Hi,
I'm a webdeveloper. Today I've found out that some of my websites have been edited against my will and without my knowledge. Always the same technique: injection of an iframe at the top or bottom of and index.php or index.html file. Very, very strange, because I'm very strict about Internet safety, I scan regularly and always keep my sites up to date (Wordpress, etc).
I ran some scans while being out the house, and apparently Bitdefender Antivirus has found some problems. Two problems it cannot delete / quarantaine / solved. I've changed all passwords and put back-ups in place, but I'm scared that I'm not protected anymore.
Bitdefender finds two things:
<ScanDetails>
<AffectedItem itemType ="File" path="[system]=]C:\WINDOWS\system32\svchost.exe (full dump)" threatType="virus" threatName="DeepScan:Generic.PWStealer.4C44AE17" action="disinfect" finalStatus= "infected" error= "no action possible"/>
<AffectedItem itemType ="Process" path="[system]=]C:\WINDOWS\system32\svchost.exe (memory dump)" threatType="virus" threatName="Generic.PWStealer.0E96BF1A" action="disinfect" finalStatus= "infected" error= "no action possible"/>
</ScanDetails>
When I reboot, I get a pop-up message saying that the system will be shut down due to an error with services.exe. It gives the error code: 1073741819
I've read the forums here, and saw a similar case. I ran Avis, made a log. Tried to reboot but it doesn't work. It gives me the shutdown symptoms I described. I included some logs: scanlog, avis log, hijack this log...
Basically, I can't do anything. I've tried to run Bitdefender Antivirus 2008 in Safe Mode, but it doesn't seem to be working. Apparently, in Safe Mode there's a permissions problem.
I run a legitimate version of Windows XP, service pack 3. I have a legitimate version of Bitdefender Antivirus 2008.
Can someone please help me? I cannot lose any of my data... I'm starting to panic.
Thanks in advance.