Author Topic: New Trojan???  (Read 25972 times)

0 Members and 1 Guest are viewing this topic.

Ms. Brooke

  • Guest
New Trojan???
« on: May 06, 2004, 08:01:34 PM »
Running Avast! in the background and a Virus warning message has suddenly popped up.

Name: Win32: Trojano-090 (Trj), File name: C:\windows\System32\iassam.exe
VPS version: 0419-1, 06/05/2004

So... apparently, I've got this virus in  my system, but I can't find any information on it.

I don't know if it is simply resident or if it has launched and if it has, I don't know how to get rid of it.

What do I do???

Ms. Brooke

  • Guest
Re:New Trojan???
« Reply #1 on: May 06, 2004, 08:08:22 PM »
Update...

I've attempted 'repair' and got the following error message: "Cannot process"

Now what???

whocares

  • Guest
Re:New Trojan???
« Reply #2 on: May 06, 2004, 09:01:30 PM »
Hi,

just boot your PC to safe mode (F8-Boot) and then move it to chest with avast, or delete it..

if that doesn't help :

what WIN do you have ? Are all ServicePacks and Windowsupdates applied ?


test the file with OnlineScanners e.g. from Trend, RAV & KAV (see below) to get a more specific name
(you need to temporarily pause AV-Resident Shield/Monitor/Guard to be able to scan the file online)

(If they all don't show it as infected, please send it in a password-protected zip-file to
virus (at) asw (dot) cz
Include the Zip-password and a link to this posting in the mailtext)

 spybot, ad-aware and cwshredder might also help
see www.lurkhere.com ->nicefiles and www.lavasoft.de

-remove the Virus/Malware and it's system modifications according to VirusInfos
from Avast, VGREP, TrendMicro, Kaspersky;
you might also try searching for the virus name or filename with google

general removal procedure:
- disable system restore on Win ME/XP
- kill respective Backdoor/Trojan process with task manager
- search for the file/process names in the registry; remove the malware's startup entries in the registry
- disinfect or (if disinfection is not possible) delete the file; this may be possible only after a reboot

if you still can't remove it, you could post a logfile of Hijackthis here


-Secure your system:
   change passwords, secure shares, install patches/updates for WIN&IE;
   disable ActiveX and Scripting in IE except for know secure sites - and better use a secure browser like Opera or Mozilla
- scan your whole system with updated avast and maybe a 2nd scanner ,e.g. TrendMicro/RAV to check whether your PC is clean ;)
- If needed, reenable system restore on Win ME/XP


Further Details and Links via the board search above ;)
« Last Edit: May 10, 2004, 11:48:15 AM by whocares »

Ms. Brooke

  • Guest
Re:New Trojan???
« Reply #3 on: May 06, 2004, 09:11:56 PM »
I moved it to chest immediately, no sense taking unnecessary chances.

I'm currently running a full system scan just in case.

Sorry for the lack of info...

I'm running WinXP and as far as I know, all updates and patches are applied. The PC is firewalled and nothing is downloaded; not even email. So I don't have any idea how this sucker got in if it's a virus.

I've searched google for both the virus and the filename and come up with nothing.

What I did come up with though is IAS which appears to have something to do with my wireless network. Related???

I find it hard to believe that I'm the first person on the net to discover a new virus... not on this pc anyway.

Any help is useful.

Thanks.

whocares

  • Guest
Re:New Trojan???
« Reply #4 on: May 07, 2004, 11:28:14 AM »
Hi,

obviously it's not a new virus, if avast detects it..

to get more info on it, scan it with the onlinescanners mentioned above.. ;)

Ms. Brooke

  • Guest
Re:New Trojan???
« Reply #5 on: May 07, 2004, 04:28:33 PM »
Are you suggesting that Avast never registers false positives.

I'll keep ya posted.

Offline .: Mac :.

  • Avast Überevangelist
  • Ultra Poster
  • *****
  • Posts: 5093
Re:New Trojan???
« Reply #6 on: May 07, 2004, 04:41:57 PM »
just like any other AV program Avast has false positives.
best way to tell for sure whenever you think avast has falsely detected a virus is to scan with housecall.
"People who are really serious about software should make their own hardware." - Alan Kay

Cassie

  • Guest
Re:New Trojan???
« Reply #7 on: May 09, 2004, 07:25:55 AM »
I have the same problem.  

whocares

  • Guest
Re:New Trojan???
« Reply #8 on: May 09, 2004, 05:26:22 PM »
I have the same problem.  

Hi Cassie,

then the same solutions/advice/questions apply to you ;)

Cassie

  • Guest
Re:New Trojan???
« Reply #9 on: May 10, 2004, 12:55:21 AM »
 :D  Ok, Smarty Pants - I can read, ya'l know.   ;D ;D

On a more serious note, when I go into Safe Mode, the Trojan does NOT show up.  Avast! is the only scanner than shows the Trojano-090 message/warning, I cannot find anything on it anywhere on the web, and I did use every other scanner in the world and none of them have detected the trojan.  

I'm dazed, confused, and feeling a bit vaporish so I will do have a nice lay down.  

!!!

Kerim

  • Guest
Re:New Trojan???
« Reply #10 on: May 10, 2004, 11:43:04 AM »
Just in case I searched my registery (XP home) for iassam.exe

Though it might not help, I put an extract of my search here.

----------------------------------------------------------------
in HKEY_CLASSES_ROOT\CLSID\{6BC09896-0CE6-11D1-BAAE-00C04FC2E20D}:

\InproServer32
(default)               REG_SZ     C:\W.\S.32\iassam.dll
ThreadingModel   REG_SZ     Free

\ProgID
(default)               REG_SZ     IAS.NTSamAuthentication

\TypLib
(default)               REG_SZ     {6BC09890-0CE6-11D1-BAAE-00C04FC2E20D}

\Version
(default)               REG_SZ     1.0

and that is almost repeated in some next keys

---------------------------------------------------------------------------



Kerim

  • Guest
Re:New Trojan???
« Reply #11 on: May 10, 2004, 11:44:39 AM »
Oooops ....   W.= Windows   and  S.32= System32   :)

whocares

  • Guest
Re:New Trojan???
« Reply #12 on: May 10, 2004, 11:47:18 AM »
Then please send in the file in to avast (see above) and tell us what they say about it ;)

Ms. Brooke

  • Guest
Re:New Trojan???
« Reply #13 on: May 11, 2004, 07:52:53 PM »
I sent the file in last week and have received nothing; not even a "we've received your email" notice.

Cassie. Are you running anything wireless?? I'm seriously wondering if we're getting a false positive based on something that Avast isn't used to seeing; wireless networking.

T.

Cassie

  • Guest
Re:New Trojan???
« Reply #14 on: May 12, 2004, 03:50:51 AM »
Nope.  Nothing wireless at all.  And that $&!@# notice keeps popping up.