Author Topic: Win32.trojanVGB0FHa0364  (Read 30610 times)

0 Members and 1 Guest are viewing this topic.

whocares

  • Guest
Re: Win32.trojan.VC77CHa0368
« Reply #30 on: March 26, 2005, 10:49:51 PM »

This time this virus is named Win32.trojan.VC77CHa0368.


a)
Please check the exact spelling that avast gives you:
 avast doesn't have such a name in it's Virus definitions file

b) "C:\WINDOWS\regedit.com"
did you rename & start this yourself ?


jazzymina

  • Guest
Re: Win32.trojanVGB0FHa0364
« Reply #31 on: March 27, 2005, 01:49:02 PM »
Hi

About a:  That was the  EXACT definition of the virus and the exact spelling of the virus that Avast mentioned.  As Is said earlier this virus is not well known, or at least I think it is. 

B: I don't think so, but my hijack this log looks strange (2 X NOTEPAD.EXE)
    :(  I think I have something very damaging on my computer. By the way I can't find windows.regedit.com in the Hijack This window screen only in the log.

C; When downloading software for Panda Online VirussScan, Avast said that the
    Panda software was infected by Win32.Kuang32 virus and I should abort
    connection. Huh?

Logfile of HijackThis v1.99.1
Scan saved at 13:20:09, on 27-3-2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sygate\SPF\smc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\The Cleaner\tca.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\The Cleaner\tcm.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Program Files\hijackthis\HijackThis.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\NOTEPAD.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.nl/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKLM\..\Run: [tcactive] C:\Program Files\The Cleaner\tca.exe
O4 - HKLM\..\Run: [tcmonitor] C:\Program Files\The Cleaner\tcm.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [Easy-PrintToolBox] C:\Program Files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE /logon
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\ccleaner.exe" /AUTO
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: SmartLinkService (SLService) -   - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe

« Last Edit: March 27, 2005, 01:54:44 PM by jazzymina »

whocares

  • Guest
Re: Win32.trojanVGB0FHa0364
« Reply #32 on: March 27, 2005, 02:17:54 PM »

was infected by Win32.Kuang32 virus


I think the spelling is still not correct
try saving the Virus-report from avast and COPY&PASTE the relevant parts here...

e.g. there's no "Win32.Kuang32"
but only a
"Win32:Kuang2" or "Win32:kuang"
likewise, avast doesn't detect a
"Win32.trojan<Whatever>

but detects
Win32:Trojan<something>

Look here:
http://www.avast.com/eng/vps_history.html
and here:
http://www.virusbtn.com/perlbin/vgrep/vgrep.cgi?terms=win32.trojan&product=1

-> Are you sure that e.g. "77CHa0368" was not part of the FILE name rather than the VIRUS name ?

*

your Hijackthis-log seems clean now at first glance,
try this:
- update avast (BOTH vps & program, currently 4.6.xxx)
- schedule/run a boot-time scan with avast
- reboot to safeMode & do a complete, thorough & archive scan with avast
- do a complete scan with ESCAN: for link/Info, see "VirusRemoval" below

 ;)

P.S.: KUANG is probably sort of a false positive (PANDA's fault): see forum search or FAQ an www.avast.com for tons of info on this

 ;)
« Last Edit: March 27, 2005, 02:21:31 PM by whocares »

bitchslap

  • Guest
Re: Win32.trojanVGB0FHa0364
« Reply #33 on: January 03, 2006, 01:59:46 PM »
 
    buy a macintosh computer.  you wont have to worry about it ever again :-*
« Last Edit: January 03, 2006, 02:01:24 PM by bitchslap »