Hello. I havent been here for a while but need some input on a problem ive been experiencing.
Im running:
Windows XP Pro SP2 (currently fully updated)
Kaspersky Anti-Hacker firewall 1.7
Norton Systemworks 2002
Spyware Doctor (PC Tools)
Spybot 1.4
Ad-Aware SE Personal Build 1.06r1 (the free version)
A while ago I got a Norton AV alert whilst I was using Internet Explorer.
The Norton log was like this:
Date: 10/04/2006, Time: 02:10:32, Administrator on SIDBOT-KK8S9ZG1
The file
C:\WINDOWS\system32\zhopaizdupla.exe
is infected with the Download.Trojan virus.
Unable to repair this file.
Date: 10/04/2006, Time: 02:10:32, Administrator on SIDBOT-KK8S9ZG1
The file
C:\WINDOWS\system32\zhopaizdupla.exe
is infected with the Download.Trojan virus.
Access to the file was denied.
Upon checking the log, I also found this which I hadnt noticed before:
Date: 27/03/2006, Time: 02:35:40, Administrator on SIDBOT-KK8S9ZG1
The file C:\WINDOWS\system32\voblaizdupla.exe is infected with the Download.Trojan virus.
The file was quarantined.
Date: 27/03/2006, Time: 02:35:40, Administrator on SIDBOT-KK8S9ZG1
Virus scanning completed.
Master boot records:
...
Boot records:
...
Files:
Scanned: 100131
Infected: 1
Repaired: 0
Quar'ed: 1
Deleted: 0
which as you can see was about two weeks before the first one.
Anyway, I scanned the PC with Norton and nothing showed this time. I ran Spyware Doctor and it only found a few tracking cookies.
A week later, and again while using IE I got this:
Date: 17/04/2006, Time: 11:20:16, Administrator on SIDBOT-KK8S9ZG1
The file
C:\WINDOWS\system32\zhopaizdupla.exe
is infected with the Download.Trojan virus.
Unable to repair this file.
Date: 17/04/2006, Time: 11:20:16, Administrator on SIDBOT-KK8S9ZG1
The file
C:\WINDOWS\system32\zhopaizdupla.exe
is infected with the Download.Trojan virus.
Access to the file was denied.
Again, after the alert I scanned again and nothing significant was found.
I decided that I should make sure that I was fully updated with Windows, so did this. I also decided to stop running an Apache webserver that I have. According to Norton AV, Spyware Doctor, Spybot S&D and Ad-Aware, my PC was squeaky clean.
Perhaps a week ago, Kaspersky firewall said that a service called phqghume.exe was trying to 'call-out'. I blocked the service, stopped the process and found the exe itself in my system32 folder. It deleted with no problems. Again, scans showed little that was bad.
Today, I opened IE and was on the force9 (UK ISP) home page and I got this:
Date: 04/05/2006, Time: 16:05:36, Administrator on SIDBOT-KK8S9ZG1
The file
C:\WINDOWS\system32\cvdjneir.exe
is infected with the Trojan.Adclicker virus.
Unable to repair this file.
Date: 04/05/2006, Time: 16:05:36, Administrator on SIDBOT-KK8S9ZG1
The file
C:\WINDOWS\system32\cvdjneir.exe
is infected with the Trojan.Adclicker virus.
Access to the file was denied.
I couldnt find the file and an initial AV scan turned up nothing. I then ran all scans with updated definitions, in Safe Mode. The only thing that looked suspicious and a possible culprit was this from Spyware Doctor:
Infection Name Location Risk
Advertising C:\Documents and Settings\Administrator\Cookies\administrator@adtec h[2].txt Low
Tracking Cookie(s) C:\Documents and Settings\Administrator\Cookies\administrator@cgi-bin[2].txt Medium
Known Bad Sites C:\Documents and Settings\Administrator\Cookies\administrator@keywo rdmax[1].txt High
Tracking Cookie(s) C:\Documents and Settings\Administrator\Cookies\administrator@blues treak[1].txt Medium
Advertising C:\Documents and Settings\Administrator\Cookies\administrator@ads.p ointroll[2].txt
I've fixed the bad things and re-scanned and everything is clean, apparently.
Any ideas as to why this is happening? Im beginning to get paranoid that I have something very horrible that is hidden away and its going to start stealing info from me or something like that.
Many sincere thank-yous for any help, advice and guidance


