Object is locked skipped
C:\WINDOWS\system32\mllmk.dll Object is locked skipped
C:\WINDOWS\system32\nutms.exe Infected: not-a-virus:AdTool.Win32.WhenU.a skipped
C:\WINDOWS\system32\pmkjg.dll Object is locked skipped
C:\WINDOWS\system32\pmnlk.dll Object is locked skipped
C:\WINDOWS\system32\rqrpqqr.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.lnz skipped
C:\WINDOWS\system32\ssqrpol.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.lnz skipped
C:\WINDOWS\system32\sstqr.dll Object is locked skipped
C:\WINDOWS\system32\ssttr.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\WINDOWS\system32\sysutil.exe Infected: not-a-virus:AdTool.Win32.WhenU.a skipped
C:\WINDOWS\system32\ubhdmdvu.dll Object is locked skipped
C:\WINDOWS\system32\usnv\pax89104.exe/data0002 Infected: not-a-virus:AdWare.Win32.TTC.d skipped
C:\WINDOWS\system32\usnv\pax89104.exe NSIS: infected - 1 skipped
C:\WINDOWS\system32\vssdoc.exe Infected: not-a-virus:AdTool.Win32.WhenU.a skipped
C:\WINDOWS\system32\vturr.dll Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\system32\winz1\begmgr11.exe Object is locked skipped
C:\WINDOWS\system32\xTmp\v55api.exe Object is locked skipped
C:\WINDOWS\TinyBHO.dll Object is locked skipped
C:\WINDOWS\tk58.exe Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
Scan process completed.
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Wednesday, April 02, 2008 7:23:49 AM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 2/04/2008
Kaspersky Anti-Virus database records: 677021
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
C:\
D:\
E:\
F:\
G:\
H:\
I:\
Scan Statistics:
Total number of scanned objects: 163513
Number of viruses found: 9
Number of infected objects: 28
Number of suspicious objects: 0
Duration of the scan process: 03:30:22
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\avg7\Log\emc.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log.lck Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinSmallazl.zip/mrofinu572.exe.tmp Infected: Trojan-Downloader.Win32.Homles.as skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinSmallazl.zip ZIP: infected - 1 skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinSmallazl1.zip/mrofinu572.exe Infected: Trojan-Downloader.Win32.Homles.as skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinSmallazl1.zip ZIP: infected - 1 skipped
C:\Documents and Settings\HP_Owner\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\HP_Owner\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\HP_Owner\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\HP_Owner\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\HP_Owner\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Documents and Settings\HP_Owner\Local Settings\Temporary Internet Files\Content.IE5\4HYOQJQ8\hctp[2] Object is locked skipped
C:\Documents and Settings\HP_Owner\Local Settings\Temporary Internet Files\Content.IE5\GHQ9YUA9\ptch[2] Object is locked skipped
C:\Documents and Settings\HP_Owner\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\HP_Owner\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\HP_Owner\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Program Files\mIRC\mirc.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.621 skipped
C:\Program Files\Mozilla Firefox\plugins\NPNd2fn.dll Infected: not-a-virus:AdTool.Win32.MyWebSearch.o skipped
C:\Program Files\SoftwareRevenue.org\2r_samba.exe/stream/data0006 Infected: not-a-virus:AdWare.Win32.Mostofate.e skipped
C:\Program Files\SoftwareRevenue.org\2r_samba.exe/stream Infected: not-a-virus:AdWare.Win32.Mostofate.e skipped
C:\Program Files\SoftwareRevenue.org\2r_samba.exe NSIS: infected - 2 skipped
C:\Program Files\TBONBin\TBONWnd.EXE Infected: not-a-virus:AdWare.Win32.BetterInternet.bd skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\VundoFix Backups\asnet.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\VundoFix Backups\eulabas.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\VundoFix Backups\ftpvga.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\VundoFix Backups\mfccat.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\system32\aqVreo01\aqVreo011065.exe Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\ddaba.dll Object is locked skipped
C:\WINDOWS\system32\drivers\core.cache.dsk Object is locked skipped
C:\WINDOWS\system32\drivers\vtminii.sys Object is locked skipped
C:\WINDOWS\system32\gebyw.dll Object is locked skipped
C:\WINDOWS\system32\IDME\dimnet201.exe Object is locked skipped
C:\WINDOWS\system32\ijjqmnai.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\WINDOWS\system32\jkkji.dll Object is locked skipped
C:\WINDOWS\system32\LogFiles\WUDF\WUDFTrace.etl Object is locked skipped
C:\WINDOWS\system32\mi1.exe/data0009/stream/data0006 Infected: not-a-virus:AdWare.Win32.Mostofate.e skipped
C:\WINDOWS\system32\mi1.exe/data0009/stream Infected: not-a-virus:AdWare.Win32.Mostofate.e skipped
C:\WINDOWS\system32\mi1.exe/data0009 Infected: not-a-virus:AdWare.Win32.Mostofate.e skipped
C:\WINDOWS\system32\mi1.exe NSIS: infected - 3 skipped
C:\WINDOWS\system32\mljhghh.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.lnz skipped
C:\WINDOWS\system32\mllji.dll Object is locked skipped
C:\WINDOWS\system32\mllmj.dll Object is locked skipped
C:\WINDOWS\system32\mllmk.dll Object is locked skipped
C:\WINDOWS\system32\nutms.exe Infected: not-a-virus:AdTool.Win32.WhenU.a skipped
C:\WINDOWS\system32\pmkjg.dll Object is locked skipped
C:\WINDOWS\system32\pmnlk.dll Object is locked skipped
C:\WINDOWS\system32\rqrpqqr.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.lnz skipped
C:\WINDOWS\system32\ssqrpol.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.lnz skipped
C:\WINDOWS\system32\sstqr.dll Object is locked skipped
C:\WINDOWS\system32\ssttr.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.gen skipped
C:\WINDOWS\system32\sysutil.exe Infected: not-a-virus:AdTool.Win32.WhenU.a skipped
C:\WINDOWS\system32\ubhdmdvu.dll Object is locked skipped
C:\WINDOWS\system32\usnv\pax89104.exe/data0002 Infected: not-a-virus:AdWare.Win32.TTC.d skipped
C:\WINDOWS\system32\usnv\pax89104.exe NSIS: infected - 1 skipped
C:\WINDOWS\system32\vssdoc.exe Infected: not-a-virus:AdTool.Win32.WhenU.a skipped
C:\WINDOWS\system32\vturr.dll Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\system32\winz1\begmgr11.exe Object is locked skipped
C:\WINDOWS\system32\xTmp\v55api.exe Object is locked skipped
C:\WINDOWS\TinyBHO.dll Object is locked skipped
C:\WINDOWS\tk58.exe Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
Scan process completed.