Author Topic: Win32:Trojan-gen. {VC}  (Read 9086 times)

0 Members and 1 Guest are viewing this topic.

moocow

  • Guest
Win32:Trojan-gen. {VC}
« on: April 16, 2004, 02:30:41 AM »
I am having a problem removing this virus. I was reading an article saying a lot of people using avast are having this problem and that it looks like a false alarm, as I have run an independent scan (Panda) which detected nothing. Any help greatly appreciated. Moocow.

Offline .: Mac :.

  • Avast Überevangelist
  • Ultra Poster
  • *****
  • Posts: 5087
Re:Win32:Trojan-gen. {VC}
« Reply #1 on: April 16, 2004, 02:53:06 AM »
« Last Edit: April 16, 2004, 02:53:40 AM by MacLover2000 »
"People who are really serious about software should make their own hardware." - Alan Kay

whocares

  • Guest
Re:Win32:Trojan-gen. {VC}
« Reply #2 on: April 16, 2004, 03:01:04 AM »
Hi,

"trojan-gen" is a general, rather unhelpful naming of avast which can be anything from rather harmless adware til fully-fledged Backdoor-Server

enter
trojan-gen
into the board-search above and follow the instructions, e.g. :
scannning with KAV, RAV, Trend, Spybot, Ad-Aware and cwshredder;
maybe disabling RESTORE or emptying Caches and TEMP migth already help..

if this doesn't help, come back with more info and post a hijackthis-log

 ;)

stipazer

  • Guest
Re:Win32:Trojan-gen. {VC}
« Reply #3 on: April 16, 2004, 01:27:40 PM »
Hello!
I 've got a problem.
Avast tells me that I 've catch Win32:Trojan-gen. {Other}
And I'm not able to get rid of it.
Please help me

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31072
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re:Win32:Trojan-gen. {VC}
« Reply #4 on: April 16, 2004, 01:30:56 PM »
Tell us where exactly Avast finds it. If you run XP disable system restore.

deanomite

  • Guest
Re:Win32:Trojan-gen. {VC}
« Reply #5 on: April 16, 2004, 10:35:55 PM »
Tell us where exactly Avast finds it. If you run XP disable system restore.

I have a similar to problem with a trojan form ad programs. It seems to come from IE. I am using NetScape 7.1 to avoid the pop ups.

I tried your suggestions, ie disabling ysystem restore and re-enabling it. It doesn't work. The virus keeps showing up when I reoot.

I have SpyBot and ran it. It doesn't help. Pehaps I don't know how to work it right.

Here is what Avast finds. It's a bit complicated, but I was able to copy the four trojans from the virus chest.

Scanning of selected files

Action was completed successfully!

Virus has been detected!
File Name: adbumb2.exe
FileID: 60
Virus Description: Win32:Bridge [Trj]

Scanning of selected files
------------------------------------------------------------------------------------------
Program will try to scan 1 selected file(s) in the Chest

Move files to temporary folder: C:\DOCUME~1\Dean\LOCALS~1\Temp\asw34.tmp
FileID: 0000000060  Original file name: C:\Program Files\STC\adbumb2.exe  New folder: C:\DOCUME~1\Dean\LOCALS~1\Temp\asw34.tmp\60.exe

Scan files in the temporary folder: C:\DOCUME~1\Dean\LOCALS~1\Temp\asw34.tmp
C:\DOCUME~1\Dean\LOCALS~1\Temp\asw34.tmp\60.exe  Win32:Bridge [Trj]
------------------------------------------------------------------------------------------
Action was completed successfully!

Scanning of selected files

Action was completed successfully!

Virus has been detected!
File Name: adbumb2[1].exe
FileID: 59
Virus Description: Win32:Bridge [Trj]

Scanning of selected files
------------------------------------------------------------------------------------------
Program will try to scan 1 selected file(s) in the Chest

Move files to temporary folder: C:\DOCUME~1\Dean\LOCALS~1\Temp\asw35.tmp
FileID: 0000000059  Original file name: C:\Documents and Settings\Dean\Local Settings\Temporary Internet Files\Content.IE5\MH6XSZE5\adbumb2[1].exe  New folder: C:\DOCUME~1\Dean\LOCALS~1\Temp\asw35.tmp\59.exe

Scan files in the temporary folder: C:\DOCUME~1\Dean\LOCALS~1\Temp\asw35.tmp
C:\DOCUME~1\Dean\LOCALS~1\Temp\asw35.tmp\59.exe  Win32:Bridge [Trj]
------------------------------------------------------------------------------------------
Action was completed successfully!

Scanning of selected files

Action was completed successfully!

Virus has been detected!
File Name: ClrSchP070.exe
FileID: 62
Virus Description: Win32:Trojan-gen. {VC}


Scanning of selected files
------------------------------------------------------------------------------------------
Program will try to scan 1 selected file(s) in the Chest

Move files to temporary folder: C:\DOCUME~1\Dean\LOCALS~1\Temp\asw36.tmp
FileID: 0000000062  Original file name: C:\Program Files\STC\ClrSchP070.exe  New folder: C:\DOCUME~1\Dean\LOCALS~1\Temp\asw36.tmp\62.exe

Scan files in the temporary folder: C:\DOCUME~1\Dean\LOCALS~1\Temp\asw36.tmp
C:\DOCUME~1\Dean\LOCALS~1\Temp\asw36.tmp\62.exe  Win32:Trojan-gen. {VC}
------------------------------------------------------------------------------------------
Action was completed successfully!

Scanning of selected files

Action was completed successfully!

Virus has been detected!
File Name: ClrSchP070[1].exe
FileID: 61
Virus Description: Win32:Trojan-gen. {VC}

Scanning of selected files
------------------------------------------------------------------------------------------
Program will try to scan 1 selected file(s) in the Chest

Move files to temporary folder: C:\DOCUME~1\Dean\LOCALS~1\Temp\asw37.tmp
FileID: 0000000061  Original file name: C:\Documents and Settings\Dean\Local Settings\Temporary Internet Files\Content.IE5\8VY1APA3\ClrSchP070[1].exe  New folder: C:\DOCUME~1\Dean\LOCALS~1\Temp\asw37.tmp\61.exe

Scan files in the temporary folder: C:\DOCUME~1\Dean\LOCALS~1\Temp\asw37.tmp
C:\DOCUME~1\Dean\LOCALS~1\Temp\asw37.tmp\61.exe  Win32:Trojan-gen. {VC}
------------------------------------------------------------------------------------------
Action was completed successfully!


I hope you can make sense of this, as I have about given up.

Dean

whocares

  • Guest
Re:Win32:Trojan-gen. {VC}
« Reply #6 on: April 17, 2004, 01:32:01 AM »
Hi,
the above still applies:
enter BRIDGE into the board-search,
and use Onlinescanners, Spybot, AD-Aware & cwshredder

report their findings here..



deanomite

  • Guest
Re:Win32:Trojan-gen. {VC}
« Reply #7 on: May 05, 2004, 03:10:02 AM »
I tried SpyBot, but it didn't work. I deleted it and installed Adaware. It found and deleted the Trogen. Try it.