Author Topic: Win32:Fabot & Win32:Hupigon-LZO -New to Avast did I infect myself???  (Read 8301 times)

0 Members and 1 Guest are viewing this topic.

JamesZ

  • Guest
SYTEM: Old Dell, XPSP2, 800MHz, 512meg

History: Over 9 months ago I installed 2 really stupid games, and used a 'KEYGEN' that my friend gave me. At the time I was using Zone Alarm internet suite, every thing tested out OK. Over a long slow time frame my internet connection started to become very unstable, And I was getting a lot of intermittent system errors. It got to the time to just shut down and reformat everything and start from scratch.

Since then my friend introduced me to AVAST! (nice program).while reinstalling my programs I came to these 2 dumb games. when I hit the 'keygen' I was supprised when Avast came up with the virus found screen. being new to Avast and not sure which option I should take I decided to click on the [ X ] at the top of the window to close the screen, so I could ask my friend about it later.  I then installed the second game and did the same thing. Then it occurred to me that after closing the screen, the executable program was not stopped.

Questions:
1. By closing the warning box did I circumvent the virus checker and infect my system? -or- Did Avast actually save my system after all by just stopping that part of the executable file?
2. If a 'Trojan' has been allowed to be executed on a system, will Avast still find and remove what ever the Trojan did and fix it? -or- Will it have to be found & removed manually??
3. I have searched the forum and the Avast web site and have not found any sort of manual removal steps. Where can I go to find this if I need it??

According to the Avast Data Base
Virus 1: Win32:Fabot [trJ] Avast database lists it as an executable and Com Trojan.
Virus 2: Win32:Hupigon-LZO [trJ] Avast database lists it as a Com Trojan.

4. What dose this actually mean?

Thanks for any help you can offer.
James

Disclaimer: I'm not a supporter of piracy, however these really simple share ware games
I use as a stress reliever. I would pay the $2.95 for each program, but I just do not like putting
my Credit card number over the internet.

Don't look know,
 but their's a puppy doing the disco on my leg.......
« Last Edit: November 06, 2008, 12:54:06 PM by JamesZ »

Offline FreewheelinFrank

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 4871
  • I'm a GNU
    • Don't Surf in the Nude!
Re: Win32:Fabot & Win32:Hupigon-LZO -New to Avast did I infect myself???
« Reply #1 on: November 06, 2008, 01:33:32 PM »
I believe that even closing the warning window, avast! would not have allowed the files to run, so you should be OK.

For more information, up load the files to VirusTotal: Google the names of the malware detected: some AV companies do better, more informative write-ups than others.

 ;)
     Bambleweeny 57 sub-meson brain     Don't Surf in the Nude Blog

Spiritsongs

  • Guest
Re: Win32:Fabot & Win32:Hupigon-LZO -New to Avast did I infect myself???
« Reply #2 on: November 06, 2008, 07:21:45 PM »
 :)  Hi :

 Any "Keygen" program is an UNDESIRABLE program to have on a computer
 since its programming usually includes "malware", usually a "trojan" . Best to
 COMPLETELY REMOVE those programs and run the "Full Scan" of some
 trustworthy antispyware/antitrojan program(s), such as the FREE Version of
"Malwarebytes' Anti-Malware" from www.malwarebytes.org/mbam.php  AND/OR
 the FREE Ver of "SUPERAntiSpyware" from www.superantispyware.com .

JamesZ

  • Guest
Re: Win32:Fabot & Win32:Hupigon-LZO -New to Avast did I infect myself???
« Reply #3 on: November 11, 2008, 09:26:40 PM »
Thanks for the quick responce.

-I'm wondering if some one can clear something up for me concerning the dastardly 'TROGENS'.
Once a Trojan has been executed, and the 'payload' dumped waitting for the 'trigger or event to activate' it; can virus checkers still find the dumped executables and registry changes, or what ever to remove and clean the system?

-- I have always thought that this was the difference between a 'virus' v.s. a 'Trojan'. Viruses are constantly running and doing there little nasty deeds, which can be caught and corrected.  Where as the Trojan files simply sit and wait for the trigger then all heck breaks lose. Thus making it too late for the virus checker to realize whats going on.... I understand that a good virus checker can detect the Trojan before activation, but what about after it's been executed????


Thanks again for any help offered!

Don't look now,
 but their's a puppy doing the disco on my leg.......