Here is a list of all the nasty stuff found after clicking 1 x-ray ptp links
X-ray is not responsilbe of that.. it is a site in rotator... but apparently the site target Can, USA, only. and the malware is on site randomly.. this is making very hard to find source. My friend say that, is the new wave of trojan... The bad guy know the ip of po so it will never be present for him when looking for or when approving the ad.
Hope they will arrest this people.....
Detected
--------
Status Object
------ ------
detected: riskware Invader Running process: c:\Program Files\Spyware Doctor\swdsvc.exe
detected: riskware Invader Running process: C:\WINDOWS\system32\nvsvc32.exe
detected: riskware Invader Running process: C:\WINDOWS\system32\control.exe
detected: riskware Invader Running process: C:\WINDOWS\SYSTEM32\winlogon.exe
detected: riskware Invader Running process: C:\WINDOWS\system32\services.exe
detected: riskware Invader Running process: C:\WINDOWS\System32\cisvc.exe
detected: riskware Invader Running process: c:\Program Files\Spyware Doctor\swdsvc.exe
detected: riskware Invader Running process: C:\WINDOWS\System32\svchost.exe
detected: riskware Invader Running process: c:\Program Files\Spyware Doctor\SDLoader.exe
deleted: virus P2P-Worm.Win32.VB.dz File: C:\antivirscan.exe
deleted: virus P2P-Worm.Win32.VB.dz File: C:\bac.exe
deleted: virus P2P-Worm.Win32.VB.dz File: C:\bac2.exe
detected: riskware Invader Running process: C:\WINDOWS\Explorer.EXE
deleted: Trojan program Trojan-Proxy.Win32.Agent.kj File: C:\windows\csrss.exe//PKLite32
detected: riskware Invader Running process: C:\Program Files\WinRAR\WinRAR.exe
deleted: Trojan program Trojan-Dropper.Win32.Delf.xo File: C:\WINDOWS\NDNuninstall7_14.exe
detected: riskware Invader Running process: C:\WINDOWS\system32\svchost.exe
deleted: adware not-a-virus:AdWare.Win32.NaviPromo.gen File: C:\WINDOWS\SYSTEM32\ZPDOQL.EXE//PE_Patch.PECompact//PecBundle//PECompact
detected: riskware Invader Running process: C:\Program Files\Outlook Express\setup50.exe
detected: riskware Invader Running process: C:\WINDOWS\system32\rundll32.exe
detected: riskware Invader Running process: C:\WINDOWS\inf\unregmp2.exe
detected: riskware Invader Running process: C:\WINDOWS\SYSTEM32\cidaemon.exe
deleted: malware Exploit.Java.ByteVerify File: C:\Documents and Settings\Mcgadget\Application Data\Sun\Java\Deployment\cache\6.0\21\1a6fec95-137c23f0/NewSecurityClassLoader.class
deleted: malware Exploit.Java.ByteVerify File: C:\Documents and Settings\Mcgadget\Application Data\Sun\Java\Deployment\cache\6.0\21\1a6fec95-137c23f0/NewURLClassLoader.class
disinfected: malware Exploit.Java.ByteVerify File: C:\Documents and Settings\Mcgadget\Application Data\Sun\Java\Deployment\cache\6.0\28\6d8c825c-6a32d609
disinfected: malware Exploit.Java.ByteVerify File: C:\Documents and Settings\Mcgadget\Application Data\Sun\Java\Deployment\cache\6.0\28\6d8c825c-6a32d609/NewSecurityClassLoader.class
disinfected: malware Exploit.Java.ByteVerify File: C:\Documents and Settings\Mcgadget\Application Data\Sun\Java\Deployment\cache\6.0\28\6d8c825c-6a32d609/NewURLClassLoader.class
disinfected: malware Exploit.Java.ByteVerify File: C:\Documents and Settings\Mcgadget\Application Data\Sun\Java\Deployment\cache\6.0\38\635eaa6-1d4a79ff
disinfected: malware Exploit.Java.ByteVerify File: C:\Documents and Settings\Mcgadget\Application Data\Sun\Java\Deployment\cache\6.0\38\635eaa6-1d4a79ff/NewSecurityClassLoader.class
disinfected: malware Exploit.Java.ByteVerify File: C:\Documents and Settings\Mcgadget\Application Data\Sun\Java\Deployment\cache\6.0\38\635eaa6-1d4a79ff/NewURLClassLoader.class
disinfected: malware Exploit.Java.ByteVerify File: C:\Documents and Settings\Mcgadget\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\java.jar-509f0663-2365b827.zip
disinfected: malware Exploit.Java.ByteVerify File: C:\Documents and Settings\Mcgadget\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\java.jar-509f0663-2365b827.zip/NewSecurityClassLoader.class
disinfected: malware Exploit.Java.ByteVerify File: C:\Documents and Settings\Mcgadget\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\java.jar-509f0663-2365b827.zip/NewURLClassLoader.class
disinfected: malware Exploit.Java.ByteVerify File: C:\Documents and Settings\Mcgadget\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\java.jar-68d0d310-61175c79.zip
disinfected: malware Exploit.Java.ByteVerify File: C:\Documents and Settings\Mcgadget\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\java.jar-7317f359-1ab9a491.zip
deleted: Trojan program Trojan-Downloader.Win32.Zlob.fjh File: C:\WINDOWS\Temp\pcb5k82z.exe//stream//Script
deleted: Trojan program Trojan-Downloader.Win32.Zlob.eoq File: C:\WINDOWS\Temp\pcb5k82z.exe//stream//data0004
deleted: Trojan program Trojan-Proxy.Win32.Agent.kj File: C:\WINDOWS\Temp\~DP1.exe//PKLite32
deleted: Trojan program Trojan-Proxy.Win32.Agent.kj File: C:\WINDOWS\Temp\~DP11.exe//PKLite32
deleted: Trojan program Trojan-Proxy.Win32.Agent.kj File: C:\WINDOWS\Temp\~DP13.exe//PKLite32
deleted: Trojan program Trojan-Proxy.Win32.Agent.kj File: C:\WINDOWS\Temp\~DP15.exe//PKLite32
deleted: Trojan program Trojan-Proxy.Win32.Agent.kj File: C:\WINDOWS\Temp\~DP17.exe//PKLite32
deleted: Trojan program Trojan-Proxy.Win32.Agent.kj File: C:\WINDOWS\Temp\~DP177.exe//PKLite32
deleted: Trojan program Trojan-Proxy.Win32.Agent.kj File: C:\WINDOWS\Temp\~DP179.exe//PKLite32
deleted: Trojan program Trojan-Proxy.Win32.Agent.kj File: C:\WINDOWS\Temp\~DP17B.exe//PKLite32
deleted: Trojan program Trojan-Proxy.Win32.Agent.kj File: C:\WINDOWS\Temp\~DP17D.exe//PKLite32
deleted: Trojan program Trojan-Proxy.Win32.Agent.kj File: C:\WINDOWS\Temp\~DP19.exe//PKLite32
deleted: Trojan program Trojan-Proxy.Win32.Agent.kj File: C:\WINDOWS\Temp\~DP1A7.exe//PKLite32
deleted: Trojan program Trojan-Proxy.Win32.Agent.kj File: C:\WINDOWS\Temp\~DP1B.exe//PKLite32
deleted: Trojan program Trojan-Proxy.Win32.Agent.kj File: C:\WINDOWS\Temp\~DP1D.exe//PKLite32
deleted: Trojan program Trojan-Proxy.Win32.Agent.kj File: C:\WINDOWS\Temp\~DP1F.exe//PKLite32
deleted: Trojan program Trojan-Proxy.Win32.Agent.kj File: C:\WINDOWS\Temp\~DP21.exe//PKLite32
deleted: Trojan program Trojan-Proxy.Win32.Agent.kj File: C:\WINDOWS\Temp\~DP27.exe//PKLite32
deleted: Trojan program Trojan-Proxy.Win32.Agent.kj File: C:\WINDOWS\Temp\~DP3.exe//PKLite32
deleted: Trojan program Trojan-Proxy.Win32.Agent.kj File: C:\WINDOWS\Temp\~DP5.exe//PKLite32
deleted: Trojan program Trojan-Proxy.Win32.Agent.kj File: C:\WINDOWS\Temp\~DP7.exe//PKLite32
deleted: Trojan program Trojan-Proxy.Win32.Agent.kj File: C:\WINDOWS\Temp\~DP9.exe//PKLite32
deleted: Trojan program Trojan-Proxy.Win32.Agent.kj File: C:\WINDOWS\Temp\~DPB.exe//PKLite32
deleted: Trojan program Trojan-Proxy.Win32.Agent.kj File: C:\WINDOWS\Temp\~DPBC.exe//PKLite32
deleted: Trojan program Trojan-Proxy.Win32.Agent.kj File: C:\WINDOWS\Temp\~DPBE.exe//PKLite32
deleted: Trojan program Trojan-Proxy.Win32.Agent.kj File: C:\WINDOWS\Temp\~DPCD.exe//PKLite32
deleted: Trojan program Trojan-Proxy.Win32.Agent.kj File: C:\WINDOWS\Temp\~DPCF.exe//PKLite32
deleted: Trojan program Trojan-Proxy.Win32.Agent.kj File: C:\WINDOWS\Temp\~DPD.exe//PKLite32
deleted: Trojan program Trojan-Proxy.Win32.Agent.kj File: C:\WINDOWS\Temp\~DPD3.exe//PKLite32
deleted: Trojan program Trojan-Proxy.Win32.Agent.kj File: C:\WINDOWS\Temp\~DPE.exe//PKLite32
deleted: Trojan program Trojan-Dropper.Win32.Delf.xo Email message attachment:
This try to turn you computer in a spam mail server....
Mtlgold