A few hours ago, I was online and the Avast resident scanner alerted me that a Win virus had been detected but there wasn’t a prompt as to what I needed to do. I’m new to the avast program. I just ran a scan with Avast and nothing was detected. I’m not sure if my system was infected or if the resident scanner prevented it from coming in. I did run a hijack this log before i ran the scan, I will copy and paste at the bottom. I have run different scans and I keep getting log files that say a lot of areas wasn’t able to be scanned. From what i read about this virus, it disables your protection programs. …
I just tried locating the first logfile and cant find it, I did another hijack this log and it said : For some reason your system denied write access to hosts file. If any hijacked domains are in this file, Hijack this may not be able to fix it.???
The hijack this is in the reply below, too many charaters to post.
Here is the avast logfile for what was found
2/12/2008 7:42:26 AM SYSTEM 1560 Sign of “Win32:Gida [trj]” has been found in mysurvey4u.com/swf/gnida.swf?campaig file.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:03:44 PM, on 2/12/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16575)
Boot mode: Normal
Please edit the url in the first post so as not to have a live link to suspect sites, e.g. http :// mysurvey4u.com/swf/gnida.swf?campaign=me9ntthe&u=1202820144428. This link is also positively detected by the DrWeb link checker, so it isn’t just avast that detects it.
The web shield only has one option, abort connection (see image), which stops the file being downloaded to your system, so it isn’t on your HDD. So you shouldn’t have to do anything else.
There doesn’t appear to be an active firewall on your system, what is your firewall ?
Suspect, do you know what this is (there are lots of google hits for hits for (\SMINST\launcher.exe) ?
O4 - HKLM..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
Okay, I do remember seeing the abort connection. Im not that familar with the Avast program yet. I just wanted to make sure, I was scared to log in into anything. I changed the link so it isnt active above.
I will make sure I have the latest Java. I use the Windows firewall, it says it is on according to the security center, I blocked all imcoming just to be safe. Should I use another firewall instead of the Windows firewall. When I am in the security center it says that the firewall is on but it doesnt detect anti virus or anti malware programs. I use the Avast antivirus, Windows defender, Windows firewall, Ad aware 2007, Spybot S&D, Spyware blaster, CCleaner, Hijack this (for posting the logs), and sometimes I use the online scanners with Trend Micro. I am usually very careful about everything I do on here. My last system was fried with numerous viruses etc, my hubby didnt have protection on there and the inevitable happened, by the time I put protection on there it was too far gone.
The Vista firewall, by default the outbound protection is disabled, even if you choose to enable it you have to manually set the rules that can be tough. Vista Firewall Control, check out this topic for some user friendly help for the Vista Firewall, Outbound protection, http://forum.avast.com/index.php?topic=30234.0
Either that or a third party firewall that provides outbound protection as any malware that manages to get past your defences will have free reign to connect to the internet to either download more of the same, pass your personal data (sensitive or otherwise, user names, passwords, keylogger retrieved data, etc.) or open a backdoor to your computer, so outbound protection is essential.
The Vista Security center won’t detect spybot, spywareblaster or ccleaner as they aren’t anti-virus applications, I don’t know if it would detect windows defender, but it should detect avast.