I was working on this computer for a friend about a year ago, trying to get rid of some malware, and while I was working on it they decided to just get a new computer. I am now trying fix it again. I tried installing Norton 360 AV, but it made the system so slow, it was nearly impossible to use. I did an online scan using BitDefender, and it found some trojans/virus'. Installed Avira AntiVir Personal, that seems to run OK. Dont know if it was the trojans making Nortons run so slow or if I need to get more memory. Here are my logs.
BitDefender Online Scanner - Real Time Virus Report
Generated at: Thu, Jul 08, 2010 - 14:27:56
--------------------------------------------------------------------------------
Scan Info
Scanned Files
191458
Infected Files
4
Virus Detected
Trojan.Vundo.GMM
1
Trojan.Agent.AGVK
1
Trojan.Generic.1615286
1
Gen:Heur.Krypt.14
1
--------------------------------------------------------------------------------
This summary of the scan process will be used by the BitDefender Antivirus Lab to create agregate statistics about virus activity around the world.
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-07-09 06:13:03
Windows 5.1.2600 Service Pack 3
Running: 7q5q9uwp.exe; Driver: C:\DOCUME~1\Paul\LOCALS~1\Temp\kwwirfog.sys
---- System - GMER 1.0.15 ----
SSDT F989706E ZwCreateKey
SSDT F9897064 ZwCreateThread
SSDT F9897073 ZwDeleteKey
SSDT F989707D ZwDeleteValueKey
SSDT spqo.sys ZwEnumerateKey [0xF9166DA4]
SSDT spqo.sys ZwEnumerateValueKey [0xF9167132]
SSDT F9897082 ZwLoadKey
SSDT spqo.sys ZwOpenKey [0xF914E0C0]
SSDT F9897050 ZwOpenProcess
SSDT F9897055 ZwOpenThread
SSDT spqo.sys ZwQueryKey [0xF916720A]
SSDT spqo.sys ZwQueryValueKey [0xF916708A]
SSDT F989708C ZwReplaceKey
SSDT F9897087 ZwRestoreKey
SSDT F9897078 ZwSetValueKey
INT 0x62 ? 8130EBF8
INT 0x82 ? 8130EBF8
---- Kernel code sections - GMER 1.0.15 ----
? spqo.sys The system cannot find the file specified. !
.text a0dpu1i0.SYS F8D01386 35 Bytes [00, 00, 00, 00, 00, 00, 20, ...]
.text a0dpu1i0.SYS F8D013AA 24 Bytes [00, 00, 00, 00, 00, 00, 00, ...]
.text a0dpu1i0.SYS F8D013C4 3 Bytes [00, 80, 02]
.text a0dpu1i0.SYS F8D013C9 1 Byte [30]
.text a0dpu1i0.SYS F8D013C9 11 Bytes [30, 00, 00, 00, 5E, 02, 00, ...] {XOR [EAX], AL; ADD [EAX], AL; POP ESI; ADD AL, [EAX]; ADD [EAX], AL; ADD [EAX], AL}
.text ...
---- Kernel IAT/EAT - GMER 1.0.15 ----
IAT \WINDOWS\System32\Drivers\SCSIPORT.SYS[ntoskrnl.exe!DbgBreakPoint] 813132D8
IAT pci.sys[ntoskrnl.exe!IoDetachDevice] [F9179DDC] spqo.sys
IAT pci.sys[ntoskrnl.exe!IoAttachDeviceToDeviceStack] [F9179E30] spqo.sys
IAT atapi.sys[HAL.dll!READ_PORT_UCHAR] [F914F042] spqo.sys
IAT atapi.sys[HAL.dll!READ_PORT_BUFFER_USHORT] [F914F13E] spqo.sys
IAT atapi.sys[HAL.dll!READ_PORT_USHORT] [F914F0C0] spqo.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_BUFFER_USHORT] [F914F800] spqo.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_UCHAR] [F914F6D6] spqo.sys
IAT \SystemRoot\System32\DRIVERS\i8042prt.sys[HAL.dll!READ_PORT_UCHAR] [F915EB90]
