Hi there,
I've not done any virus fixing for a while as things seem to have been taking quite good care of themselves, so I'm a bit out of practice. However, a couple of days ago a process called wJQs.exe popped up asking ZoneAlarm for permission to access the internet. I immediately thought it looked a bit dodgy, so pressed 'Deny' and did a bit of research into it... which is why I'm here.
I've followed as many instructions as I could before posting, but the Deckard's scanner links seemed to be down, so I don't have a log for that.
I should also point out that I (possibly foolishly) deleted the wJQs.exe file from my Temp directory, once I found out it was there.
Anyway, here are the logs so far...
Malwarebytes' Anti-Malware 1.31
Database version: 1456
Windows 5.1.2600 Service Pack 2
16/12/2008 06:10:07
mbam-log-2008-12-16 (06-10-06).txt
Scan type: Full Scan (C:\|)
Objects scanned: 146890
Time elapsed: 56 minute(s), 3 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
# version=4
# OnlineScanner.ocx=1.0.0.635
# OnlineScannerDLLA.dll=1, 0, 0, 79
# OnlineScannerDLLW.dll=1, 0, 0, 78
# OnlineScannerUninstaller.exe=1, 0, 0, 49
# vers_standard_module=3695 (20081216)
# vers_arch_module=1.064 (20080214)
# vers_adv_heur_module=1.064 (20070717)
# EOSSerial=ef8e89109a151240a7f584fb71ccdb5b
# end=finished
# remove_checked=false
# unwanted_checked=true
# utc_time=2008-12-16 03:29:13
# local_time=2008-12-16 03:29:13 (+0000, GMT Standard Time)
# country="United Kingdom"
# osver=5.1.2600 NT Service Pack 2
# scanned=426061
# found=1
# scan_time=11855
C:\WINDOWS\system32\drivers\SjyPkt.sys Win32/Rootkit.Agent.NHO trojan 3D7EF286E806F9BD9339AA52E28DCD67
Any help would be massively appreciated.
Chris
Edit: Also (and I have no idea if it's relevant or not) MBAM said that it couldn't connect to the internet to check for updates - just thought it was worth mentioning.