|
OK... I think I am in trouble with this C:\WINDOWS\sys1pie.dll file.... I deleted it out of the windows folder and checked there... it wasn't there so I rebooted and ran the Kaspersky program again and it looks as if the file relocated itself to another folder (c:!Submit)... what is that about? also there seems to be some more keyloggers that are in C:\System Volume Information\ in some restore folders.... I am so worried now!!!! here is the new kaspersky log file...
-------------------------------------------------------------------------------
KASPERSKY ON-LINE SCANNER REPORT
Thursday, August 18, 2005 07:03:02
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky On-line Scanner version: 5.0.67.0
Kaspersky Anti-Virus database last update: 18/08/2005
Kaspersky Anti-Virus database records: 135740
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: standard
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
C:\
D:\
E:\
F:\
Scan Statistics:
Total number of scanned objects: 96703
Number of viruses found: 6
Number of infected objects: 9
Number of suspicious objects: 0
Duration of the scan process: 2801 sec
Infected Object Name - Virus Name
C:\!Submit\sys1pie.dll Infected: Trojan-Spy.Win32.KeyLogger.cq
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\05413BB4.exe Infected: Trojan-Spy.Win32.VB.eh
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\054465B1.ocx Infected: Trojan-Downloader.Win32.VB.ez
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\05470FAD.exe Infected: Trojan-Downloader.Win32.Small.afq
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\0C1743B4.exe Infected: Trojan-Dropper.Win32.SurfSide.a
C:\Program Files\Norton Internet Security\Norton AntiVirus\Quarantine\3647564C.exe Infected: Trojan-Spy.Win32.KeyLogger.ao
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP122\A0022476.dll Infected: Trojan-Spy.Win32.KeyLogger.cq
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP122\A0022500.dll Infected: Trojan-Spy.Win32.KeyLogger.cq
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP46\A0002107.exe Infected: Trojan-Spy.Win32.KeyLogger.ao
Scan process completed.
|