PDA

View Full Version : Virus/trojan


danman
08-25-2008, 09:01 PM
The past few days Avast has been picking up trojans on a particular PC of mine. I believe it's win32.pophot-am [trj] or some such file.
Anyhow it seems to trigger 2 particual files namely
84jcoasu4g3.exe
update.exe
There is no real hard info on either on google.

Anyhow repeated scans show nothing after removal/deletion.
I'm running Spybot S&D, Superantispyware Pro and Avast constantly and theyre gone... until they (the trigger) pops back up which is 1 or 2 times a day.
Anyhow I looked at my lights on the Router and they were going some so I knew something was using bandwidth.
I ran CurrPorts to see what was running

Nvidia.exe (apparently there is a virus called this too) was in my windows folder and that appeared to be in contact with hotel487.server or some such host. I killed it in Task Manager and then renamed it Nvidia.exe.bak A couple of mins later another thing shown up as trying to contact that server. I killed that too.
The only things running in the background at this time apart from antivirus/antispyware/Spybot was TVersity and FlashGet. My connection was still flashing so I killed both of them. Traffic has been dead for some time now and the virus/trojan hasn't re-appeared (for a couple of hours)

Now, is FlashGet or TVersity downloading something that is causing re-infestation do you think? I read a google report that the Flashget server had been serving up malware back in March of this year so it's not impossible that it could happen again.
Renaming Nvidia.exe to a .bak file has so far had no negative impact so I'm not concerned about that, scans are currently clean but I am concerned that all apps uptodate could not stop re-infection heuristically (if thats the right term?). I've tried using I.E and Firefox (uptodate) I'm scanning with everything I can even crappy Defender.
What more can I do? Have I been compromised? I know avast appears to have caught them but what was using my bandwidth? Was it malign or just TVersity/Flashget doing something and nothing?
Was all of this a false posative. I know Avast is hypersensitive, all manner of Standalone apps etc seem to trigger it but usually good judgement wins the day.
This has left me confused and has led to about 5 nights of worry etc.
Good god when you have this much security you should sleep better at night?
Anyone else have this and know whats what please?

duffy90210
08-26-2008, 06:57 AM
Sound like a rootkit, have you tried doing Avast update, then when it next find the virus, get it to do a scan from DOS when restarting.

danman
08-26-2008, 07:32 AM
Thanks for reply bud,
Avast is 100% up-to-date, however it's only the home user edition so I can't see an option to scan from DOS.
I have however removed the drive and scanned it on 2 other PC's. 1 running the latest up-to-date Kaspersky and the other running NOD 32. Nothing is found.

I believe the combination I have tried are pretty much all the heavy hitters and nothing comes up. Obviously checking in this way doesn't scan active processes but it might catch any tell tale files I would have thought?

Sufficed to say, since disabling the 3 I mentioned above... TVersity, FlashGet and Nvidia.exe about 20 hrs has passed with no new indications/alarms. Whatever was using my bandwidth and throwing up the Avast scanner is I would tentatively say is silenced.
Obviously I use TVersity and FlashGet and I'd like to re-enable them at some point. Could the alarm bells be false positives? As I say, SuperAntispyware and all the others never picked up on anything and I am well aware of how Sensitive Avast can be.

Again, thanks for your input.
Dan

danman
08-26-2008, 10:18 AM
Right, it was deffo TVersity that was using my bandwidth, I just looked in the download folder of TVersity and there was over 3.5GB of crap (streamed feeds according to the TVersity Forum) I had not subscribed to these and they should not have been enabled. I'm mad as fook. At least thats why my lights were blinking on router. Sooooo, I couldn't unsubscribe for some cnutish reason so I deleted it.
Wonder if this will stop my rogue files as well?

hobogobo
08-27-2008, 01:11 PM
avast boot scan in home edition http://www.schmahl.net/?Page=cr/avastbootscan.htm

hobogobo
08-27-2008, 01:13 PM
if not try smitfix but be warned if its attatched to a system file the file will be deleted along with the virus

danman
08-28-2008, 12:18 AM
Thanks very much, never knew Avast had a right click menu.
Learn something new every day
Much obliged

tef89
08-28-2008, 04:17 AM
Boot scan is an awesome feature - AVAST is the best AVP I've ever had - hope it sorts your problems dan ;)

danman
08-29-2008, 12:53 AM
Problem hasn't shown since Monday now. Started a boot scan and all seems clear. Not sure what to make of it all.