Today, I was fixing someone's computer, and it was severly infected. (It had like every virus and trojan known to man). When I first started the computer was really slow. I updated and ran Ad-Aware and started scanning, and all of a sudden the computer shuts off, I then reboot into safe mode and continue running Ad-Aware and remove everything. She had a ton of spyware (dialers, trojan downloaders, elitebar, 180searchsolutions, and some other things). Well her computer was just not getting better after 2 different antispyware programs (Ad-Aware and Spy Sweeper) and an antivirus program (antivir). I then ran HijackThis, and since I can't post the log I wrote down all the malicious stuff that I knew was malicious. I have noticed that she has trojan.vundo. I have no idea on how to get this off. She has a Windows XP computer (2-3 year old gateway) with 128MB of RAM and a 14.6GB hard drive. The following entries that I noticed are below:
BHO: C:\Windows\System32\jkll.dll
BHO: MSEVENTS object C:\Windows\System32\awvtr.dll
BHO: (no name)- blank
Winlogon notify: C:\Windows\System32\awvtr.dll
Delus: HKLM\..\RunOnce: C:\Docume`1\Admin`1\Locals\Temp\delus.exe
ZXIKAG: "C:\Program Files\InetGet2\CP.GH2.exe"\SHUN\PC=CP.GH2\SHUN\PC=CP.GH2
BJCFD: C:\Program Files\Broad Jump\Client Foundation\CFD.exe
IPInSightLan03: "C:\Program Files\Visual Networks\Visual IPInsight\SBC\ipclient.exe
IPInsightmonitor: C:\Program Files\Visual Networks\Visual IPInsight\SBC\IPMon32.exe
FLMOFFICE 4D Mouse: C:/Program Files/Browser Mouse\mouse32a.exe
hpfsched: C:\Windows\hpfsched.exe
Hotkey kbd 9910 Daemon: SK9910DM.exe
Winlogon Notfiy: jkkll- C:\Windows\System32\jkkll.dll
Keep in mind that there is no way for me to post the entire log, because she does not have access to the internet right now, because of the computer shut offs. Please help me, fix her computer. Thanks for your help.
(O and please don't reply saying to make it a normal startup HijackThis log. This is the best I can do. I say this because a person from another board posted that)
BHO: C:\Windows\System32\jkll.dll
BHO: MSEVENTS object C:\Windows\System32\awvtr.dll
BHO: (no name)- blank
Winlogon notify: C:\Windows\System32\awvtr.dll
Delus: HKLM\..\RunOnce: C:\Docume`1\Admin`1\Locals\Temp\delus.exe
ZXIKAG: "C:\Program Files\InetGet2\CP.GH2.exe"\SHUN\PC=CP.GH2\SHUN\PC=CP.GH2
BJCFD: C:\Program Files\Broad Jump\Client Foundation\CFD.exe
IPInSightLan03: "C:\Program Files\Visual Networks\Visual IPInsight\SBC\ipclient.exe
IPInsightmonitor: C:\Program Files\Visual Networks\Visual IPInsight\SBC\IPMon32.exe
FLMOFFICE 4D Mouse: C:/Program Files/Browser Mouse\mouse32a.exe
hpfsched: C:\Windows\hpfsched.exe
Hotkey kbd 9910 Daemon: SK9910DM.exe
Winlogon Notfiy: jkkll- C:\Windows\System32\jkkll.dll
Keep in mind that there is no way for me to post the entire log, because she does not have access to the internet right now, because of the computer shut offs. Please help me, fix her computer. Thanks for your help.
(O and please don't reply saying to make it a normal startup HijackThis log. This is the best I can do. I say this because a person from another board posted that)