AVG identifes backdoor.small.os

afterburn

New member
New virus/trojan that hijacks DNS settings and replaces all search results from google etc. Not able to get to many anti-spyware sites.

leaves a dll/executable that runs everytime apps launch using app_init, re-registers itself after deleting with hijack this.
File name c:\windows\system32\prefc000.dat also many ini files with keywords in them with the size of 1438 KB with random names.

Avenger removed the dat file. Then hijackthis removed the entry.
 
Hi there.

In future, if possible, please zip or rar the file/s and send them to: detections(AT)spybot.info (Replace AT with @)

Thanks.
 
Back
Top