It is likely a keylogger - please go back and read my previous post - an antivirus will NOT find it
use SPYBOT quickly

I would disconnect from internet, (you may have to be on internet to install Spybot Search and Destroy) then scan, then scan again in safe mode as per Spybot instructions.

It is *probably* taking keylogging info and sending to a site somewhere... that is the purpose of these types of trojans

I am NOT trying to cause widespread panic, but it is a serious threat when one of these gets in, I have first and second hand experience removing this for others. Tend to your machine, especially if you have banking accounts or access to other web sites thru FTP on that machine.
If you watch when it first gets in you can see it connecting to .cn sites to update itself and start running...
I tested a couple infected sites and closely watched the results.
It gets into a web site through FTP by an infected admin, so all access should be closed and known clean backups used. Hopefully these exist on a source seperate from the main site.

A clean machine should also be used to reset all passwords for any admins to get access. Otherwise passwords are still held at the remote site for later reinfection.
It's an ugly ugly situation once it gets in.
I can list other sites infected right now, and have actually reported them to Google but they have not responded by associating a warning with these sites yet.


I do not work here, but the benefits are still awesome
Make your sound your own!