Hi, i recently got infected by a trojan dialer virus that seemed to infect my c:\windows\system32\winhab32.dll and c:\windows\system32\adserv.dll file.
it got detected by my norton antivirus but could not repair it. i just downloaded ewido to remove it but somehow it didn't work. and now it seems to have infected other files as well in my temp folder.
Panda online scan:
Incident Status Location
Spyware:spyware/betterinet Not disinfected C:\WINDOWS\SYSTEM32\in10b6s.dll
Adware:adware/block-checker Not disinfected Windows Registry
Spyware:Cookie/Statcounter Not disinfected C:\Documents and Settings\yang\Application Data\Mozilla\Firefox\Profiles\g2d3t1i2.default\cookies.txt[.statcounter.com/]
Spyware:Cookie/myaffiliateprogram Not disinfected C:\Documents and Settings\yang\Application Data\Mozilla\Firefox\Profiles\g2d3t1i2.default\cookies.txt[www.myaffiliateprogram.com/]
Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\yang\Application Data\Mozilla\Firefox\Profiles\g2d3t1i2.default\cookies.txt[.casalemedia.com/]
Spyware:Cookie/Zedo Not disinfected C:\Documents and Settings\yang\Application Data\Mozilla\Firefox\Profiles\g2d3t1i2.default\cookies.txt[.zedo.com/]
Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\yang\Application Data\Mozilla\Firefox\Profiles\g2d3t1i2.default\cookies.txt[.atwola.com/]
Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\yang\Application Data\Mozilla\Firefox\Profiles\g2d3t1i2.default\cookies.txt[.com.com/]
Virus:Trj/Downloader.IHX Disinfected C:\Documents and Settings\yang\Local Settings\Temporary Internet Files\Content.IE5\OTQF85MR\wdinit64[1].exe
Virus:Trj/Downloader.IHX Disinfected C:\Documents and Settings\yang\Local Settings\Temporary Internet Files\Content.IE5\PKCF1DOT\wdinit64[1].exe
Virus:Trj/Downloader.IHX Disinfected C:\Documents and Settings\yang\Local Settings\Temporary Internet Files\Content.IE5\SPEB09QN\wdinit64[1].exe
Spyware:Cookie/Statcounter Not disinfected C:\Documents and Settings\yang\Application Data\Mozilla\Firefox\Profiles\g2d3t1i2.default\cookies.txt[]
Spyware:Cookie/go Not disinfected C:\Documents and Settings\zhiyong\Cookies\zhiyong@go[1].txt
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\zhiyong\Application Data\Mozilla\Firefox\Profiles\2gm6o87l.default\cookies.txt[]
Virus:Trj/Keylog.BR Not disinfected C:\Documents and Settings\zhiyong\Application Data\Mozilla\Firefox\Profiles\2gm6o87l.default\Cache\B0C96152d01[rinst.exe]
Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\david\Cookies\david@atwola[1].txt
Spyware:Cookie/Xmts Not disinfected C:\Documents and Settings\david\Cookies\david@xmts[1].txt
Spyware:Cookie/go Not disinfected C:\Documents and Settings\david\Cookies\david@go[1].txt
Ewido scan :
---------------------------------------------------------
ewido anti-malware - Scan report
---------------------------------------------------------
+ Created on: 2:14:27 AM, 4/9/2006
+ Report-Checksum: 6B545889
+ Scan result:
[504] C:\WINDOWS\system32\winhab32.dll -> Trojan.Agent.qt : Error during cleaning
C:\Documents and Settings\yang\Local Settings\Temporary Internet Files\Content.IE5\N7DZVDWW\wdinit64[1].exe -> Trojan.Dialer.oy : Cleaned with backup
C:\Documents and Settings\yang\Local Settings\Temporary Internet Files\Content.IE5\N7DZVDWW\wdinit64[2].exe -> Trojan.Dialer.oy : Cleaned with backup
:mozilla.21:C:\Documents and Settings\yang\Application Data\Mozilla\Firefox\Profiles\g2d3t1i2.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.22:C:\Documents and Settings\yang\Application Data\Mozilla\Firefox\Profiles\g2d3t1i2.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.23:C:\Documents and Settings\yang\Application Data\Mozilla\Firefox\Profiles\g2d3t1i2.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.24:C:\Documents and Settings\yang\Application Data\Mozilla\Firefox\Profiles\g2d3t1i2.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.31:C:\Documents and Settings\yang\Application Data\Mozilla\Firefox\Profiles\g2d3t1i2.default\cookies.txt -> TrackingCookie.Myaffiliateprogram : Cleaned with backup
:mozilla.34:C:\Documents and Settings\yang\Application Data\Mozilla\Firefox\Profiles\g2d3t1i2.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned with backup
:mozilla.36:C:\Documents and Settings\yang\Application Data\Mozilla\Firefox\Profiles\g2d3t1i2.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned with backup
:mozilla.60:C:\Documents and Settings\yang\Application Data\Mozilla\Firefox\Profiles\g2d3t1i2.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.61:C:\Documents and Settings\yang\Application Data\Mozilla\Firefox\Profiles\g2d3t1i2.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.62:C:\Documents and Settings\yang\Application Data\Mozilla\Firefox\Profiles\g2d3t1i2.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.69:C:\Documents and Settings\yang\Application Data\Mozilla\Firefox\Profiles\g2d3t1i2.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.71:C:\Documents and Settings\yang\Application Data\Mozilla\Firefox\Profiles\g2d3t1i2.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.72:C:\Documents and Settings\yang\Application Data\Mozilla\Firefox\Profiles\g2d3t1i2.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.129:C:\Documents and Settings\yang\Application Data\Mozilla\Firefox\Profiles\g2d3t1i2.default\cookies.txt -> TrackingCookie.Com : Cleaned with backup
::Report End
it got detected by my norton antivirus but could not repair it. i just downloaded ewido to remove it but somehow it didn't work. and now it seems to have infected other files as well in my temp folder.
Panda online scan:
Incident Status Location
Spyware:spyware/betterinet Not disinfected C:\WINDOWS\SYSTEM32\in10b6s.dll
Adware:adware/block-checker Not disinfected Windows Registry
Spyware:Cookie/Statcounter Not disinfected C:\Documents and Settings\yang\Application Data\Mozilla\Firefox\Profiles\g2d3t1i2.default\cookies.txt[.statcounter.com/]
Spyware:Cookie/myaffiliateprogram Not disinfected C:\Documents and Settings\yang\Application Data\Mozilla\Firefox\Profiles\g2d3t1i2.default\cookies.txt[www.myaffiliateprogram.com/]
Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\yang\Application Data\Mozilla\Firefox\Profiles\g2d3t1i2.default\cookies.txt[.casalemedia.com/]
Spyware:Cookie/Zedo Not disinfected C:\Documents and Settings\yang\Application Data\Mozilla\Firefox\Profiles\g2d3t1i2.default\cookies.txt[.zedo.com/]
Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\yang\Application Data\Mozilla\Firefox\Profiles\g2d3t1i2.default\cookies.txt[.atwola.com/]
Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\yang\Application Data\Mozilla\Firefox\Profiles\g2d3t1i2.default\cookies.txt[.com.com/]
Virus:Trj/Downloader.IHX Disinfected C:\Documents and Settings\yang\Local Settings\Temporary Internet Files\Content.IE5\OTQF85MR\wdinit64[1].exe
Virus:Trj/Downloader.IHX Disinfected C:\Documents and Settings\yang\Local Settings\Temporary Internet Files\Content.IE5\PKCF1DOT\wdinit64[1].exe
Virus:Trj/Downloader.IHX Disinfected C:\Documents and Settings\yang\Local Settings\Temporary Internet Files\Content.IE5\SPEB09QN\wdinit64[1].exe
Spyware:Cookie/Statcounter Not disinfected C:\Documents and Settings\yang\Application Data\Mozilla\Firefox\Profiles\g2d3t1i2.default\cookies.txt[]
Spyware:Cookie/go Not disinfected C:\Documents and Settings\zhiyong\Cookies\zhiyong@go[1].txt
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\zhiyong\Application Data\Mozilla\Firefox\Profiles\2gm6o87l.default\cookies.txt[]
Virus:Trj/Keylog.BR Not disinfected C:\Documents and Settings\zhiyong\Application Data\Mozilla\Firefox\Profiles\2gm6o87l.default\Cache\B0C96152d01[rinst.exe]
Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\david\Cookies\david@atwola[1].txt
Spyware:Cookie/Xmts Not disinfected C:\Documents and Settings\david\Cookies\david@xmts[1].txt
Spyware:Cookie/go Not disinfected C:\Documents and Settings\david\Cookies\david@go[1].txt
Ewido scan :
---------------------------------------------------------
ewido anti-malware - Scan report
---------------------------------------------------------
+ Created on: 2:14:27 AM, 4/9/2006
+ Report-Checksum: 6B545889
+ Scan result:
[504] C:\WINDOWS\system32\winhab32.dll -> Trojan.Agent.qt : Error during cleaning
C:\Documents and Settings\yang\Local Settings\Temporary Internet Files\Content.IE5\N7DZVDWW\wdinit64[1].exe -> Trojan.Dialer.oy : Cleaned with backup
C:\Documents and Settings\yang\Local Settings\Temporary Internet Files\Content.IE5\N7DZVDWW\wdinit64[2].exe -> Trojan.Dialer.oy : Cleaned with backup
:mozilla.21:C:\Documents and Settings\yang\Application Data\Mozilla\Firefox\Profiles\g2d3t1i2.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.22:C:\Documents and Settings\yang\Application Data\Mozilla\Firefox\Profiles\g2d3t1i2.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.23:C:\Documents and Settings\yang\Application Data\Mozilla\Firefox\Profiles\g2d3t1i2.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.24:C:\Documents and Settings\yang\Application Data\Mozilla\Firefox\Profiles\g2d3t1i2.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.31:C:\Documents and Settings\yang\Application Data\Mozilla\Firefox\Profiles\g2d3t1i2.default\cookies.txt -> TrackingCookie.Myaffiliateprogram : Cleaned with backup
:mozilla.34:C:\Documents and Settings\yang\Application Data\Mozilla\Firefox\Profiles\g2d3t1i2.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned with backup
:mozilla.36:C:\Documents and Settings\yang\Application Data\Mozilla\Firefox\Profiles\g2d3t1i2.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned with backup
:mozilla.60:C:\Documents and Settings\yang\Application Data\Mozilla\Firefox\Profiles\g2d3t1i2.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.61:C:\Documents and Settings\yang\Application Data\Mozilla\Firefox\Profiles\g2d3t1i2.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.62:C:\Documents and Settings\yang\Application Data\Mozilla\Firefox\Profiles\g2d3t1i2.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.69:C:\Documents and Settings\yang\Application Data\Mozilla\Firefox\Profiles\g2d3t1i2.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.71:C:\Documents and Settings\yang\Application Data\Mozilla\Firefox\Profiles\g2d3t1i2.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.72:C:\Documents and Settings\yang\Application Data\Mozilla\Firefox\Profiles\g2d3t1i2.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.129:C:\Documents and Settings\yang\Application Data\Mozilla\Firefox\Profiles\g2d3t1i2.default\cookies.txt -> TrackingCookie.Com : Cleaned with backup
::Report End