recurring viruses plz help!!!

Discussion in 'System Security & Infection Support' started by andriarox, Dec 30, 2004.

  1. andriarox

    andriarox

    Joined:
    Dec 16, 2004
    Messages:
    7
    Likes Received:
    0
    Location:
    Virginia
    I have the AVG Virus scan software. Twice today while on the Internet a box popped up (from AVG) and said "Virus Detected" so I disconnected from the Internet and ran a full system scan and these are the viruses that it has found:

    vxhj8kdq5.exe
    Trojan horse Downloader.Small.8.R
    C:\WINDOWS\TEMP\vxh8jkdq5.exe

    5.qtdfmp
    C:\WINDOWS\TEMP\5.qtdfmp

    vxhj8kdq2.exe
    Trojan horse Favadd.B
    C:\WINDOWS\vxh8jkdq2.exe

    2.qtdfmp
    Trojan horse Favadd.B
    C:\WINDOWS\TEMP\2.qtdfmp

    Also I had this "Highlighter" spyware program on my computer and I had to delete it with my Spybot S&D Program. Furthermore, I have noticed that when I hit Ctrl+Alt+Delete one of the things in the list is "Kernels32". That has never been there before. Also as I was typing this message the AVG Virus alert dialog box popped up and said "VIRUS DETECTED" and it was the "vxh8jkdq5.exe" virus that AVG said it "deleted" earlier today. Why does this keep happening? Here lately its either a virus or spyware or something. Can someone please help to get rid of these and stop them from re-infecting my computer? Thank you SO much!!!
     
    andriarox, Dec 30, 2004
    #1
    1. Advertisements

  2. andriarox

    andriarox

    Joined:
    Dec 16, 2004
    Messages:
    7
    Likes Received:
    0
    Location:
    Virginia
    Here is my AVG log file:
    "Partition table (MBR)","ok","Quick checked"
    "Boot sector of disk C:","ok","Quick checked"
    "System registry Software\Microsoft\Windows NT\CurrentVersion\Windows\Load","","Scanned"
    "System registry Software\Microsoft\Windows NT\CurrentVersion\Windows\Run","","Scanned"
    "System registry Software\Microsoft\Windows\CurrentVersion\Run","","Scanned"
    "System registry Software\Microsoft\Windows\CurrentVersion\RunOnce","","Scanned"
    "System registry Software\Microsoft\Windows\CurrentVersion\RunOnceEx","","Scanned"
    "System registry Software\Microsoft\Windows\CurrentVersion\RunServices","","Scanned"
    "System registry Software\Microsoft\Windows\CurrentVersion\RunServicesOnce","","Scanned"
    "System registry Software\Microsoft\Windows\CurrentVersion\Run","","Scanned"
    "System registry Software\Microsoft\Windows\CurrentVersion\RunOnce","","Scanned"
    "System registry Software\Microsoft\Windows\CurrentVersion\RunOnceEx","","Scanned"
    "System registry Software\Microsoft\Windows\CurrentVersion\RunServices","","Scanned"
    "System registry Software\Microsoft\Windows\CurrentVersion\RunServicesOnce","","Scanned"
    "System registry Software\Microsoft\Windows\CurrentVersion\Winlogon\Userinit","","Scanned"
    "System registry SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell","","Scanned"
    "System registry exefile\shell\open\command","","Scanned"
    "System registry scrfile\shell\open\command","","Scanned"
    "System registry scrfile\shell\config\command","","Scanned"
    "System registry batfile\shell\open\command","","Scanned"
    "System registry cmdfile\shell\open\command","","Scanned"
    "System registry comfile\shell\open\command","","Scanned"
    "System registry piffile\shell\open\command","","Scanned"
    "System registry giffile\shell\open\command","","Scanned"
    "System registry htmlfile\shell\open\command","","Scanned"
    "System registry htafile\shell\open\command","","Scanned"
    "System registry jpegfile\shell\open\command","","Scanned"
    "System registry txtfile\shell\open\command","","Scanned"
    "System registry regfile\shell\open\command","","Scanned"
    "System registry cplfile\shell\cplopen\command","","Scanned"
    "System registry Word.Document.8\shell\open\command","","Scanned"
    "System registry WordPad.Document.1\shell\open\command","","Scanned"
    "C:\PROGRA~1\ACCESS~1\WORDPAD.EXE","ok","Quick checked"
    "C:\PROGRA~1\GRISOFT\AVGFRE~1\avgamsvr.exe","ok","Quick checked"
    "C:\PROGRA~1\GRISOFT\AVGFRE~1\avgcc.exe","ok","Quick checked"
    "C:\PROGRA~1\GRISOFT\AVGFRE~1\avgemc.exe","ok","Quick checked"
    "C:\PROGRA~1\INTERN~1\IEXPLORE.EXE","ok","Quick checked"
    "C:\WINDOWS\EXPLORER.EXE","ok","Quick checked"
    "C:\WINDOWS\LOADQM.EXE","ok","Quick checked"
    "C:\WINDOWS\NOTEPAD.EXE","ok","Quick checked"
    "C:\WINDOWS\PCTPTT.EXE","ok","Quick checked"
    "C:\WINDOWS\REGEDIT.EXE","ok","Quick checked"
    "C:\WINDOWS\RUNDLL32.EXE","ok","Quick checked"
    "C:\WINDOWS\SYSTEM\MSHTA.EXE","ok","Quick checked"
    "C:\WINDOWS\SYSTEM\MSTASK.EXE","ok","Quick checked"
    "C:\WINDOWS\SYSTEM\SHELL32.DLL","ok","Quick checked"
    "C:\WINDOWS\SYSTEM\SHIMGVW.DLL","ok","Quick checked"
    "C:\WINDOWS\SYSTEM\SYSTRAY.EXE","ok","Quick checked"
    "C:\WINDOWS\SYSTEM\kernels32.exe","ok","Quick checked"
    "C:\WINDOWS\SYSTEM\qttask.exe","ok","Quick checked"
    "C:\WINDOWS\System\Restore\STATEMGR.EXE","ok","Quick checked"
    "C:\IO.SYS","ok","Quick checked"
    "C:\MSDOS.SYS","ok","Quick checked"
    "C:\COMMAND.COM","ok","Quick checked"
    "C:\WINDOWS\SYSTEM\kernel32.dll","ok","Quick checked"
    "C:\WINDOWS\SYSTEM\wsock32.dll","ok","Quick checked"
    "C:\WINDOWS\SYSTEM\user32.dll","ok","Quick checked"
    "C:\WINDOWS\SYSTEM\shell32.dll","ok","Quick checked"
    "C:\WINDOWS\SYSTEM\vxh8jkdq2.exe","","Deleted"
    "C:\WINDOWS\TEMP\2.qtdfmp","","Deleted"


    These are the two that keep coming up only the 2 is a 5.
     
    andriarox, Dec 30, 2004
    #2
    1. Advertisements

  3. andriarox

    James Photojournalist

    Joined:
    Dec 24, 2002
    Messages:
    6,662
    Likes Received:
    35
    Hi, delete them using the process I explained in your other [thread=4343]thread[/thread].
     
    James, Dec 30, 2004
    #3
    1. Advertisements

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments (here). After that, you can post your question and our members will help you out.