so here is the situation I have...
few days ago my compute got infected, and started opening various advertisment sites, and no matter how many times I've removed them (I'm using spybot-search & destroy and Ad-Aware SE personal both regulary updated) in a week or two same advertisment would pop up, so I've just blocked those sites that were opening, and deleting virus every time it poped up (I'm using Avira Anti Virus PE). Lately I've had Vundo.gen poping up regulary as infection and no matter how many times I would delete it, it would show up again. Than there are two entries that spybot can't delete, they are both recognized as TR/Agent.33302 by Avira and are part of Virtumonde in Spybot entries, no matter how many times I would delete them (even over HiJack This, and even when I try to delete them on startup or from safe mode) they would return every time I try to open Internet Explorer or any link in it, they are located in system32 folder every time they appear.
Then there's new infection which just showed up after I've returned home after being two weeks away, problem is that noone used computer, and Avira recognized it right when I started computer. That one just randomly goes crazy and for like 5 minutes tries multiple attacks so much that my PC frezzes almost every time from alerts by Avira, that last one is recognized as TR/PSW.Gamania.B.
I have two more infections that aren't that much bother, 'cause they don't activate too often those are:
TR/Spy.VBStat.B.1 and
TR/JuanSearch.B
I haven't named any of infected files because they have rather random names. Some of them are found in Temporary Internet Files folder, but I can't seem to delete everything, 'cause IE gets frozen every time I try to delete them, and when I try to get into IE5.Content folder (or whatever it's name is) I can't delete everything from there, it just gives me error. Also I can't scan my whole PC with Avira 'cause it just stops while scaning root folder and I don't want to install any other anti virus program so I wouldn't have conflicts between those two.
Sorry for lenghty explanation, but I wanted to make it easier for someone who would maybe want to help me... thanks in advance.
And also I've noticed that those aren't included in hijackthis log so I thought I've had to name them for someone to actually be able to help me, 'cause some of them do appear among entries in log from time to time. as for entries I've removed bit lord and winamp from logs 'cause I've had them running atm, but I've had left MSN runing, since there has been increased in entries that hijackthis finds for MSN since it's been replaced with windows live messenger. And internet explorer usually doesn't remove itself from running processes once it's closed.
Logfile of HijackThis v1.99.1
Scan saved at 21:11:46, on 18.7.2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\UAService7.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\NIKOLA\uni\HijackThis.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: AntiVir Guard.lnk = C:\Program Files\AVPersonal\AVGNT.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: Download with GetRight - C:\Program Files\GetRight\GRdownload.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Open with GetRight Browser - C:\Program Files\GetRight\GRbrowse.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{89075EDC-A71C-4745-9529-E8A05331FB0A}: NameServer = 80.65.162.101 217.199.128.11
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O23 - Service: AntiVir Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Service (AntiVirService) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Sony DADC Austria AG. - C:\WINDOWS\system32\UAService7.exe
also I don't remember having this
O17 - HKLM\System\CCS\Services\Tcpip\..\{89075EDC-A71C-4745-9529-E8A05331FB0A}: NameServer = 80.65.162.101 217.199.128.11
entry in my previous logs, but since my pc got infected no matter how many times I would remove it, it would show up again, I've even removed it over regedit.