Forum     

Go Back   Digit Technology Discussion Forum > Software > Software Q&A
Register FAQ Calendar Mark Forums Read

Software Q&A Having trouble with software? Find solutions here


Closed Thread
 
LinkBack Thread Tools Display Modes
Old 18-05-2007, 01:46 AM   #1 (permalink)
Right Off the Assembly Line
 
Join Date: Aug 2005
Location: Chennai
Posts: 7
Post Got infected with win32/dzan.a virus !!


I got a virus win32/Dzan.a and it has infected all my files right from MSconfig and regedit.I use AVG antivirus Pro version.it detects he virus but cud not run a scan since the virus has disabled the av virus scan.,

How to remove the virus.becoz i have most of my business mails and files in here which amounts to more than 3 gb.so pls anyone suggest a way to heal my system.

I have Win xp desktop and i Use AVG antivirus with Firewall.Normally thr was no problem either of virus or spyware issues..
but last week i disabled to check some settings and did not enable it on.

My sister seems to hav donwlaoded some thing from net and damn god....some virus was infected...

The next day i found my sytem floppy drive light was glowing unnecessatily..on dount i enabled my AVG...the next secomd it showed my system is infected with win32/dzan.a worm

Thr was no option of healinng it in avg..so moved to vault.I tried to to a virus sca but avg cant open the virus scanner since it has taken over by virus and now only firewall is working fine.

On seeing the location,i tried deleting some files hwich were infected..now floppy light is not glowing but my AvG says it has detected the virus in this file..and that file.
On online reserach i found sophos would solve problem,so installed sophos antivirus and ran it...it found another virus...win32/nyxem and removed all.but never gave any info abt dzan.a virus.
I tried to enter Msconfig but cant..also cant open regedit also.

So now im doing a bit defender online scan and it says vb worm and win32.dzan.b was detected and it deleted..it didnt mention abt Dzan.a

and i also cant open anyother programs since virus has infected some important files in all programs..also ant unistall the programs,becoz it particulary infects the unistall file only...

So guys what can be done..i dont want o reinstall the OS..since many data are stored,i dont want o lose it...
Plz tell me how to do it??/

Last edited by sosmuthu; 21-05-2007 at 10:57 PM.
sosmuthu is offline  
Advertisements. Register and be a member of the community to get rid of them.
Advertisement

Old 18-05-2007, 01:06 PM   #2 (permalink)
In The Zone
 
Join Date: Oct 2006
Location: Jabalpur
Posts: 325
Default Re: Got infected with win32/dzan.a virus !!

Use Bitdefender Online Scan to remove the virus. AVG always disable.
__________________
http://www.miraclesoftware.in

Authorized Software Distributor - Online Software Shopping
boosters is offline  
Old 18-05-2007, 01:16 PM   #3 (permalink)
Broken In
 
uchiha.sasuke's Avatar
 
Join Date: Nov 2006
Posts: 159
Default Re: Got infected with win32/dzan.a virus !!

tell me d xact problems u r facing in ur pc....u can remove them manually....
__________________
True Power lies within the blood of your peoples revenge...The devils fruit can lead me there...
uchiha.sasuke is offline  
Old 18-05-2007, 03:30 PM   #4 (permalink)
Fresh Stock Since 2005
 
Join Date: Feb 2005
Posts: 1,015
Default Re: Got infected with win32/dzan.a virus !!

Download Hijackthis and run it... Then "Do a System Scan and Save a Logfile" an d then paste the contents of the log file here and\or PM it to me.. then we can teach you to manually remove da vai rush....
__________________
http://www.khattam.info
khattam_ is offline  
Old 20-05-2007, 01:12 AM   #5 (permalink)
Right Off the Assembly Line
 
Join Date: Aug 2005
Location: Chennai
Posts: 7
Default Re: Got infected with win32/dzan.a virus !!

I have Win xp desktop and i Use AVG antivirus with Firewall.Normally thr was no problem either of virus or spyware issues..
but last week i disabled to check some settings and did not enable it on.

My sister seems to hav donwlaoded some thing from net and damn god....some virus was infected...

The next day i found my sytem floppy drive light was glowing unnecessatily..on dount i enabled my AVG...the next secomd it showed my system is infected with win32/dzan.a worm

Thr was no option of healinng it in avg..so moved to vault.I tried to to a virus sca but avg cant open the virus scanner since it has taken over by virus and now only firewall is working fine.

On seeing the location,i tried deleting some files hwich were infected..now floppy light is not glowing but my AvG says it has detected the virus in this file..and that file.
On online reserach i found sophos would solve problem,so installed sophos antivirus and ran it...it found another virus...win32/nyxem and removed all.but never gave any info abt dzan.a virus.
I tried to enter Msconfig but cant..also cant open regedit also.

So now im doing a bit defender online scan and it says vb worm and win32.dzan.b was detected and it deleted..it didnt mention abt Dzan.a

and i also cant open anyother programs since virus has infected some important files in all programs..also ant unistall the programs,becoz it particulary infects the unistall file only...

So guys what can be done..i dont want o reinstall the OS..since many data are stored,i dont want o lose it...
Plz tell me how to do it??/
sosmuthu is offline  
Old 21-05-2007, 10:56 PM   #6 (permalink)
Right Off the Assembly Line
 
Join Date: Aug 2005
Location: Chennai
Posts: 7
Default Re: Got infected with win32/dzan.a virus !!

Guys!! can u help me plz..!!!
sosmuthu is offline  
Old 21-05-2007, 10:59 PM   #7 (permalink)
Rebooting
 
Choto Cheeta's Avatar
 
Join Date: Aug 2004
Location: 220.225.82.33
Posts: 6,266
Default Re: Got infected with win32/dzan.a virus !!

Quote:
Originally Posted by sosmuthu
Guys!! can u help me plz..!!!
Deactivate AVG, go to, http://www.kaspersky.com/virusscanner and run a Online Ondemand scan of the system ..... See if that can find any and whther can clean it or not !!!
__________________
rebooting
ChotoCheeta.com
Choto Cheeta is offline  
Old 23-05-2007, 03:54 PM   #8 (permalink)
Alpha Geek
 
Join Date: Jan 2007
Location: In your hearts
Posts: 828
Default Re: Got infected with win32/dzan.a virus !!

hey you must first download another antivirus which can repair a file like norton, quickheal others update ther defs and just scan.

hey you must first download another antivirus which can repair a file like norton, quickheal others update ther defs and just scan. One more thing you are saying bout different virus name. Every av company has it's own name for one virus, while other has another name thoug virus signature are same. It may be the case that sophos has detected the sam virus which avg is detecting

Last edited by abhijangda; 23-05-2007 at 03:54 PM. Reason: Automerged Doublepost
abhijangda is offline  
Old 23-05-2007, 06:18 PM   #9 (permalink)
Distinguished Member
 
anandk's Avatar
 
Join Date: Mar 2005
Location: Pune
Posts: 3,783
Default Re: Got infected with win32/dzan.a virus !!

Quote:
Originally Posted by sosmuthu
Guys!! can u help me plz..!!!
as sgstd pls post ur hjt logfile here only then can some1 really help u looks like a simple av+as+ccleaner scan is not helping u ...
__________________
> www.TheWindowsClub.com <
= www.WinVistaClub.com =
Microsoft® MVP
anandk is offline  
Old 18-11-2007, 10:53 AM   #10 (permalink)
Right Off the Assembly Line
 
Join Date: Nov 2007
Posts: 1
Default Re: Got infected with win32/dzan.a virus !!

I too have the win32/dzan.a problem....
here is the Log created with Hijack this...
plz help me out


Logfile of HijackThis v1.99.1
Scan saved at 10:46:50 AM, on 11/18/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\PROGRA~1\WINABI~1\FOLDER~1\FGKEY.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\uTorrent\utorrent.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\HijackThis\HijackThis.exe

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [googletalk] C:\Program Files\Google\Google Talk\googletalk.exe /autostart
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [µTorrent] "C:\Program Files\uTorrent\utorrent.exe"
O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\utorrent.exe"
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/par...an_unicode.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/S.../bin/cabsa.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/actives...ree/asinst.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{26361D6D-2357-4CDE-806C-9DB41A20ACF1}: NameServer = 203.145.184.32,202.56.250.5
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: FGKEY - WinAbility® Corporation - C:\PROGRA~1\WINABI~1\FOLDER~1\FGKEY.EXE
sizzler is offline  
Old 18-11-2007, 11:10 AM   #11 (permalink)
-----ATi-----
 
nvidia's Avatar
 
Join Date: May 2007
Location: Bangalore
Posts: 2,322
Default Re: Got infected with win32/dzan.a virus !!

Had a question but didnt want to open a new thread.
I need to remove some virus from my comp.
How much bandwidth will be used if i run a online scan???
__________________
http://twitter.com/akshayms
nvidia is offline  
Old 18-11-2007, 11:56 AM   #12 (permalink)
Alpha Geek
 
Join Date: Jan 2006
Posts: 543
Default Re: Got infected with win32/dzan.a virus !!

When an online scan is being done, initially an amount of MB will be downloaded. These are usually the scanning engine and the updated definitions. It varies for different vendors.
cool_techie_tvm is offline  
Closed Thread

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Infected by Win32:Passma [wrm] darshanwadikar Software Q&A 6 12-06-2006 06:38 PM
Computer infected with Win32/Hidrag.A Virus!!! SHell Software Q&A 6 11-09-2005 08:13 PM
help system infected with Win32.pinfi virus. Mangal Pandey Software Q&A 2 24-08-2005 12:56 PM
Got Infected with Trojan-Downloader.Win32.Small.apc ashisharya Internet & WWW 5 24-03-2005 09:50 AM
Help !! My PC is infected with Win32/Beavis 4350 kl_ravi Software Q&A 11 17-02-2005 09:48 PM

 
Latest Threads
- by clinton
- by Tenida
- by Anorion
- by Niilesh

Advertisement




All times are GMT +5.5. The time now is 02:54 PM.


Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2012, vBulletin Solutions, Inc.

Search Engine Optimization by vBSEO 3.3.2