Tom's Guide | Tom's Hardware | Tom's Games
![]() |
![]() |
![]() |
Hello all, I am in dire need of help. I have several virus's I am going to paste the rav scan log here. Thanks Amber
C:\Documents and Settings\All Users\Application Data\IEService\v28.exe->(CExe) - TrojanDropper:Win32/VB.CD -> Infected
C:\Documents and Settings\Owner\Local Settings\Temp\i2.tmp - TrojanDownloader:Win32/Small.ID -> Suspicious
C:\Documents and Settings\Owner\Local Settings\Temp\i4.tmp - TrojanDownloader:Win32/Small.ID -> Suspicious
C:\Documents and Settings\Owner\Local Settings\Temp\polmx2.cab->polmx2.exe - TrojanDownloader:Win32/Agent.AE -> Infected
C:\Documents and Settings\Owner\Local Settings\Temp\polmx2.exe - TrojanDownloader:Win32/Agent.AE -> Infected
C:\Documents and Settings\Owner\Local Settings\Temp\wupdt.exe - TrojanDownloader:Win32/Intexp.A -> Infected
C:\Documents and Settings\Owner\Local Settings\Temp\ICD1.tmp\wupdt.exe - TrojanDownloader:Win32/OneClickNetS.D -> Infected
C:\Documents and Settings\Owner\Local Settings\Temp\IncrediMail\foto.zip->foto/foto.html->(SCRIPT0001) - JS/Dword.dr* -> Infected
C:\Documents and Settings\Owner\Local Settings\Temp\IncrediMail\foto.zip->foto/foto/foto1.exe - Win32/Bagle.AI -> Infected
C:\Documents and Settings\Owner\Local Settings\Temp\THI6839.tmp\wupdt.exe - TrojanDownloader:Win32/Intexp.A -> Infected
C:\Documents and Settings\Owner\Local Settings\Temp\THI74DB.tmp\wupdt.exe - TrojanDownloader:Win32/Intexp.A -> Infected
C:\Documents and Settings\Owner\Local Settings\Temp\THI76ED.tmp\wupdt.exe - TrojanDownloader:Win32/Intexp.A -> Infected
C:\Program Files\IncrediFind\BHO\IncFindBHO.dll_tobedeleted - TrojanDownloader:Win32/Small.BX -> Infected
C:\Program Files\IncrediFind\BHO\IncFindBHO150.dll_tobedeleted_tobedeleted - TrojanDownloader:Win32/Keenval.A -> Infected
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP262\A0036969.exe - Backdoor:Win32/Ruledor.E -> Infected
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP262\A0036972.exe - Tool:PornDialer.EA -> Infected
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP262\A0036973.exe - TrojanDownloader:Win32/Keenval.A -> Infected
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP262\A0036974.exe - TrojanDownloader:Win32/Keenval.C -> Infected
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP262\A0036975.exe - TrojanDownloader:Win32/Keenval.A -> Infected
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP262\A0036994.exe - TrojanDownloader:Win32/OneClickNetS.D -> Infected
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP262\A0036995.dll - TrojanDownloader:Win32/Keenval.A -> Infected
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP262\A0036996.exe - TrojanDownloader:Win32/Keenval.A -> Infected
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP262\A0037004.dll - TrojanDownloader:Win32/Small.BX -> Infected
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP262\A0037005.exe - TrojanDownloader:Win32/Keenval.C -> Infected
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP262\A0037006.exe - TrojanDownloader:Win32/Stubby.A -> Infected
C:\System Volume Information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP262\A0037007.exe - TrojanSpy/Win32.BiSpy.A -> Infected
C:\WINNT\dwcg2.exe->[nsins.2] - Tool:PornDialer.EA -> Infected
C:\WINNT\polmx2.exe - TrojanDownloader:Win32/Agent.AE -> Infected
C:\WINNT\system32\benceed.dll - TrojanDownloader:Win32/Rameh.A -> Infected
C:\WINNT\system32\biI.exe->(UPXW) - PWS:Win32/Bispy -> InfectedScanned
============================
Objects: 63000
Directories: 4704
Archives: 7153
Size(Kb): -1355333
Infected files: 28Found
============================
Viruses found: 15
Suspicious files: 2
Disinfected files: 0
Mail files: 397

I am not sure exactly what your question is. Have you tried using your antivirus program to fix these problems? From your log, just about any antivirus program should be able to take care of many of the virus/trojan problems that are listed. There are some listed in you system restore files, however that would require you to turn system restore off and restart the computer. During the restart I would enter the safe mode and run ther antivirus program's scan again to see what else can be detected and fixed. Then I would restart and run another antivirus program scan from the normal mode to see if any problems might remain or if the system is clean. You could then add to this post what those exact problems are, so that we can assist you further.

These are not viruses, but trojan adware programs. Check the list on this page,
http://securityresponse.symantec.com/avcenter/tools.list.html
...to find removal tools and instructions.
Disable XP's System Restore and restart the machine, leave System Restore disabled until you get rid of this stuff.
I would also recommend getting AdAware and SpyBot Search & Destroy, both work well together and do an excellant job of keeping adware of your system.
http://www.majorgeeks.com/download2471.html
http://www.majorgeeks.com/download506.html
_________________________
The internet is no longer a toy, it's a COMBAT ZONE!

Hello, Ok I have downloaded both spybot and adware I have been able to remove most of my problems, I also was able to download a new antivirus,"Mcafee" and have ran that at least once a week, Still I have a problem. My desktop icons are arranged for easy finding, but the next day their gone. When Im on the internet, windows freeze, are unable to display, and when i restart my pc, I have so many programs starting at start up that it takes 10 min. to do anything. When I ran norton it comes up with my_doom trojan virus but will not get rid of it. When I ran Mcafee it said it got rid of it. Things are still messes up. What is the next step?
Thank you so much Amber

![]() |
![]() |
![]() |

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.
| Ads by Google |