my AVG keeps popping up windows telling me that it found various .exe files of the Trojan Horse PSW.Legendmir.CPW
My Hijack this log is as follows:
Logfile of HijackThis v1.99.1
Scan saved at 13:54:32, on 03/09/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
CLOSE ALL WINDOWS (even this one) AND PROGRAMS!!!!
Run Hijack This!
Click "Do a systen scan only".
Then "check" the box to the left of these item(s):
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
Thanks for immediate help. I did as you suggested but AVG is still popping up windows about it. After deleting what you told me, the logfile appeared as follows:
Logfile of HijackThis v1.99.1
Scan saved at 16:13:03, on 03/09/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
As a virus name, they are being detected as Trojan Horse PSW.Legendmir.CPW. They are being located in Windows\Temp as Win8.exe or Win4 or Win2 or Win(other numbers).exe and also in the Documents and Settings Folder\Local Settings.
Thanks
I ran the ATF cleaner as you told me, but AVG is still popping up about this trojan.
I don't know if this can help, I ran Hijackthis again and pasted the logfile:
Logfile of HijackThis v1.99.1
Scan saved at 17:15:05, on 03/09/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
I did as you told me and I think that it is ok now. I haven't had any popus till now and the ewido also returned positive results which I quarantined and deleted immediately. The report is as follows:
E:\WINDOWS\NDNuninstall6_38.exe -> Adware.NewDotNet : No action taken.
E:\WINDOWS\NDNuninstall7_22.exe -> Adware.NewDotNet : No action taken.
E:\WINDOWS\system32\Ravdm.exe -> Downloader.Small.czl : No action taken.
E:\Program Files\Internet Explorer\PLUGINS\system32.jmp -> Trojan.Legmir.564 : No action taken.
E:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\6VW3AHCJ\c[1].gif -> Trojan.Lmir.azg : No action taken.
E:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\6VW3AHCJ\c[2].gif -> Trojan.Lmir.azg : No action taken.
E:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\6VW3AHCJ\c[3].gif -> Trojan.Lmir.azg : No action taken.
E:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\6VW3AHCJ\c[4].gif -> Trojan.Lmir.azg : No action taken.
E:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\6VW3AHCJ\c[5].gif -> Trojan.Lmir.azg : No action taken.
E:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\WXAZO183\c[1].gif -> Trojan.Lmir.azg : No action taken.
E:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\WXAZO183\c[2].gif -> Trojan.Lmir.azg : No action taken.
E:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\WXAZO183\c[3].gif -> Trojan.Lmir.azg : No action taken.
E:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\WXAZO183\c[4].gif -> Trojan.Lmir.azg : No action taken.
E:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\WXAZO183\c[5].gif -> Trojan.Lmir.azg : No action taken.
E:\Documents and Settings\Malcolm\Local Settings\Temp\Win10.exe -> Trojan.Lmir.azg : No action taken.
E:\Documents and Settings\Malcolm\Local Settings\Temp\Win11.exe -> Trojan.Lmir.azg : No action taken.
E:\Documents and Settings\Malcolm\Local Settings\Temp\Win12.exe -> Trojan.Lmir.azg : No action taken.
E:\Documents and Settings\Malcolm\Local Settings\Temp\Win13.exe -> Trojan.Lmir.azg : No action taken.
E:\Documents and Settings\Malcolm\Local Settings\Temp\Win14.exe -> Trojan.Lmir.azg : No action taken.
E:\Documents and Settings\Malcolm\Local Settings\Temp\Win5.exe -> Trojan.Lmir.azg : No action taken.
E:\Documents and Settings\Malcolm\Local Settings\Temp\Win6.exe -> Trojan.Lmir.azg : No action taken.
E:\Documents and Settings\Malcolm\Local Settings\Temp\Win7.exe -> Trojan.Lmir.azg : No action taken.
E:\Documents and Settings\Malcolm\Local Settings\Temp\Win8.exe -> Trojan.Lmir.azg : No action taken.
E:\Documents and Settings\Malcolm\Local Settings\Temp\Win9.exe -> Trojan.Lmir.azg : No action taken.
E:\Documents and Settings\Malcolm\Local Settings\Temp\WinA.exe -> Trojan.Lmir.azg : No action taken.
E:\Documents and Settings\Malcolm\Local Settings\Temp\WinB.exe -> Trojan.Lmir.azg : No action taken.
E:\Documents and Settings\Malcolm\Local Settings\Temp\WinC.exe -> Trojan.Lmir.azg : No action taken.
E:\Documents and Settings\Malcolm\Local Settings\Temp\WinD.exe -> Trojan.Lmir.azg : No action taken.
E:\Documents and Settings\Malcolm\Local Settings\Temp\WinE.exe -> Trojan.Lmir.azg : No action taken.
E:\Documents and Settings\Malcolm\Local Settings\Temp\WinF.exe -> Trojan.Lmir.azg : No action taken.
E:\Documents and Settings\Malcolm\Local Settings\Temporary Internet Files\Content.IE5\2M1RKEFF\c[1].gif -> Trojan.Lmir.azg : No action taken.
E:\WINDOWS\system32\explore.exe -> Trojan.WOW.fc : No action taken.
E:\WINDOWS\system32\myztr.dll -> Trojan.WOW.fc : No action taken.
E:\WINDOWS\system32\Server.exe -> Trojan.WOW.fi : No action taken.
The hijackthis report is this:
Logfile of HijackThis v1.99.1
Scan saved at 19:15:12, on 03/09/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
If you need this topic reopened, please request this by sending an email to us at the following link (Click for address) Include your post user name and detail why you need it reopened with a valid link to your post.
Any bad links or emails that are not from the original poster will be deleted without response.
Any emails without the subject "Reopen" will be deleted without being looked at.
If this is not your thread please start a New Topic.
✨ Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI