azszaa.exe

Do you know this virus (a small mouth is its icon)? It disconnect my computer from ADSL and create a dialer named Internet without phone number.

A google search for azszaa.exe returns zero hits, which in itself is suspicious and is possibly a randomly generated name.

I assume that avast didn’t detect anything on this trojan dialler ?

If you are not getting a virus warning that you believe is an undetected virus/malware then if you can zip and password protect (‘virus’, will do) the suspect file and send it to virus @ avast.com (no spaces), or send from the chest (after adding it to the User Files section of the chest).

Give a brief outline of the problem (possibly a link to this thread), the fact that you believe it to be an undetected virus/malware and include the password in the body of the email. Some info on the avast version and VPS number (see about avast {right click avast icon}) will also help.

If you haven’t already got this software (freeware), download, install, update and run it, preferably in safe mode.

  1. Ewido, a.k.a. avg anti-spyware If using winXP. or a-Squared free if using win98/ME.

Hi e.valacca,

Run these free scanners too:

Ad-Aware:

http://www.download.com/3000-2144-10045910.html

Spybot Search & Destroy:

http://www.safer-networking.org/en/download/index.html

If none of this helps, please post a HijackThis! log:

http://www.bleepingcomputer.com/tutorials/tutorial42.html

Hi e.vallaca,

The executable mentioned by you or a similar executable can be part of the WORM_RBOT.BJT, look here: http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_RBOT.BJT&VSect=T
or part of W32/Agobot-NK - Spyware Worm: http://www.sophos.com/security/analyses/w32agobotnk.html

Removal information given there as well,

polonus