Deleted Member
Topic Starter
hahaha i guess i broke the rule somehow …
i didnt post any HJT LOG
but AVG spyware log
it really freak me out… those trojan were keyloggers!!!
lucky i follow one of the admins and use the ewido antispyware and somehow it change it company to AVG.
anyone here is my log
———————————————————
AVG Anti-Spyware - Scan Report
———————————————————
+ Created at: 11:02:15 AM 10/5/2006
+ Scan result:
C:\System Volume Information\_restore{49A6A861-7B36-4928-9784-B7C1D64AB817}\RP32\A0040393.exe -> Adware.WSearch : Cleaned.
C:\System Volume Information\_restore{49A6A861-7B36-4928-9784-B7C1D64AB817}\RP32\A0040394.exe -> Adware.WSearch : Cleaned.
C:\WINDOWS\system32\8.exe/DeskUn.exe -> Adware.WSearch : Cleaned.
C:\WINDOWS\system32\8.exe/Mrup.exe -> Adware.WSearch : Cleaned.
C:\System Volume Information\_restore{49A6A861-7B36-4928-9784-B7C1D64AB817}\RP32\A0040408.dll -> Adware.Zhongsou : Cleaned.
C:\WINDOWS\system32\8.exe/fshook.dll.zgx -> Adware.Zhongsou : Cleaned.
C:\Program Files\mIRC\zion\plugins\zion_updater.mrc -> Backdoor.Small.o : Cleaned.
C:\System Volume Information\_restore{49A6A861-7B36-4928-9784-B7C1D64AB817}\RP33\A0042594.exe -> Downloader.Agent.alw : Cleaned.
C:\System Volume Information\_restore{49A6A861-7B36-4928-9784-B7C1D64AB817}\RP6\A0000504.EXE -> Downloader.Agent.awf : Cleaned.
C:\System Volume Information\_restore{49A6A861-7B36-4928-9784-B7C1D64AB817}\RP33\A0042589.exe -> Downloader.Agent.axg : Cleaned.
C:\System Volume Information\_restore{49A6A861-7B36-4928-9784-B7C1D64AB817}\RP33\A0042600.exe -> Downloader.Agent.axg : Cleaned.
C:\System Volume Information\_restore{49A6A861-7B36-4928-9784-B7C1D64AB817}\RP36\A0042977.exe -> Downloader.Harnig.bq : Cleaned.
C:\System Volume Information\_restore{49A6A861-7B36-4928-9784-B7C1D64AB817}\RP9\A0002641.exe -> Downloader.Harnig.bq : Cleaned.
C:\System Volume Information\_restore{49A6A861-7B36-4928-9784-B7C1D64AB817}\RP16\A0019341.exe -> Downloader.Small : Cleaned.
C:\System Volume Information\_restore{49A6A861-7B36-4928-9784-B7C1D64AB817}\RP16\A0019395.exe -> Downloader.Small : Cleaned.
C:\System Volume Information\_restore{49A6A861-7B36-4928-9784-B7C1D64AB817}\RP16\A0019345.exe -> Hijacker.Agent.hg : Cleaned.
C:\Documents and Settings\Teo\Cookies\teo@advertising[2].txt -> TrackingCookie.Advertising : Cleaned.
C:\Documents and Settings\Teo\Cookies\teo@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned.
C:\System Volume Information\_restore{49A6A861-7B36-4928-9784-B7C1D64AB817}\RP16\A0019352.dll -> Trojan.Agent.rx : Cleaned.
C:\System Volume Information\_restore{49A6A861-7B36-4928-9784-B7C1D64AB817}\RP36\A0042968.exe -> Trojan.Delf.of : Cleaned.
C:\System Volume Information\_restore{49A6A861-7B36-4928-9784-B7C1D64AB817}\RP30\A0039259.dll -> Trojan.Lineage.alp : Cleaned.
C:\System Volume Information\_restore{49A6A861-7B36-4928-9784-B7C1D64AB817}\RP30\A0040259.dll -> Trojan.Lineage.alp : Cleaned.
C:\System Volume Information\_restore{49A6A861-7B36-4928-9784-B7C1D64AB817}\RP30\A0040285.dll -> Trojan.Lineage.alp : Cleaned.
C:\System Volume Information\_restore{49A6A861-7B36-4928-9784-B7C1D64AB817}\RP30\A0040293.dll -> Trojan.Lineage.alp : Cleaned.
C:\System Volume Information\_restore{49A6A861-7B36-4928-9784-B7C1D64AB817}\RP32\A0040414.dll -> Trojan.Lineage.alp : Cleaned.
C:\System Volume Information\_restore{49A6A861-7B36-4928-9784-B7C1D64AB817}\RP32\A0040418.dll -> Trojan.Lineage.alp : Cleaned.
C:\System Volume Information\_restore{49A6A861-7B36-4928-9784-B7C1D64AB817}\RP32\A0040424.dll -> Trojan.Lineage.alp : Cleaned.
C:\System Volume Information\_restore{49A6A861-7B36-4928-9784-B7C1D64AB817}\RP32\A0040435.dll -> Trojan.Lineage.alp : Cleaned.
C:\System Volume Information\_restore{49A6A861-7B36-4928-9784-B7C1D64AB817}\RP32\A0041435.dll -> Trojan.Lineage.alp : Cleaned.
C:\System Volume Information\_restore{49A6A861-7B36-4928-9784-B7C1D64AB817}\RP32\A0041444.dll -> Trojan.Lineage.alp : Cleaned.
C:\System Volume Information\_restore{49A6A861-7B36-4928-9784-B7C1D64AB817}\RP32\A0041448.dll -> Trojan.Lineage.alp : Cleaned.
C:\System Volume Information\_restore{49A6A861-7B36-4928-9784-B7C1D64AB817}\RP32\A0042571.dll -> Trojan.Lineage.alp : Cleaned.
C:\System Volume Information\_restore{49A6A861-7B36-4928-9784-B7C1D64AB817}\RP33\A0042583.dll -> Trojan.Lineage.alp : Cleaned.
C:\System Volume Information\_restore{49A6A861-7B36-4928-9784-B7C1D64AB817}\RP35\A0042644.dll -> Trojan.Lineage.alp : Cleaned.
C:\System Volume Information\_restore{49A6A861-7B36-4928-9784-B7C1D64AB817}\RP36\A0042869.dll -> Trojan.Lineage.alp : Cleaned.
C:\System Volume Information\_restore{49A6A861-7B36-4928-9784-B7C1D64AB817}\RP36\A0042963.dll -> Trojan.Lineage.alp : Cleaned.
C:\Documents and Settings\Teo\Desktop\Download Folder\SDFix\SDFix\backups\backups.zip/backups/WINLOGON.EXE -> Trojan.Lmir.bai : Cleaned.
C:\Documents and Settings\Teo\Desktop\Download Folder\SDFix\SDFix\backups\backups.zip/backups/regedit.com -> Trojan.Lmir.bai : Cleaned.
C:\Program Files\Common Files\iexplore.pif -> Trojan.Lmir.bai : Cleaned.
C:\Program Files\Internet Explorer\iexplore.com -> Trojan.Lmir.bai : Cleaned.
C:\System Volume Information\_restore{49A6A861-7B36-4928-9784-B7C1D64AB817}\RP30\A0040271.com -> Trojan.Lmir.bai : Cleaned.
C:\System Volume Information\_restore{49A6A861-7B36-4928-9784-B7C1D64AB817}\RP30\A0040275.EXE -> Trojan.Lmir.bai : Cleaned.
C:\System Volume Information\_restore{49A6A861-7B36-4928-9784-B7C1D64AB817}\RP30\A0040276.com -> Trojan.Lmir.bai : Cleaned.
C:\System Volume Information\_restore{49A6A861-7B36-4928-9784-B7C1D64AB817}\RP33\A0042588.exe -> Trojan.Lmir.bai : Cleaned.
C:\System Volume Information\_restore{49A6A861-7B36-4928-9784-B7C1D64AB817}\RP33\A0042599.exe -> Trojan.Lmir.bai : Cleaned.
C:\System Volume Information\_restore{49A6A861-7B36-4928-9784-B7C1D64AB817}\RP36\A0042967.EXE -> Trojan.Lmir.bai : Cleaned.
C:\System Volume Information\_restore{49A6A861-7B36-4928-9784-B7C1D64AB817}\RP36\A0042970.com -> Trojan.Lmir.bai : Cleaned.
C:\System Volume Information\_restore{49A6A861-7B36-4928-9784-B7C1D64AB817}\RP36\A0042971.COM -> Trojan.Lmir.bai : Cleaned.
C:\System Volume Information\_restore{49A6A861-7B36-4928-9784-B7C1D64AB817}\RP36\A0042972.pif -> Trojan.Lmir.bai : Cleaned.
C:\System Volume Information\_restore{49A6A861-7B36-4928-9784-B7C1D64AB817}\RP36\A0042973.com -> Trojan.Lmir.bai : Cleaned.
C:\System Volume Information\_restore{49A6A861-7B36-4928-9784-B7C1D64AB817}\RP36\A0042974.com -> Trojan.Lmir.bai : Cleaned.
C:\System Volume Information\_restore{49A6A861-7B36-4928-9784-B7C1D64AB817}\RP36\A0042975.com -> Trojan.Lmir.bai : Cleaned.
C:\System Volume Information\_restore{49A6A861-7B36-4928-9784-B7C1D64AB817}\RP36\A0042976.com -> Trojan.Lmir.bai : Cleaned.
C:\System Volume Information\_restore{49A6A861-7B36-4928-9784-B7C1D64AB817}\RP36\A0042978.exe -> Trojan.Lmir.bai : Cleaned.
C:\WINDOWS\1.com -> Trojan.Lmir.bai : Cleaned.
C:\WINDOWS\Debug\DebugProgram.exe -> Trojan.Lmir.bai : Cleaned.
C:\WINDOWS\explorer.com -> Trojan.Lmir.bai : Cleaned.
C:\WINDOWS\finder.com -> Trojan.Lmir.bai : Cleaned.
C:\WINDOWS\system32\MSCONFIG.COM -> Trojan.Lmir.bai : Cleaned.
C:\WINDOWS\system32\command.pif -> Trojan.Lmir.bai : Cleaned.
C:\WINDOWS\system32\dxdiag.com -> Trojan.Lmir.bai : Cleaned.
C:\WINDOWS\system32\finder.com -> Trojan.Lmir.bai : Cleaned.
C:\WINDOWS\system32\regedit.com -> Trojan.Lmir.bai : Cleaned.
C:\WINDOWS\system32\rundll32.com -> Trojan.Lmir.bai : Cleaned.
C:\Program Files\Common Files\Microsoft Shared\MSInfo\rejoi.tmp -> Trojan.QQPass.ih : Cleaned.
C:\System Volume Information\_restore{49A6A861-7B36-4928-9784-B7C1D64AB817}\RP15\A0019311.vxd -> Trojan.QQPass.ih : Cleaned.
C:\System Volume Information\_restore{49A6A861-7B36-4928-9784-B7C1D64AB817}\RP16\A0019380.vxd -> Trojan.QQPass.ih : Cleaned.
C:\System Volume Information\_restore{49A6A861-7B36-4928-9784-B7C1D64AB817}\RP16\snapshot\MFEX-1.DAT -> Trojan.QQPass.ih : Cleaned.
C:\System Volume Information\_restore{49A6A861-7B36-4928-9784-B7C1D64AB817}\RP16\snapshot\MFEX-2.DAT -> Trojan.QQPass.ih : Cleaned.
C:\System Volume Information\_restore{49A6A861-7B36-4928-9784-B7C1D64AB817}\RP16\A0019335.exe -> Trojan.Small.ev : Cleaned.
C:\System Volume Information\_restore{49A6A861-7B36-4928-9784-B7C1D64AB817}\RP16\A0019336.exe -> Trojan.Small.ev : Cleaned.
C:\System Volume Information\_restore{49A6A861-7B36-4928-9784-B7C1D64AB817}\RP16\A0019339.exe -> Trojan.Small.ev : Cleaned.
C:\System Volume Information\_restore{49A6A861-7B36-4928-9784-B7C1D64AB817}\RP16\A0019396.exe -> Trojan.WOW.ia : Cleaned.
C:\System Volume Information\_restore{49A6A861-7B36-4928-9784-B7C1D64AB817}\RP16\A0019397.com -> Trojan.WOW.ia : Cleaned.
C:\System Volume Information\_restore{49A6A861-7B36-4928-9784-B7C1D64AB817}\RP16\A0019398.com -> Trojan.WOW.ia : Cleaned.
C:\System Volume Information\_restore{49A6A861-7B36-4928-9784-B7C1D64AB817}\RP16\A0019399.COM -> Trojan.WOW.ia : Cleaned.
C:\System Volume Information\_restore{49A6A861-7B36-4928-9784-B7C1D64AB817}\RP16\A0019400.exe -> Trojan.WOW.ia : Cleaned.
C:\System Volume Information\_restore{49A6A861-7B36-4928-9784-B7C1D64AB817}\RP16\A0019401.pif -> Trojan.WOW.ia : Cleaned.
C:\System Volume Information\_restore{49A6A861-7B36-4928-9784-B7C1D64AB817}\RP16\A0019402.com -> Trojan.WOW.ia : Cleaned.
C:\System Volume Information\_restore{49A6A861-7B36-4928-9784-B7C1D64AB817}\RP16\A0019403.exe -> Trojan.WOW.ia : Cleaned.
::Report end
all the virus have the same name as the system file….. beware of it and hopefully people out there can have basic protection…
Anyway , LONG LIVE THE SLYWARE WARRIOR!!