I have avast on my comp that operates WinXP Home edition and I’m running the
Avast 4.5 Home edition. I’ve installed all updates from Microsoft as well as updates from Avast.
Avast has been giving me a virus warning for Win32:Trojan-gen (other). So I scheduled a scan on boot-up and it located it in c:\windows\lmp_klib.dll
I tried the option of repair and repair all and got a Repair error 42060 I opted to move it and the comp booted up as per usual and then I got another warning same as mentioned in the beginning. I tried moving it to the virus chest, which I believe it did, but it still get the same warning upon reboot.
I downloaded and ran the Avast removal program and had it scan but strangely it did not find it.
No luck, turned system restore OFF. Booted in Safe Mode.
Ran the 4 programs… this is the hijack this log:
Logfile of HijackThis v1.99.1
Scan saved at 8:56:12 PM, on 2/19/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Hmmm dunno what schmocht is neither…
I still get the virus/trojan warning sigh
This is my avast log exerpted:
2/15/2005 7:26:03 PM SYSTEM 1084 Sign of “Win32:Trojan-gen. {Other}” has been found in “C:\System Volume Information_restore{03E9A8FF-AF11-4EDA-B0FA-08BD5255C101}\RP102\A0028601.dll” file.
2/15/2005 7:26:04 PM SYSTEM 1084 Sign of “Win32:Trojan-gen. {Other}” has been found in “C:\System Volume Information_restore{03E9A8FF-AF11-4EDA-B0FA-08BD5255C101}\RP102\A0028614.dll” file.
2/15/2005 7:31:22 PM SYSTEM 508 Sign of “Win32:Trojan-gen. {Other}” has been found in “C:\WINDOWS\lmp_klib.dll” file.
2/15/2005 7:32:52 PM SYSTEM 1776 Sign of “Win32:Trojan-gen. {Other}” has been found in “C:\WINDOWS\lmp_klib.dll” file.
2/15/2005 7:49:03 PM SYSTEM 488 Sign of “Win32:Trojan-gen. {Other}” has been found in “C:\WINDOWS\lmp_klib.dll” file.
2/15/2005 8:00:05 PM SYSTEM 1620 Sign of “Win32:Trojan-gen. {Other}” has been found in “C:\WINDOWS\lmp_klib.dll” file.
2/15/2005 8:03:48 PM SYSTEM 1616 Sign of “Win32:Trojan-gen. {Other}” has been found in “C:\WINDOWS\lmp_klib.dll” file.
2/15/2005 8:07:05 PM Yoshiko 2652 Sign of “Win32:Trojan-gen. {Other}” has been found in “C:\Program Files\Alwil Software\Avast4\DATA\moved\lmp_klib.dll” file.
2/15/2005 8:10:37 PM SYSTEM 1692 Sign of “Win32:Trojan-gen. {Other}” has been found in “C:\WINDOWS\lmp_klib.dll” file.
2/15/2005 8:32:37 PM SYSTEM 1692 Sign of “Win32:Trojan-gen. {Other}” has been found in “C:\System Volume Information_restore{03E9A8FF-AF11-4EDA-B0FA-08BD5255C101}\RP127\A0035086.dll” file.
2/16/2005 11:34:18 AM SYSTEM 1780 Sign of “Win32:Trojan-gen. {Other}” has been found in “C:\WINDOWS\lmp_klib.dll” file.
2/16/2005 12:01:35 PM SYSTEM 1780 Sign of “Win32:Trojan-gen. {Other}” has been found in “C:\System Volume Information_restore{03E9A8FF-AF11-4EDA-B0FA-08BD5255C101}\RP127\A0035086.dll” file.
2/17/2005 1:22:47 PM SYSTEM 1784 Sign of “Win32:Trojan-gen. {Other}” has been found in “C:\WINDOWS\lmp_klib.dll” file.
2/18/2005 10:14:40 AM SYSTEM 1900 Sign of “Win32:Trojan-gen. {Other}” has been found in “C:\WINDOWS\lmp_klib.dll” file.
2/18/2005 4:41:47 PM SYSTEM 1988 Sign of “Win32:Trojan-gen. {Other}” has been found in “C:\WINDOWS\lmp_klib.dll” file.
2/18/2005 8:14:47 PM SYSTEM 1872 Sign of “Win32:Trojan-gen. {Other}” has been found in “C:\WINDOWS\lmp_klib.dll” file.
2/19/2005 11:11:56 AM SYSTEM 1780 Sign of “Win32:Trojan-gen. {Other}” has been found in “C:\WINDOWS\lmp_klib.dll” file.
2/19/2005 6:36:19 PM SYSTEM 1784 Sign of “Win32:Trojan-gen. {Other}” has been found in “C:\WINDOWS\lmp_klib.dll” file.
2/19/2005 6:47:52 PM SYSTEM 1648 Sign of “Win32:Trojan-gen. {Other}” has been found in “C:\WINDOWS\lmp_klib.dll” file.
2/19/2005 7:33:44 PM SYSTEM 1776 Sign of “Win32:Trojan-gen. {Other}” has been found in “C:\WINDOWS\lmp_klib.dll” file.
2/19/2005 7:36:48 PM Yoshiko 3480 Sign of “Win32:Trojan-gen. {Other}” has been found in “c:\windows\lmp_klib.dll” file.
2/19/2005 7:41:16 PM SYSTEM 1864 Sign of “Win32:Trojan-gen. {Other}” has been found in “C:\WINDOWS\lmp_klib.dll” file.
2/19/2005 8:15:33 PM SYSTEM 360 Sign of “Win32:Trojan-gen. {Other}” has been found in “C:\WINDOWS\lmp_klib.dll” file.
2/19/2005 8:16:18 PM SYSTEM 360 Sign of “Win32:Trojan-gen. {Other}” has been found in “C:\WINDOWS\LMP_KLIB.DLL” file.
2/19/2005 8:56:04 PM SYSTEM 408 Sign of “Win32:Trojan-gen. {Other}” has been found in “C:\WINDOWS\lmp_klib.dll” file.
2/19/2005 9:32:35 PM SYSTEM 1784 Sign of “Win32:Trojan-gen. {Other}” has been found in “C:\WINDOWS\lmp_klib.dll” file.
2/19/2005 9:38:47 PM SYSTEM 1788 Sign of “Win32:Trojan-gen. {Other}” has been found in “C:\WINDOWS\lmp_klib.dll” file.
From what i can find out, it is a password stealing trojan, it looks for passwords for the following programs:
mICQ
The Bat!
miranda
Trillian
Total Commander
Windows Commander
OK, your problem is, you booted into safe mode, so boot into normal mode, make sure avast is fully up to date, then run a scan (with ‘scan inside archives’ enabled) and delete/move what avast finds,then go to windows update and get all patches (if any), then run these other scanners you said you had, then redo and repost the hijackthis log.
Aftert this change your passwords for the programs mentioned above (if you use any of them)