Author Topic: Win 32 Trojano 1320  (Read 4676 times)

0 Members and 1 Guest are viewing this topic.

caloute

  • Guest
Win 32 Trojano 1320
« on: March 28, 2006, 05:49:30 AM »
Hello,

It's the second time I pick up that kind of virus, the first time I formatted the hard drive but that was 2 weeks ago, and this time I would like to try and remove it without having to format.
I am using avast home edition and it has detected Trojano 1320, but even though I try to delete it, when I reboot the pc, it is pretty much still there, I tried to remove it using different software such as spywaredoctor or ewido but it does not work. The virus seems to be stuck to winlogon.dll and svchost.dll.
Is there anyway I can remove it without having to format the hard drive? Thanks for your help.
The virus also seems to affect my ATI graphic card software, and cause an error when booting. What a pain, I whish I could kick some virus maker arse.

Thanks for your help cal

Offline FreewheelinFrank

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 4871
  • I'm a GNU
    • Don't Surf in the Nude!
Re: Win 32 Trojano 1320
« Reply #1 on: March 28, 2006, 09:22:45 AM »
Hi caloute,

Infected winlogon is a sign of a preocess injecting Trojan. Ewido is good at dealing with these, but does require Windows 2000/XP:

http://www.ewido.net/en/

     If you have a previous OS, try a-Squared http://www.emsisoft.com/en/
     Bambleweeny 57 sub-meson brain     Don't Surf in the Nude Blog

caloute

  • Guest
Re: Win 32 Trojano 1320
« Reply #2 on: March 28, 2006, 01:26:49 PM »
Thanks FWF,

Looks like Ewido did not help that much so I have to go with Hijackthis now, and see what happen. But I think it is gonna go down to formating the c drive again.
C:\WINDOWS\System\winlogon.dll is infected and even trying to delete still comes back on restore.
What a pain.

Cal

Caloute

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34051
  • malware fighter
Re: Win 32 Trojano 1320
« Reply #3 on: March 28, 2006, 03:38:02 PM »
Hi caloute,

Here is a nice removal instruction. If you want to translate it, do that with Babelfish, if that won't help ask our forum member Tech through a PM, he can help you with the brazilian translation for the removing part:
http://linhadefensiva.uol.com.br/forum/index.php?s=4d9ea569c764a34f6255d5814c903d37&showtopic=3196&st=0&#entry15416

loads of success,

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!