Author Topic: trojan Win 32:small-caa  (Read 6646 times)

0 Members and 1 Guest are viewing this topic.

dickshar

  • Guest
trojan Win 32:small-caa
« on: October 08, 2006, 06:20:09 PM »
A recent scan resulted in discovery of 2 of these same trojans. As suggested by the program I "moved to chest" Is there any thing  further I need to do? Can I delete them? What is the best way to prevent from getting them? I had 3 trojans last June and they were difficult to delete

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89062
  • No support PMs thanks
Re: trojan Win 32:small-caa
« Reply #1 on: October 08, 2006, 06:23:14 PM »
You have done the right thing, 'first do no harm' don't delete, send virus to the chest and investigate.

There is no rush to delete anything from the chest, a protected area where it can do no harm. Anything that you send to the chest you should leave there for a week or two. If after that time you have suffered no adverse effects from moving these to the chest, scan them again (inside the chest) and if they are still detected as viruses, delete them.

What is the infected file name, where was it found e.g. (C:\windows\system32\infected-file-name.xxx) ?

You could also check the offending/suspect file at: VirusTotal - Multi engine on-line virus scanner
Or Jotti - Multi engine on-line virus scanner if any other scanners here detect them it is less likely to be a false positive. You can't do this with the file in the chest, you will need to move it out.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: trojan Win 32:small-caa
« Reply #2 on: October 08, 2006, 09:47:26 PM »
What is the best way to prevent from getting them?
Use a well configurated and protected computer, updated.
Surf safelly  ;)
The best things in life are free.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89062
  • No support PMs thanks
Re: trojan Win 32:small-caa
« Reply #3 on: October 08, 2006, 10:30:17 PM »
You haven't yet mentioned the file names or location they were found and I suspect they are probably in system folders a common tactic. I'm guessing that you have XP (you didn't say) and if so you need permission to place files in the system folders. So following on from Tech's advice to protect yourself, take pre-emptive measures.

Whilst browsing or collecting email, etc. if you get infected then the malware by default inherits the same permissions that you have for your user account. So if the user account has administrator rights, the malware has administrator rights and can reap havoc. With limited rights the malware can't put files in the system folders, create registry entries, etc. This greatly reduces the potential harm that can be done by an undetected or first day virus, etc.

Check out the link to DropMyRights (in my signature below) - Browsing the Web and Reading E-mail Safely as an Administrator. This obviously applies to those NT based OSes that have administrator settings, winNT, win2k, winXP.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

dickshar

  • Guest
Re: trojan Win 32:small-caa
« Reply #4 on: October 09, 2006, 06:32:04 PM »
I am sorry that I could not get back on line sooner. I do have windows xp. Have been using firefox browser. The virus chest information says  Name: aoo944493 - Original location:c:systemvolume info/restore. The 2nd item;,Name:csinject.exe, Original location:c:programfiles,norton systemworks/cleansweep

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89062
  • No support PMs thanks
Re: trojan Win 32:small-caa
« Reply #5 on: October 09, 2006, 08:32:15 PM »
The c:\System Volume Information folder is a part of the system restore function and as such is protected by windows, the only way to clean infected _restore points is to disable system restore and reboot. This will clear ALL _restore points. Once you have disabled system restore, reboot, scan your PC again and if clear enable system restore.

Win XP-ME - How to disable System Restore

The csinject.exe will have to be treated as outlined above check against the multi engine scanners.

However, a forum search for csinject.exe returns two other hits, this may be false positive, why we suggest confirmation against other scanners http://forum.avast.com/index.php?topic=24077.0.

The other one is a 2004 post but is unrelated to your problem.

Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

dickshar

  • Guest
Re: trojan Win 32:small-caa
« Reply #6 on: October 09, 2006, 10:11:55 PM »
I have removed the system restore points as suggested. I have tried several other virus scanners but they found nothing. I'm not sure I have the technical ability to do the suggestion about the administrator. Thanks for your help.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89062
  • No support PMs thanks
Re: trojan Win 32:small-caa
« Reply #7 on: October 09, 2006, 11:32:09 PM »
This as is pointed out in the other Topic looks like it could be a false positive detection.

It isn't too complicated if you take it a step at a time Print of the instructions on the DropMyRights link so you can follow them step by step whilst off-line. There is also a link to the Microsoft page about DropMyRights, this has many images to illustrate what to do (my little bit tries to simplify setting up the shortcuts), so it would also be advisable to print that also.

If you still feel it is beyond you don't worry unduly you have survived this far, just make sure that your OS, anti-virus, anti-spyware and firewall are up to date. If you have a friend who knows a little about computers, perhaps they might help.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: trojan Win 32:small-caa
« Reply #8 on: October 10, 2006, 01:26:10 AM »
I have removed the system restore points as suggested. I have tried several other virus scanners but they found nothing. I'm not sure I have the technical ability to do the suggestion about the administrator. Thanks for your help.
To know if a file is a false positive, please submit it to JOTTI or VirusTotal and let us know the result. If it is indeed a false positive, send it in a password protected zip to virus@avast.com
Please, mention in the body of the message why you think it is a false positive and the password used.
The best things in life are free.

dickshar

  • Guest
Re: trojan Win 32:small-caa
« Reply #9 on: October 10, 2006, 04:55:02 PM »
I am sorry, but do not understand how to submit the file for review. When I hit "browse" on the site it brings up some of my files but don't know what and how to submit it What am I supposed to put in the box, and how do I get it there.

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: trojan Win 32:small-caa
« Reply #10 on: October 10, 2006, 05:22:36 PM »
As suggested by the program I "moved to chest" Is there any thing  further I need to do?
Sorry, it was not your fault but mine.
If the file is in Chest, right click it and send it from there to Alwil for further analysis.
If you use email communication (smtp) you need to fill the SMTP avast tab of settings before sendind it to Alwil FROM Chest.
The best things in life are free.

dickshar

  • Guest
Re: trojan Win 32:small-caa
« Reply #11 on: October 10, 2006, 06:30:03 PM »
I still don't know what I am doing. I used outlook express to send it to Alwil, and it sent it there. I don't know who or what Alwil is and how I can contact them or what they will do with the file.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89062
  • No support PMs thanks
Re: trojan Win 32:small-caa
« Reply #12 on: October 10, 2006, 06:55:40 PM »
Alwil are the company that created avast!

If you have sent the sample zipped and password protected to virus@avast.com (as Tech outlined above) the job is done. the avast team will only contact you if they need any more information.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security