Just over an hour ago i reformatted due to this trojan (IRC/Backdoor.sdl). After i had reformatted and re-installed XP, set-up my internet connection etc the virus was still there!
I have AVG 6 which was unable to move the files to the vault. There are 2 infected files:
Winregs32.exe
Msnmssgs.exe
I have ad-aware, but after it's first run the reference file seems to have gone astray, and will not update to correct itself.
I found a thread related to my problem, and followed the steps using Hijack This, although my log was completely different. i managed to follow it, but when coming out of safemode and re scanning, the infections were still there.
However, after running AVG again it was able to heal the files. I am unsure that i have cured it, as my broadband connection details say i have a lot of traffic, but i have no programs open which would need it! Please could you look at this log, i would be over the moon if i can sort this with your help
Hijack This log:
Logfile of HijackThis v1.98.2
Scan saved at 00:06:22, on 08/11/2004
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\UTILIT~1\AVG6\avgserv.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe
C:\WINDOWS\System32\sysmsvc.exe
C:\WINDOWS\System32\RUNDLL32.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Utilities\Winamp\winampa.exe
C:\UTILIT~1\AVG6\avgcc32.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Utilities\AVG6\avgw.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Jack\Local Settings\Temp\Temporary Directory 2 for hijackthis.zip\HijackThis.exe
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Utilities\Spybot\SDHelper.dll
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [MsWindows SysDate] sysmsvc.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [WinampAgent] C:\Utilities\Winamp\winampa.exe
O4 - HKLM\..\Run: [AVG_CC] C:\UTILIT~1\AVG6\avgcc32.exe /STARTUP
O4 - HKLM\..\RunServices: [MsWindows SysDate] sysmsvc.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O17 - HKLM\System\CCS\Services\Tcpip\..\{D7E73806-F5A0-4870-B6FE-55BFEF9557BD}: NameServer = 212.67.120.148 212.67.96.129
I apreciate any help you could give on this. it's driving me round the bend
Thanks in advance...
Jack