melc00
Topic Starter
Avg free found a trojan on my machine and identified it as (backdoor.small.22.z)
using C:\WINDOWS\System32\rdpcfger.dll . However I searched every search engine I could find and recieved no confirmation from any of them.
Avg did delete rdpfger.dll and Hijack this found the entry in my registry. I then
made a search of the registry and found it in "browser helper objects".
My question is, can this be a brand new trojan since I couldnt find any info at all.
This my log with Hijack this.
Logfile of HijackThis v1.99.1
Scan saved at 7:31:35 PM, on 3/9/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Tiny Personal Firewall\persfw.exe
C:\Documents and Settings\mel\Desktop\downloaded\hijackthis\HijackThis.exe
O2 - BHO: rdpcfger - {5DE7E9F0-1968-B561-FB7C-B1FD5E5840EE} - C:\WINDOWS\System32\rdpcfger.dll (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: Tiny Personal Firewall (PersFw) - Tiny Software - C:\Program Files\Tiny Personal Firewall\persfw.exe
Thank you for any answers you can give on this topic.