Please Help!

Hello! I'm not an expert in computers, and surely a beginner in fighting viruses. I have troubles with: Worm/VB.COX; Win32.Worm.IM.Sohanat.B; Exploit.ADODB.Stream.DC. Honestly I know allmost nothing about this viruses, but I cannot wipe them away. I've tried with AVG and BitDefender 8 Professional Plus, wich wiped them away, but they reappear. What can I do? I cannot change the home internet page. When I sign in at Yahoo Messenger, the virus sends messages with infected websites to my friends list... How bad are these viruses for my computer? When the files have been moved to the Quarantine in BeatDefender as infected should I click the delete button? Can BeatDefender work properly if AVG is still instaled and working? Sorry for all these many questions... but I think you can help me! Thank you!

Comments

  • Hello,


    you can't have two real-time antivirus scanners installed at the same time, that causes problems. Why are you still using BitDefender 8, that's too old? I suggest that you run the BitDefender online scanner, it's very good at cleaning viruses.


    http://www.bitdefender.com/scan8/ie.html

  • Hello! I have tried the online antivirus and the files were deleted. Still I find them again in the computer. I cannot change the start web site. It's www.uklottery.com or something like that. I have problems with a file called SWCHOST.exe The virus didn't disappear. What can I do? Thanks again!


    Can this scan report help you?


    <HTML>


    <HEAD>


    <TITLE>BitDefender Online Scanner -Scan Report</TITLE>


    <META HTTP-EQUIV="Content-Type" CONTENT="text/html; charset=iso-8859-1">


    <meta name="generator" content="Namo WebEditor v5.0(Trial)">


    </HEAD>


    <BODY BGCOLOR=#FFFFFF leftmargin="10" marginwidth="0" topmargin="20" marginheight="0" >


    <table align="center" border="0" cellpadding="0" cellspacing="0" width="90%">


    <tr>


    <td width="458">


    <p><font face="Arial" color=red><span style="font-size:14pt;"><b>BitDefender


    Online Scanner</b></span></font></p>


    </td>


    <td width="40%">


    <p> </p>


    </td>


    <td width="10%">


    <p> </p>


    </td>


    </tr>


    <tr>


    <td colspan="3" width="912">


    <p><font face="Arial"><span style="font-size:11pt;"><B>Scan report generated


    at: Fri, Nov 30, 2007 - 22:34:55</b></span></font></p>


    </td>


    </tr>


    <tr>


    <td width="458">


    <p><font face="Arial"><span style="font-size:11pt;"><B> </b></span></font></p>


    </td>


    <td width="40%">


    <p> </p>


    </td>


    <td width="10%">


    <p> </p>


    </td>


    </tr>


    <tr>


    <td width="458">


    <p><font face="Arial"><span style="font-size:11pt;"><B>Scan


    path: </b></span><span style="font-size:10pt;">A:\;C:\;D:\;E:\;F:\;G:\;</span></font></p>


    </td>


    <td width="40%">


    <p> </p>


    </td>


    <td width="10%">


    <p> </p>


    </td>


    </tr>


    <tr>


    <td width="458">


    <p><font face="Arial"><span style="font-size:11pt;"><B> </b></span></font></p>


    </td>


    <td width="40%">


    <p> </p>


    </td>


    <td width="10%">


    <p> </p>


    </td>


    </tr>


    <tr>


    <td width="458">


    <table border="1" cellspacing="0" bordercolordark="white" bordercolorlight="black" width="100%">


    <tr>


    <td width="451" colspan="2" bgcolor="#CCCCCC">


    <p><font face="Arial" size="2"><B>Statistics</b></font></p>


    </td>


    </tr>


    <tr>


    <td width="57%">


    <p><font face="Arial" size="2">Time</font></p>


    </td>


    <td width="43%" align="right">


    <p><font face="Arial" size="2">03:04:29</font></p>


    </td>


    </tr>


    <tr>


    <td width="57%">


    <p><font face="Arial" size="2">Files</font></p>


    </td>


    <td width="43%" align="right">


    <p><font face="Arial" size="2">349978</font></p>


    </td>


    </tr>


    <tr>


    <td width="57%">


    <p><font face="Arial" size="2">Folders</font></p>


    </td>


    <td width="43%" align="right">


    <p><font face="Arial" size="2">11021</font></p>


    </td>


    </tr>


    <tr>


    <td width="57%">


    <p><font face="Arial" size="2">Boot Sectors</font></p>


    </td>


    <td width="43%" align="right">


    <p><font face="Arial" size="2">3</font></p>


    </td>


    </tr>


    <tr>


    <td width="57%">


    <p><font face="Arial" size="2">Archives</font></p>


    </td>


    <td width="43%" align="right">


    <p><font face="Arial" size="2">3410</font></p>


    </td>


    </tr>


    <tr>


    <td width="57%">


    <p><font face="Arial" size="2">Packed Files</font></p>


    </td>


    <td width="43%" align="right">


    <p><font face="Arial" size="2">18850</font></p>


    </td>


    </tr>


    </table>


    </td>


    <td width="40%">


    <p> </p>


    </td>


    <td width="10%">


    <p> </p>


    </td>


    </tr>


    <tr>


    <td width="458">


    <table border="1" cellspacing="0" bordercolordark="white" bordercolorlight="black" width="100%">


    <tr>


    <td width="451" colspan="2" bgcolor="#CCCCCC">


    <p><font face="Arial" size="2"><B>Results</b></font></p>


    </td>


    </tr>


    <tr>


    <td width="57%">


    <p><font face="Arial" size="2">Identified Viruses </font></p>


    </td>


    <td width="43%" align="right">


    <p><font face="Arial" size="2">4</font></p>


    </td>


    </tr>


    <tr>


    <td width="57%">


    <p><font face="Arial" size="2">Infected Files </font></p>


    </td>


    <td width="43%" align="right">


    <p><font face="Arial" size="2">7</font></p>


    </td>


    </tr>


    <tr>


    <td width="57%">


    <p><font face="Arial" size="2">Suspect Files </font></p>


    </td>


    <td width="43%" align="right">


    <p><font face="Arial" size="2">0</font></p>


    </td>


    </tr>


    <tr>


    <td width="57%">


    <p><font face="Arial" size="2">Warnings</font></p>


    </td>


    <td width="43%" align="right">


    <p><font face="Arial" size="2">0</font></p>


    </td>


    </tr>


    <tr>


    <td width="57%">


    <p><font face="Arial" size="2">Disinfected</font></p>


    </td>


    <td width="43%" align="right">


    <p><font face="Arial" size="2">0</font></p>


    </td>


    </tr>


    <tr>


    <td width="57%">


    <p><font face="Arial" size="2">Deleted Files</font></p>


    </td>


    <td width="43%" align="right">


    <p><font face="Arial" size="2">8</font></p>


    </td>


    </tr>


    </table>


    </td>


    <td width="40%">


    <p> </p>


    </td>


    <td width="10%">


    <p> </p>


    </td>


    </tr>


    <tr>


    <td width="458">


    <table border="1" cellspacing="0" bordercolordark="white" bordercolorlight="black" width="100%">


    <tr>


    <td width="451" colspan="2" bgcolor="#CCCCCC">


    <p><font face="Arial" size="2"><B>Engines Info</b></font></p>


    </td>


    </tr>


    <tr>


    <td width="57%">


    <p><font face="Arial" size="2">Virus Definitions</font></p>


    </td>


    <td width="43%" align="right">


    <p><font face="Arial" size="2">879615</font></p>


    </td>


    </tr>


    <tr>


    <td width="57%">


    <p><font face="Arial" size="2">Engine build</font></p>


    </td>


    <td width="43%" align="right">


    <p><font face="Arial" size="2">AVCORE v1.0 (build 2422) (i386) (Sep 25 2007 08:26:36)</font></p>


    </td>


    </tr>


    <tr>


    <td width="57%">


    <p><font face="Arial" size="2">Scan plugins</font></p>


    </td>


    <td width="43%" align="right">


    <p><font face="Arial" size="2">14</font></p>


    </td>


    </tr>


    <tr>


    <td width="57%">


    <p><font face="Arial" size="2">Archive plugins</font></p>


    </td>


    <td width="43%" align="right">


    <p><font face="Arial" size="2">38</font></p>


    </td>


    </tr>


    <tr>


    <td width="57%">


    <p><font face="Arial" size="2">Unpack plugins</font></p>


    </td>


    <td width="43%" align="right">


    <p><font face="Arial" size="2">7</font></p>


    </td>


    </tr>


    <tr>


    <td width="57%">


    <p><font face="Arial" size="2">E-mail plugins</font></p>


    </td>


    <td width="43%" align="right">


    <p><font face="Arial" size="2">6</font></p>


    </td>


    </tr>


    <tr>


    <td width="57%">


    <p><font face="Arial" size="2">System plugins</font></p>


    </td>


    <td width="43%" align="right">


    <p><font face="Arial" size="2">1</font></p>


    </td>


    </tr>


    </table>


    </td>


    <td width="40%">


    <p> </p>


    </td>


    <td width="10%">


    <p> </p>


    </td>


    </tr>


    <tr>


    <td width="458">


    <table border="1" cellspacing="0" bordercolordark="white" bordercolorlight="black" width="100%">


    <tr>


    <td width="451" colspan="2" bgcolor="#CCCCCC">


    <p><font face="Arial" size="2"><B>Scan Settings</b></font></p>


    </td>


    </tr>


    <tr>


    <td width="57%">


    <p><font face="Arial" size="2">First Action</font></p>


    </td>


    <td width="43%" align="right">


    <p><font face="Arial" size="2">Disinfect</font></p>


    </td>


    </tr>


    <tr>


    <td width="57%">


    <p><font face="Arial" size="2">Second Action</font></p>


    </td>


    <td width="43%" align="right">


    <p><font face="Arial" size="2">Delete</font></p>


    </td>


    </tr>


    <tr>


    <td width="57%">


    <p><font face="Arial" size="2">Heuristics</font></p>


    </td>


    <td width="43%" align="right">


    <p><font face="Arial" size="2">Yes</font></p>


    </td>


    </tr>


    <tr>


    <td width="57%">


    <p><font face="Arial" size="2">Enable Warnings</font></p>


    </td>


    <td width="43%" align="right">


    <p><font face="Arial" size="2">Yes</font></p>


    </td>


    </tr>


    <tr>


    <td width="57%">


    <p><font face="Arial" size="2">Scanned Extensions</font></p>


    </td>


    <td width="43%" align="right">


    <p><font face="Arial" size="2">*;</font></p>


    </td>


    </tr>


    <tr>


    <td width="57%">


    <p><font face="Arial" size="2">Exclude Extensions</font></p>


    </td>


    <td width="43%" align="right">


    <p><font face="Arial" size="2"> </font></p>


    </td>


    </tr>


    <tr>


    <td width="57%">


    <p><font face="Arial" size="2">Scan Emails</font></p>


    </td>


    <td width="43%" align="right">


    <p><font face="Arial" size="2">Yes</font></p>


    </td>


    </tr>


    <tr>


    <td width="57%">


    <p><font face="Arial" size="2">Scan Archives</font></p>


    </td>


    <td width="43%" align="right">


    <p><font face="Arial" size="2">Yes</font></p>


    </td>


    </tr>


    <tr>


    <td width="57%">


    <p><font face="Arial" size="2">Scan Packed</font></p>


    </td>


    <td width="43%" align="right">


    <p><font face="Arial" size="2">Yes</font></p>


    </td>


    </tr>


    <tr>


    <td width="57%">


    <p><font face="Arial" size="2">Scan Files</font></p>


    </td>


    <td width="43%" align="right">


    <p><font face="Arial" size="2">Yes</font></p>


    </td>


    </tr>


    <tr>


    <td width="57%">


    <p><font face="Arial" size="2">Scan Boot</font></p>


    </td>


    <td width="43%" align="right">


    <p><font face="Arial" size="2">Yes</font></p>


    </td>


    </tr>


    </table>


    </td>


    <td width="40%">


    <p> </p>


    </td>


    <td width="10%">


    <p> </p>


    </td>


    </tr>


    <tr>


    <td colspan=2>  


    <table border="1" cellspacing="0" bordercolordark="white" bordercolorlight="black" width="100%">


    <tr>


    <td width="252" bgcolor="#CCCCCC">


    <p><font face="Arial" size="2"><B>Scanned File</b></font></p>


    </td>


    <td width="195" bgcolor="#CCCCCC" align="right">


    <p align="left"><b><font size="2" face="Arial"> Status</font></b></p>


    </td>


    </tr>


    <tr>


    <td width="57%">


    <p><font face="Arial" size="2">C:\Documents and Settings\Gabi\Local Settings\Temp\SVCHOST.EXE=>(AutoIT)</font></p>


    </td>


    <td width="43%" align="left">


    <p><font face="Arial" size="2">Infected with: Win32.Worm.IM.Sohanat.B</font></p>


    </td>


    </tr><tr>


    <td width="57%">


    <p><font face="Arial" size="2">C:\Documents and Settings\Gabi\Local Settings\Temp\SVCHOST.EXE=>(AutoIT)</font></p>


    </td>


    <td width="43%" align="left">


    <p><font face="Arial" size="2">Disinfection failed</font></p>


    </td>


    </tr><tr>


    <td width="57%">


    <p><font face="Arial" size="2">C:\Documents and Settings\Gabi\Local Settings\Temp\SVCHOST.EXE=>(AutoIT)</font></p>


    </td>


    <td width="43%" align="left">


    <p><font face="Arial" size="2">Deleted</font></p>


    </td>


    </tr><tr>


    <td width="57%">


    <p><font face="Arial" size="2">C:\Documents and Settings\Gabi\Local Settings\Temporary Internet Files\Content.IE50BX6P8X\index[2].htm</font></p>


    </td>


    <td width="43%" align="left">


    <p><font face="Arial" size="2">Infected with: Exploit.ADODB.Stream.DC</font></p>


    </td>


    </tr><tr>


    <td width="57%">


    <p><font face="Arial" size="2">C:\Documents and Settings\Gabi\Local Settings\Temporary Internet Files\Content.IE50BX6P8X\index[2].htm</font></p>


    </td>


    <td width="43%" align="left">


    <p><font face="Arial" size="2">Disinfection failed</font></p>


    </td>


    </tr><tr>


    <td width="57%">


    <p><font face="Arial" size="2">C:\Documents and Settings\Gabi\Local Settings\Temporary Internet Files\Content.IE50BX6P8X\index[2].htm</font></p>


    </td>


    <td width="43%" align="left">


    <p><font face="Arial" size="2">Deleted</font></p>


    </td>


    </tr><tr>


    <td width="57%">


    <p><font face="Arial" size="2">C:\Documents and Settings\Gabi\Local Settings\Temporary Internet Files\Content.IE5\3WHLY0YT\popup[1].htm</font></p>


    </td>


    <td width="43%" align="left">


    <p><font face="Arial" size="2">Infected with: Trojan.Clicker.CM</font></p>


    </td>


    </tr><tr>


    <td width="57%">


    <p><font face="Arial" size="2">C:\Documents and Settings\Gabi\Local Settings\Temporary Internet Files\Content.IE5\3WHLY0YT\popup[1].htm</font></p>


    </td>


    <td width="43%" align="left">


    <p><font face="Arial" size="2">Disinfection failed</font></p>


    </td>


    </tr><tr>


    <td width="57%">


    <p><font face="Arial" size="2">C:\Documents and Settings\Gabi\Local Settings\Temporary Internet Files\Content.IE5\3WHLY0YT\popup[1].htm</font></p>


    </td>


    <td width="43%" align="left">


    <p><font face="Arial" size="2">Deleted</font></p>


    </td>


    </tr><tr>


    <td width="57%">


    <p><font face="Arial" size="2">C:\Documents and Settings\Gabi\Local Settings\Temporary Internet Files\Content.IE5\YHRYKCG2\exe[1]</font></p>


    </td>


    <td width="43%" align="left">


    <p><font face="Arial" size="2">Infected with: Trojan.PWS.Zbot.E</font></p>


    </td>


    </tr><tr>


    <td width="57%">


    <p><font face="Arial" size="2">C:\Documents and Settings\Gabi\Local Settings\Temporary Internet Files\Content.IE5\YHRYKCG2\exe[1]</font></p>


    </td>


    <td width="43%" align="left">


    <p><font face="Arial" size="2">Disinfection failed</font></p>


    </td>


    </tr><tr>


    <td width="57%">


    <p><font face="Arial" size="2">C:\Documents and Settings\Gabi\Local Settings\Temporary Internet Files\Content.IE5\YHRYKCG2\exe[1]</font></p>


    </td>


    <td width="43%" align="left">


    <p><font face="Arial" size="2">Deleted</font></p>


    </td>


    </tr><tr>


    <td width="57%">


    <p><font face="Arial" size="2">C:\Documents and Settings\Gabi\Local Settings\Temporary Internet Files\Content.IE5\YHRYKCG2\YM[1].exe=>(AutoIT)</font></p>


    </td>


    <td width="43%" align="left">


    <p><font face="Arial" size="2">Infected with: Win32.Worm.IM.Sohanat.B</font></p>


    </td>


    </tr><tr>


    <td width="57%">


    <p><font face="Arial" size="2">C:\Documents and Settings\Gabi\Local Settings\Temporary Internet Files\Content.IE5\YHRYKCG2\YM[1].exe=>(AutoIT)</font></p>


    </td>


    <td width="43%" align="left">


    <p><font face="Arial" size="2">Disinfection failed</font></p>


    </td>


    </tr><tr>


    <td width="57%">


    <p><font face="Arial" size="2">C:\Documents and Settings\Gabi\Local Settings\Temporary Internet Files\Content.IE5\YHRYKCG2\YM[1].exe=>(AutoIT)</font></p>


    </td>


    <td width="43%" align="left">


    <p><font face="Arial" size="2">Deleted</font></p>


    </td>


    </tr><tr>


    <td width="57%">


    <p><font face="Arial" size="2">C:\tmp03sz.exe</font></p>


    </td>


    <td width="43%" align="left">


    <p><font face="Arial" size="2">Infected with: Trojan.PWS.Zbot.E</font></p>


    </td>


    </tr><tr>


    <td width="57%">


    <p><font face="Arial" size="2">C:\tmp03sz.exe</font></p>


    </td>


    <td width="43%" align="left">


    <p><font face="Arial" size="2">Disinfection failed</font></p>


    </td>


    </tr><tr>


    <td width="57%">


    <p><font face="Arial" size="2">C:\tmp03sz.exe</font></p>


    </td>


    <td width="43%" align="left">


    <p><font face="Arial" size="2">Deleted</font></p>


    </td>


    </tr><tr>


    <td width="57%">


    <p><font face="Arial" size="2">C:\WINDOWS\system\antivirus.exe=>(AutoIT)</font></p>


    </td>


    <td width="43%" align="left">


    <p><font face="Arial" size="2">Infected with: Win32.Worm.IM.Sohanat.B</font></p>


    </td>


    </tr><tr>


    <td width="57%">


    <p><font face="Arial" size="2">C:\WINDOWS\system\antivirus.exe=>(AutoIT)</font></p>


    </td>


    <td width="43%" align="left">


    <p><font face="Arial" size="2">Disinfection failed</font></p> </td>


    </tr><tr>


    <td width="57%">


    <p><font face="Arial" size="2">C:\WINDOWS\system\antivirus.exe=>(AutoIT)</font></p>


    </td>


    <td width="43%" align="left">


    <p><font face="Arial" size="2">Deleted</font></p>


    </td>


    </tr>


    </table>


    </td>


    <td width="10%">


    <p> </p>


    </td>


    </tr>


    <tr>


    <td width="458">


    <p><font face="Arial"><span style="font-size:11pt;"><B> </b></span></font></p>


    </td>


    <td width="40%">


    <p> </p>


    </td>


    <td width="10%">


    <p> </p>


    </td>


    </tr>


    <tr>


    <td width="458">


    <p><font face="Arial"><span style="font-size:11pt;"><B> </b></span></font></p>


    </td>


    <td width="40%">


    <p> </p>


    </td>


    <td width="10%">


    <p> </p>


    </td>


    </tr>


    </table>


    <p> </p>


    </body>


    </html>

  • The report says some files have been deleted, but probably the swchost.exe remained. Please download this program: http://www.filehippo.com/download/0e0a4476...3c07c/download/ , run it and click Do a system scan and safe logfile. Save the file to your desktop and then post here the contents.

  • Hello! This is the hijackthis scan:


    Logfile of Trend Micro HijackThis v2.0.2


    Scan saved at 16:24:27, on 03.12.2007


    Platform: Windows XP SP1 (WinNT 5.01.2600)


    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)


    Boot mode: Normal


    Running processes:


    C:\WINDOWS\System32\smss.exe


    C:\WINDOWS\system32\winlogon.exe


    C:\WINDOWS\system32\services.exe


    C:\WINDOWS\system32\lsass.exe


    C:\WINDOWS\system32\svchost.exe


    C:\WINDOWS\System32\svchost.exe


    C:\Program Files\Ahead\InCD\InCDsrv.exe


    C:\WINDOWS\system32\spoolsv.exe


    C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe


    C:\WINDOWS\explorer.exe


    C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe


    C:\PROGRA~1\Grisoft\AVG7\avgemc.exe


    C:\WINDOWS\System32\drivers\CDAC11BA.EXE


    C:\WINDOWS\System32\svchost.exe


    C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe


    C:\Program Files\Winamp\winampa.exe


    C:\Program Files\Common Files\Real\Update_OB\realsched.exe


    C:\Program Files\QuickTime\qttask.exe


    D:\Program Files\D-Tools\daemon.exe


    C:\WINDOWS\system\antivirus.exe


    C:\WINDOWS\wt\updater\wcmdmgr.exe


    C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe


    C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe


    C:\PROGRA~1\Grisoft\AVG7\avgcc.exe


    C:\Program Files\Softwin\BitDefender8\bdmcon.exe


    C:\Program Files\Softwin\BitDefender8\bdoesrv.exe


    C:\Program Files\Softwin\BitDefender8\bdnagent.exe


    C:\Program Files\Softwin\BitDefender8\bdswitch.exe


    C:\WINDOWS\System32\ctfmon.exe


    C:\Program Files\Messenger\msmsgs.exe


    C:\Program Files\Softwin\BitDefender8\vsserv.exe


    C:\PROGRA~1\Grisoft\AVG7\avgw.exe


    C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe


    C:\Program Files\Internet Explorer\iexplore.exe


    c:\program files\winamp toolbar\WinampTbServer.exe


    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe


    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://uk.rd.yahoo.com/customize/ycomp/def.../search/ie.html


    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://uk.rd.yahoo.com/customize/ycomp/def...://uk.yahoo.com


    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://uklotttery.us/


    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://uk.yahoo.com


    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://uk.yahoo.com


    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://uk.rd.yahoo.com/customize/ycomp/def...://uk.yahoo.com


    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll


    F2 - REG:system.ini: Shell=explorer.exe C:\WINDOWS\system\lsass.exe


    F2 - REG:system.ini: UserInit=userinit.exe,C:\WINDOWS\system\lsass.exe,C:\WINDOWS\System32\ntos.exe,


    O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll


    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx


    O2 - BHO: Winamp Toolbar BHO - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll


    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx


    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll


    O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll


    O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"


    O4 - HKLM\..\Run: [wcmdmgr] C:\WINDOWS\wt\updater\wcmdmgrl.exe -launch


    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot


    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime


    O4 - HKLM\..\Run: [DAEMON Tools-1033] "D:\Program Files\D-Tools\daemon.exe" -lang 1033


    O4 - HKLM\..\Run: [Task Manager] C:\WINDOWS\system\antivirus.exe


    O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"


    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP


    O4 - HKLM\..\Run: yoyxofs.exe


    O4 - HKLM\..\Run: [bDMCon] C:\Program Files\Softwin\BitDefender8\\bdmcon.exe


    O4 - HKLM\..\Run: [bDOESRV] C:\Program Files\Softwin\BitDefender8\\bdoesrv.exe


    O4 - HKLM\..\Run: [bDNewsAgent] C:\Program Files\Softwin\BitDefender8\\bdnagent.exe


    O4 - HKLM\..\Run: [bDSwitchAgent] C:\Program Files\Softwin\BitDefender8\\bdswitch.exe


    O4 - HKLM\..\Run: [Yahoo Messenger] C:\WINDOWS\system\symantec.exe


    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe


    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background


    O4 - HKCU\..\Run: [RealPlayer] "C:\Program Files\Real\RealPlayer\realplay.exe" /RunUPGToolCommandReBoot


    O4 - HKCU\..\Run:
    yoyxofs.exe


    O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet


    O4 - HKCU\..\Run: [Orb] "C:\Program Files\Winamp Remote\bin\OrbTray.exe" /background


    O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')


    O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')


    O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')


    O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')


    O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe


    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present


    O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1


    O8 - Extra context menu item: &Winamp Toolbar Search - C:\Documents and Settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html


    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000


    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe


    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe


    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL


    O9 - Extra button: Researcher - {9455301C-CF6B-11D3-A266-00C04F689C50} - C:\Program Files\Common Files\Microsoft Shared\Encarta Researcher\EROProj.dll


    O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm


    O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm


    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll


    O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) -
    http://us.dl1.yimg.com/download.yahoo.com/...nst_current.cab


    O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) -
    http://download.bitdefender.com/resources/scan8/oscan8.cab


    O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) -
    http://www.sibelius.com/download/software/...tiveXPlugin.cab


    O20 - AppInit_DLLs: sockspy.dll sockspy.dll sockspy.dll sockspy.dll sockspy.dll sockspy.dll sockspy.dll sockspy.dll sockspy.dll sockspy.dll sockspy.dll sockspy.dll sockspy.dll sockspy.dll sockspy.dll sockspy.dll sockspy.dll sockspy.dll sockspy.dll


    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe


    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe


    O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe


    O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe


    O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\System32\drivers\CDAC11BA.EXE


    O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe


    O23 - Service: BitDefender Virus Shield (VSSERV) - SOFTWIN S.R.L. - C:\Program Files\Softwin\BitDefender8\vsserv.exe


    O23 - Service: BitDefender Communicator (XCOMM) - Softwin - C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe


    --


    End of file - 8459 bytes


    Thank you!

  • alexcrist
    alexcrist
    edited December 2007

    Hello Gabby,


    Please fix the following lines:


    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://uklotttery.us/
    F2 - REG:system.ini: Shell=explorer.exe C:\WINDOWS\system\lsass.exe
    F2 - REG:system.ini: UserInit=userinit.exe,C:\WINDOWS\system\lsass.exe,C:\WINDOWS\System32\ntos.exe,
    O4 - HKLM\..\Run: [Task Manager] C:\WINDOWS\system\antivirus.exe
    O4 - HKLM\..\Run: [Topic lnternet] yoyxofs.exe
    O4 - HKLM\..\Run: [Yahoo Messenger] C:\WINDOWS\system\symantec.exe
    O4 - HKCU\..\Run: [Topic lnternet] yoyxofs.exe
    O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1


    Also, this line seems a little suspicious to me, but I'm not sure. I ask someone else to say if it should be fixed or not:


    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present


    And the following line seems very weird. sockspy.dll is a file belonging to BitDefender v10, but why it is called this many times is a mistry to me. Maybe someone else can answer this question:


    O20 - AppInit_DLLs: sockspy.dll sockspy.dll sockspy.dll sockspy.dll sockspy.dll sockspy.dll sockspy.dll sockspy.dll sockspy.dll sockspy.dll sockspy.dll sockspy.dll sockspy.dll sockspy.dll sockspy.dll sockspy.dll sockspy.dll sockspy.dll sockspy.dll


    Cris.

  • Hello again! I deleted the first group of files you told me. Still, some of them remained, but I can't find them anymore in the hijackthis window so I can fix them. They appear only in the notepad report:


    Logfile of Trend Micro HijackThis v2.0.2


    Scan saved at 23:43:34, on 03.12.2007


    Platform: Windows XP SP1 (WinNT 5.01.2600)


    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)


    Boot mode: Normal


    Running processes:


    C:\WINDOWS\System32\smss.exe


    C:\WINDOWS\system32\winlogon.exe


    C:\WINDOWS\system32\services.exe


    C:\WINDOWS\system32\lsass.exe


    C:\WINDOWS\system32\svchost.exe


    C:\WINDOWS\System32\svchost.exe


    C:\Program Files\Ahead\InCD\InCDsrv.exe


    C:\WINDOWS\system32\spoolsv.exe


    C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe


    C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe


    C:\PROGRA~1\Grisoft\AVG7\avgemc.exe


    C:\WINDOWS\System32\drivers\CDAC11BA.EXE


    C:\WINDOWS\System32\svchost.exe


    C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe


    C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe


    C:\Program Files\Softwin\BitDefender8\vsserv.exe


    C:\WINDOWS\explorer.exe


    C:\Program Files\Winamp\winampa.exe


    C:\Program Files\Common Files\Real\Update_OB\realsched.exe


    D:\Program Files\D-Tools\daemon.exe


    C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe


    C:\PROGRA~1\Grisoft\AVG7\avgcc.exe


    C:\Program Files\Softwin\BitDefender8\bdmcon.exe


    C:\Program Files\Softwin\BitDefender8\bdoesrv.exe


    C:\Program Files\Softwin\BitDefender8\bdnagent.exe


    C:\Program Files\Softwin\BitDefender8\bdswitch.exe


    C:\WINDOWS\System32\ctfmon.exe


    C:\Program Files\Winamp Remote\bin\OrbTray.exe


    C:\WINDOWS\wt\updater\wcmdmgr.exe


    C:\Program Files\Winamp Remote\bin\Orb.exe


    C:\DOCUME~1\Gabi\LOCALS~1\Temp\SVCHOST.EXE


    C:\DOCUME~1\Gabi\LOCALS~1\Temp\SVCHOST.EXE


    C:\DOCUME~1\Gabi\LOCALS~1\Temp\SVCHOST.EXE


    C:\Program Files\Internet Explorer\iexplore.exe


    C:\PROGRA~1\Lavasoft\AD-AWA~1\Ad-Aware.exe


    C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe


    C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe


    C:\Program Files\Internet Explorer\iexplore.exe


    c:\program files\winamp toolbar\WinampTbServer.exe


    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe


    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://uk.rd.yahoo.com/customize/ycomp/def.../search/ie.html


    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://uk.rd.yahoo.com/customize/ycomp/def...://uk.yahoo.com


    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://uk.yahoo.com


    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://uk.yahoo.com


    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://uk.rd.yahoo.com/customize/ycomp/def...://uk.yahoo.com


    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll


    O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll


    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx


    O2 - BHO: Winamp Toolbar BHO - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll


    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll


    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx


    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll


    O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll


    O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"


    O4 - HKLM\..\Run: [wcmdmgr] C:\WINDOWS\wt\updater\wcmdmgrl.exe -launch


    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot


    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime


    O4 - HKLM\..\Run: [DAEMON Tools-1033] "D:\Program Files\D-Tools\daemon.exe" -lang 1033


    O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"


    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP


    O4 - HKLM\..\Run: [bDMCon] C:\Program Files\Softwin\BitDefender8\\bdmcon.exe


    O4 - HKLM\..\Run: [bDOESRV] C:\Program Files\Softwin\BitDefender8\\bdoesrv.exe


    O4 - HKLM\..\Run: [bDNewsAgent] C:\Program Files\Softwin\BitDefender8\\bdnagent.exe


    O4 - HKLM\..\Run: [bDSwitchAgent] C:\Program Files\Softwin\BitDefender8\\bdswitch.exe


    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe


    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background


    O4 - HKCU\..\Run: [RealPlayer] "C:\Program Files\Real\RealPlayer\realplay.exe" /RunUPGToolCommandReBoot


    O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet


    O4 - HKCU\..\Run: [Orb] "C:\Program Files\Winamp Remote\bin\OrbTray.exe" /background


    O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')


    O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')


    O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')


    O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')


    O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe


    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present


    O8 - Extra context menu item: &Winamp Toolbar Search - C:\Documents and Settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html


    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000


    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe


    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe


    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL


    O9 - Extra button: Researcher - {9455301C-CF6B-11D3-A266-00C04F689C50} - C:\Program Files\Common Files\Microsoft Shared\Encarta Researcher\EROProj.dll


    O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm


    O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm


    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll


    O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/...nst_current.cab


    O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab


    O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/software/...tiveXPlugin.cab


    O20 - AppInit_DLLs: sockspy.dll sockspy.dll sockspy.dll sockspy.dll sockspy.dll sockspy.dll sockspy.dll sockspy.dll sockspy.dll sockspy.dll sockspy.dll sockspy.dll sockspy.dll sockspy.dll sockspy.dll sockspy.dll sockspy.dll sockspy.dll sockspy.dll


    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe


    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe


    O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe


    O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe


    O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\System32\drivers\CDAC11BA.EXE


    O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe


    O23 - Service: BitDefender Virus Shield (VSSERV) - SOFTWIN S.R.L. - C:\Program Files\Softwin\BitDefender8\vsserv.exe


    O23 - Service: BitDefender Communicator (XCOMM) - Softwin - C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe


    --


    End of file - 8231 bytes


    I received from a friend Spybot and Ad-Aware. Can this programs help me?


    The home page, wich I couldn't change before (www.uklottery.com) has changed into www.msn.com (wich is much better:) but I still can't change it from Internet properties. And while I am signed in at YahooMessenger, all my friends receive messages from me with the site uklottery, and I can't control this. Thank you for your help!

  • Hello Gabby,


    As far as I can see, your log is clean now. I'll take a more closer look tomorrow, just to be sure.


    SpyBot Search and Destroy and Ad-Aware are very good antispyware/anti-adware prorgams. Also, I could recommend SUPERAntiSpyware.


    If you still have problems after running these, please post. I'll look for a solution to fix your startpage. :)


    Cris.

  • Hello Gabby,


    Fix also the following line:


    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present


    Also, there is a process running that shouldn't exist. If this process is not detected by BitDefender (and I assume it's not, since it's running), please go to that path, find the file, put it in a ZIP archive (with the password infected) and attach it to a new post.


    C:\DOCUME~1\Gabi\LOCALS~1\Temp\SVCHOST.EXE


    After that, delete the file from disk (before trying to delete it, open TaskManager and kill all three instances of the process).


    Warning! Be careful to make distinction before the svchost.exe that is located in Windows\System32 and the one located in the Temp folder!


    Also, the Temp folder is hidden. To be able to see it, go to Explorer -> Folder options... -> View and select Show hidden files and folders. Also, disable Hide protected operating system files.


    Cris.

  • Warning! Be careful to make distinction before the svchost.exe that is located in Windows\System32 and the one located in the Temp folder!


    That's impossible with Task manager in Windows XP. If she fixes the registry entries, it won't load the next reboot and she can delete the files manually then.

  • That's impossible with Task manager in Windows XP. If she fixes the registry entries, it won't load the next reboot and she can delete the files manually then.


    Well, it might be possible, because the legit file is written with lower case letters, and it runs with System credentials (SYSTEM, LOCAL SERVICE or NETWORK SERVICE). But the other file is uppercase (and thi will show in TaskManager), and also I believe it runs with user credentials (which can be seen in TaskManager). :)


    Cris.

  • Hello!


    Guys, thanks a lot! For the moment I'm ok and everything got to normal. I didn't do the archive thing you told me, because I didn't have much time lately, but I used the HijackThis, AdAware and Spybot programs, and by this moment everything is cool. I can change my start web page (no more uklottery), and nothing virused is being sent anymore to my friends in messenger list. So, it's like before. But still I'll do the archive thing with svchost.exe.


    Merry christmas and God bless you, bluespirite and Cris!


    Thank you!

  • You're very welcome, Gabby.


    If you already used all those cleaning utilities (HijackThis, Ad-Aware, SypBot), there's a chance that the suspicious SVCHOST.EXE might have already been deleted. Just as a hint for next time you get infected (if there will be a next time :P ): get the infected files before running cleaning tools, because they might be deleted and you won't find them anymore. ;)


    And a Merry Christmas to you, too.


    Cris.