Welcome to SecurityForumz.com!
FAQFAQ      ProfileProfile    Private MessagesPrivate Messages   Log inLog in

AVG Found a Trojan

 
   Security Forums (Home) -> AVG RSS
Next:  Keylogger Detection & Removal?  
Author Message
Lou

External


Since: Feb 07, 2008
Posts: 1



(Msg. 1) Posted: Thu Feb 07, 2008 1:55 pm
Post subject: AVG Found a Trojan
Archived from groups: alt>comp>virus (more info?)

My anti virus program, AVG, automatically scans my computer every morning at
9 AM.
Yesterday it reported that it changed the following files: kernel32.dll;
user32.dll; shell32.dll; ntoskrnl.dll; and hosts, and found the following:
Trojan horse Downloader.VB.AXO and file A0032564.exe. It then deleted this
file.
This morning it again reported that it changed the same five files, but did
not find a Trojan.
However my System Restore has been made useless. It will not make a restore
point and it will not restore my computer to a previously made restore
point.
I went to Start|My Computer|Properties and the "Turn off System Restore" box
was unchecked.
How can I be assured this Trojan is no longer on my computer?
How can I recover "System Restore"?
--
-----
Lou
Of all the things I've lost,
I miss my mind the most

 >> Stay informed about: AVG Found a Trojan 
Back to top
Login to vote
VanguardLH

External


Since: Feb 07, 2008
Posts: 7



(Msg. 2) Posted: Thu Feb 07, 2008 6:58 pm
Post subject: Re: AVG Found a Trojan [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

"Lou" wrote in message news:13qms2nd5up4v37@corp.supernews.com...
>
> AVG reported that it changed the following files: kernel32.dll
> user32.dll
> shell32.dll
> ntoskrnl.dll

You sure it wasn't merely informing you that these system files had
*changed*? Well, if you configure the autoupdate service to download
and install updates without user intervention then you are letting
Microsoft change the state of your host at anytime that Microsoft
wants to do so. Change the settings in the Automatic Update service
to only inform you of new updates, then you decide when you download
them and when you install them.

> hosts

Don't know why it cares about the hosts file. That lists IP addresses
for unresolved hostnames (and is looked up before a DNS query so it
can be used to mask out "bad" sites). There is obviously no malware
in a hosts file, just a list of hostname-to-IPaddress lookups.

> and found the following: Trojan horse Downloader.VB.AXO and file
> A0032564.exe. It then deleted this file.

You sure it didn't *quarantine* the file?

> This morning it again reported that it changed the same five files,
> but did not find a Trojan.
> However my System Restore has been made useless. It will not make a
> restore point and it will not restore my computer to a previously
> made restore point.
> I went to Start|My Computer|Properties and the "Turn off System
> Restore" box was unchecked.
> How can I be assured this Trojan is no longer on my computer?

Use something other than AVG to detect the claimed pest infestation.
Try the online scanners: Symantec Security Check, McAfee FreeScan,
F-Secure Health Check, TrendMicro Housecall, or ESET Online Scanner.

> How can I recover "System Restore"?

You might now have to run "sfc /scannow" (and have your Windows
install CD ready). After that, go visit the Windows Update site.
After that, run an on-demand scan using AVG. It might detect the
change but then rerun the manual scan again to see if it keeps
bitching about the change in system files.

 >> Stay informed about: AVG Found a Trojan 
Back to top
Login to vote
David H. Lipman

External


Since: Jul 04, 2003
Posts: 1735



(Msg. 3) Posted: Thu Feb 07, 2008 9:15 pm
Post subject: Re: AVG Found a Trojan [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

From: "Lou" <louisr.RemoveThis@toast.net>

| My anti virus program, AVG, automatically scans my computer every morning at
| 9 AM.
| Yesterday it reported that it changed the following files: kernel32.dll;
| user32.dll; shell32.dll; ntoskrnl.dll; and hosts, and found the following:
| Trojan horse Downloader.VB.AXO and file A0032564.exe. It then deleted this
| file.

The file changes were due to a recently installed patch.


| This morning it again reported that it changed the same five files, but did
| not find a Trojan.
| However my System Restore has been made useless. It will not make a restore
| point and it will not restore my computer to a previously made restore
| point.
| I went to Start|My Computer|Properties and the "Turn off System Restore" box
| was unchecked.
| How can I be assured this Trojan is no longer on my computer?
| How can I recover "System Restore"?


Download MULTI_AV.EXE from the URL --
http://www.pctipp.ch/ds/28400/28470/Multi_AV.exe

http://www.pctipp.ch/downloads/dl/35905.asp

English:
http://www.raymond.cc/blog/archives/2008/01/09/scan-your-computer-with...ltiple-

To use this utility, perform the following...
Execute; Multi_AV.exe { Note: You must use the default folder C:\AV-CLS }
Choose; Unzip
Choose; Close

Execute; C:\AV-CLS\StartMenu.BAT
{ or Double-click on 'Start Menu' in C:\AV-CLS }

NOTE: You may have to disable your software FireWall or allow WGET.EXE to go through your
FireWall to allow it to download the needed AV vendor related files.

C:\AV-CLS\StartMenu.BAT -- { or Double-click on 'Start Menu' in C:\AV-CLS}
This will bring up the initial menu of choices and should be executed in Normal Mode.
This way all the components can be downloaded from each AV vendor's web site.
The choices are; Sophos, Trend, McAfee, Kaspersky, Exit this menu and Reboot the PC.

You can choose to go to each menu item and just download the needed files or you can
download the files and perform a scan in Normal Mode. Once you have downloaded the files
needed for each scanner you want to use, you should reboot the PC into Safe Mode [F8 key
during boot] and re-run the menu again and choose which scanner you want to run in Safe
Mode. It is suggested to run the scanners in both Safe Mode and Normal Mode.

When the menu is displayed hitting 'H' or 'h' will bring up a more comprehensive PDF help
file.

Additional Instructions:
http://pcdid.com/Multi_AV.htm


* * * Please report back your results * * *


--
Dave
http://www.claymania.com/removal-trojan-adware.html
Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp
 >> Stay informed about: AVG Found a Trojan 
Back to top
Login to vote
David H. Lipman

External


Since: Jul 04, 2003
Posts: 1735



(Msg. 4) Posted: Fri Feb 08, 2008 1:18 am
Post subject: Re: AVG Found a Trojan [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

From: "VanguardLH" <V RemoveThis @nguard.LH>

< snip >

|
>> hosts
|
| Don't know why it cares about the hosts file. That lists IP addresses
| for unresolved hostnames (and is looked up before a DNS query so it
| can be used to mask out "bad" sites). There is obviously no malware
| in a hosts file, just a list of hostname-to-IPaddress lookups.
|

< snip >

It is prudent to monitor the etc/hosts file for alterations. Many forms of malware will
insert line to misdirect legitimate sites to illegitimate/malicious sites.

For example.
You go to your browser and and type; http://www.google.com
Instead of going to Google, the browser goes to a porn site because of entries in the
etc/hosts putting in the static IP address of the porn site.

Another example.
A Trojan places an entry in the etc/hosts file that redirects www.mcafee.com to the
diagnostic responder address [ 127.0.0.1 ]. This way McAfee can not resolve to a web site
and it will fail to get signature updates allowing the Trojan to reamin on the PC because
there are no signatures to find it and McAfee can no longer obtain updates.

Conversely, the etc/hosts file can be used to block access to known malicious sites.
Most well know is the MVP Hosts file
http://www.mvps.org/winhelp2002/hosts.htm

This is because of the default methodology that the OS uses to perform a name to IP address
lookup.

First the OS checks the hosts file. If there is a line item in this table then the OS uses
the IP address found in the table referenced to the host name.
Second is if there is no entry in the hosts table. Then the OS will make a query to a DNS
server to resolve the host name to an IP address.

BTW: I believe there is a registry entry to change the order of how the OS performs name
resolution.

--
Dave
http://www.claymania.com/removal-trojan-adware.html
Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp
 >> Stay informed about: AVG Found a Trojan 
Back to top
Login to vote
Display posts from previous:   
Related Topics:
AVG found Backdoor Trojan - My free version of AVG reports finding the Trojan horse 'BackDoor.Generic2.GZV ' in C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211 \RP207\A0030239.dll I cannot tell whether it cleaned it up or not. There are repeated..

AVG found the following.... - Hi, I am unable to get rid of the following it appears to affect my browser where I can't reach to "search sites" on how to remove. I am unable to remove it with "Trojan Remover" and "AVG" just reports it. Trojan horses; *...

AVG 6.0 Found a virus but - AVG 6.0 Found a virus but it will not let me delete it ! The virus is I-Worm/Mimail it will not let me it to the virus vault.Also I have tried deleting it myself but it says cannot delete file because it is in use.Please can someone help me.Thank in..

AVG and found Virus's - AVG has found and quarantied the following: A0004104.exe dllhost.exe Are these in fact a virus? I have just finished reformatting and re-installing WIN XP. -- Cheers! Pepper's Mum

Found a bug in AVG 6.0, build 518 - Today I came across a file that contained the trojan Backdoor.Subseven, which was not found by AVG 6.0/518. The file had a name such as "xyzabc.avi.com". Because the filename had the .com extension, AVG failed to properly scan the file when I...
   Security Forums (Home) -> AVG All times are: Pacific Time (US & Canada) (change)
Page 1 of 1

 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum



[ Contact us | Terms of Service/Privacy Policy ]