1. This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.

Urgent!! Help needed for w32.Myzor.Fk@yf

Discussion in 'Windows - Virus and spyware problems' started by aw_yf, Jul 3, 2006.

  1. aw_yf

    aw_yf Member

    Joined:
    Jul 3, 2006
    Messages:
    21
    Likes Received:
    0
    Trophy Points:
    11
    here is the log from the scan...

    File C:\Documents and Settings\Ho Su Liang\Desktop\SmitfraudFix.zip tagged as not-a-virus:RiskTool.Win32.Reboot.f. No Action Taken.
    File C:\Documents and Settings\Ho Su Liang\Desktop\SmitfraudFix\Reboot.exe tagged as not-a-virus:RiskTool.Win32.Reboot.f. No Action Taken.
    File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\2EA04DCE infected by "Email-Worm.Win32.NetSky.q" Virus. Action Taken: File Deleted.
    File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\30970FA4 infected by "Email-Worm.Win32.NetSky.r" Virus. Action Taken: File Deleted.
    File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\31680EBE infected by "Email-Worm.Win32.NetSky.r" Virus. Action Taken: File Deleted.
    File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\32740198 infected by "Email-Worm.Win32.NetSky.r" Virus. Action Taken: File Deleted.
    File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\60FE6E8A infected by "Email-Worm.Win32.NetSky.d" Virus. Action Taken: File Deleted.
    File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\619823E1 infected by "Email-Worm.Win32.NetSky.q" Virus. Action Taken: File Deleted.
    File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\4D8100F3 infected by "Trojan.Win32.Spooner.f" Virus. Action Taken: File Deleted.
    File C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\4D842AEF infected by "Trojan.Win32.Spooner.f" Virus. Action Taken: File Deleted.
     
  2. tapiiri

    tapiiri Regular member

    Joined:
    Jun 11, 2005
    Messages:
    1,142
    Likes Received:
    0
    Trophy Points:
    46
    Hi aw_yf

    I dont see that virus in your hijack log.

    Escan log is okei, too

    What inform you that there is sdbot.mhh trojan
    And what is files name and its path ?
     
    Last edited: Aug 17, 2006
  3. aw_yf

    aw_yf Member

    Joined:
    Jul 3, 2006
    Messages:
    21
    Likes Received:
    0
    Trophy Points:
    11
    hi,

    ya i'm puzzled as well. I did ACG scan and the result was no infected files. However, I do get AVG pop up "Virus Alert" saying that the file reg32sys.exe is infected with the backdoor.sdbot.mhh trojan.

    In addition when i connected to the internet, I also get the pop up "the windows is shutting down...." and the file is the lsass.exe.

    YF
     
  4. tapiiri

    tapiiri Regular member

    Joined:
    Jun 11, 2005
    Messages:
    1,142
    Likes Received:
    0
    Trophy Points:
    46
    Find and delete if exist:

    reg32sys.exe

     
  5. aw_yf

    aw_yf Member

    Joined:
    Jul 3, 2006
    Messages:
    21
    Likes Received:
    0
    Trophy Points:
    11
  6. tapiiri

    tapiiri Regular member

    Joined:
    Jun 11, 2005
    Messages:
    1,142
    Likes Received:
    0
    Trophy Points:
    46
    Please send a fresh hijacklog
     

Share This Page