Hello,
I can’t believe that I am back writing ANOTHER post about the same (bleeping) virus that has been bothering me for months :o. Just when I think everything is going okay, the damn thing pops up again.
Avast says that some file in my temp.folder contains a sample of the before mentioned virus.
Apparently it is a Win32.Trojan-gen {other} virus and I already have four samples of it in my virus chest, all of them with different extensions starting with the letter V.
So the name of the current virus is Win32:Trojan-gen {Other} V7BGEHA03260. The strange thing is that it always pops up AFTER a I ran a scan a few days earlier, then the scan doesn’t mention anything, then a few days later: bam,virus.
Also, lately I have been starting to get weird pop-ups of C:\WINDOWS\explorer.exe and other weird Win32.files that are asking my permission to enter my network.
I am posting another hijack this log, so please have a look. I don’t know what to do anymore, either this is a serious virus that Avast can’t remove, or it’s a bug or something. I scanned the files in the viruschest and posted the log below.
Move files to temporary folder: C:\DOCUME~1\YASEMI~1\LOCALS~1\Temp\asw10E.tmp
FileID: 0000000015 Original file name: C:\DOCUME~1\YASEMI~1\LOCALS~1\Temp\VB2G3Qa02420\VB2G3Qa02420 New folder: C:\DOCUME~1\YASEMI~1\LOCALS~1\Temp\asw10E.tmp\15
FileID: 0000000014 Original file name: C:\DOCUME~1\YASEMI~1\LOCALS~1\Temp\V3B0FHa03604\V3B0FHa03604 New folder: C:\DOCUME~1\YASEMI~1\LOCALS~1\Temp\asw10E.tmp\14
FileID: 0000000017 Original file name: C:\DOCUME~1\YASEMI~1\LOCALS~1\Temp\V7BGFHa03260 New folder: C:\DOCUME~1\YASEMI~1\LOCALS~1\Temp\asw10E.tmp\17
FileID: 0000000016 Original file name: C:\DOCUME~1\YASEMI~1\LOCALS~1\Temp\V7CCFHa02608 New folder: C:\DOCUME~1\YASEMI~1\LOCALS~1\Temp\asw10E.tmp\16
C:\DOCUME~1\YASEMI~1\LOCALS~1\Temp\asw10E.tmp\14 Win32:Trojan-gen. {Other}C:\DOCUME~1\YASEMI~1\LOCALS~1\Temp\asw10E.tmp\17 Win32:Trojan-gen. {Other}
C:\DOCUME~1\YASEMI~1\LOCALS~1\Temp\asw10E.tmp\17 Win32:Trojan-gen. {Other}
Action was completed successfully!
Logfile of HijackThis v1.99.1
Scan saved at 15:07:55, on 3-5-2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sygate\SPF\smc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\PROGRA~1\Java\J2RE14~1.2\bin\java.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Alwil Software\Avast4\ashSimpl.exe
C:\Program Files\hijackthis\HijackThis.exe
C:\WINDOWS\system32\NOTEPAD.EXE
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.nl/
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O4 - HKLM..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKLM..\Run: [gcasServ] “C:\Program Files\Microsoft AntiSpyware\gcasServ.exe”
O4 - HKLM..\Run: [Easy-PrintToolBox] C:\Program Files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE /logon
O4 - HKLM..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKCU..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU..\Run: [ccleaner] “C:\Program Files\CCleaner\ccleaner.exe” /AUTO
O4 - HKCU..\Run: [LDM] \Program
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O16 - DPF: {80DD2229-B8E4-4C77-B72F-F22972D723EA} (AvxScanOnline Control) - http://www.bitdefender.com/scan/Msie/bitdefender.cab
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe