Author Topic: Bredo  (Read 5200 times)

0 Members and 1 Guest are viewing this topic.

wyv

  • Guest
Bredo
« on: August 31, 2009, 10:10:43 PM »
Hi.

I'm getting messages, one after the other, that Avast has found a virus called Win32:BredoPack (Cryp).

Normally, with the help of Avast (the free version) I can cope with viruses, but now it just keeps popping up. It cannot be repaired and Move to chest doesn't seem to help either.

I use WinXP. The virus is found here: C:\Documents and Settings\All Users\Application Data\Microsoft\Shortcuts\icwsetup.exe

I'm not familiar with viruses at all, so please be patient with me and if you help me, please explain it in a simple way. Thank you.

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: Bredo
« Reply #1 on: August 31, 2009, 10:37:41 PM »
Are you using Windows XP/Vista?
Can you schedule a boot-time scanning?
Start avast! > Right click the skin > Schedule a boot-time scanning.
Select for scanning archives.
Boot.
If infected files are found, it's safer to send them to Chest instead of deleting them.
This way you can further analysis them.

See also: http://www.digitalred.com/avast-boot-time.php

Access denied means, generally, that the file is in use by another process (program) and cannot be repaired/cleaned/moved/handled by avast!
The report file is created automatically in <avast4>\Data\Report\aswBoot.txt
The best things in life are free.

Offline Maxx_original

  • Moderator
  • Super Poster
  • *
  • Posts: 1479
Re: Bredo
« Reply #2 on: August 31, 2009, 10:55:06 PM »
BredoPack is a successor of WaliVun (fake UPS tracking e-mails)... can you upload the sample to www.virustotal.com and post the result here?

XeterPL

  • Guest
Re: Bredo
« Reply #3 on: September 01, 2009, 09:59:08 AM »

hunty

  • Guest
Re: Bredo
« Reply #4 on: September 01, 2009, 01:51:54 PM »
got the exactly same problem yesterday, it kept popping up and moving to chest didn't solve it so I just scanned the PC before windows booted up (how i was recommended by avast) and so far so good

CharleyO

  • Guest
Re: Bredo
« Reply #5 on: September 02, 2009, 09:45:16 AM »
***

Welcome to the forums - wyv, XeterPL, and hunty.   :)

@ wyv & XeterPL,

Have you followed the recommendations and has the problem gotten better?


@ hunty,

Good job of it and let us know if the problem returns.


***