Author Topic: I got 52 Trojan Horses?  (Read 23261 times)

0 Members and 1 Guest are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33902
  • malware fighter
Re: I got 52 Trojan Horses?
« Reply #15 on: August 02, 2008, 07:06:10 PM »
Hi C0731R ,

I think it is also time to clean up house (computer temp files meant) with ATF Cleaner (yes tick all and fire) and the additional ClearProg to have a go at specific IE, Fx and Windows files.
Get ATF Cleaner here: http://www.majorgeeks.com/downloadget.php?id=4949&file=15&evp=72ef5a5e927b2276e6a5bc34c89d005a

Get ClearProg here: http://www.clearprog.de/site.php?id=10&lang=en

That is a lot of crap less, I do this only a regular basis and it never caused me any harm, because I like my comp nicely crisp and clean, and what I like to save saved through back-up,

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Chim

  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 1151
Re: I got 52 Trojan Horses?
« Reply #16 on: August 02, 2008, 07:44:43 PM »
Well not scanning the swap file  txt files etc
personal choice
now if the exclusion was for .exe .dll etc then we would know there was malware afoot
let us know what you find out

I just sent avast! Tech Support my E-mail inquiry.
Whenever I get a reply from them, I will let you all know what the lowdown is on these "DEFAULT" Standard Shield Exclusions.
Dell Optiplex 780 / Core 2 Duo E8400 3.00 GHz / 4 Gig RAM / Windows XP Pro 32-Bit SP3 / Panda Dome  Free 18.07.00 / MBAM / SAS / NetZero Dial Up / Maxthon MX5 5.2.5.4000

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: I got 52 Trojan Horses?
« Reply #17 on: August 03, 2008, 01:18:48 AM »
"DEFAULT" Standard Shield Exclusions.
?:\PageFile.sys
should be enough ;)
The best things in life are free.

C0731R

  • Guest
Re: I got 52 Trojan Horses?
« Reply #18 on: August 05, 2008, 09:40:48 AM »
Okay, ya'll, I'm back. Looks like this issue has stirred up some discussion; it's also taught me quite a bit about "pamuters" (my son's word) that I hadn't learned yet.

I've scanned most of the 52 flagged & quarantined files what Avast! flagged as Trojan Horses, and as VirusTotal scans the file the only system that indicates that these files are Trojan Horses is Avast!.

The screen gives what appears to be basic file info, like file size, etc., then lists all of the scanning systems used. At the bottom is says (0 exports).


Any other info I can share here? Let me know.

To me, this begs the question: was there a recent Avast! update that is now seeing these files as Trojans, when older versions didn't? I'm thinking that I need to make the changes to have Avast! ignore them in future scans. It appears to me that most or all of these "Trojan" false alarms actually serve some purpose, so at this point, I guess I'll leave them for now; I may go through and kill 'em all later. It appears I've got a lot of "housecleaning" to do. I'll wait for everyone's advice before I decide on anything.

Thanks for all your help, everyone.

thx - cpr

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: I got 52 Trojan Horses?
« Reply #19 on: August 05, 2008, 02:15:15 PM »
"DEFAULT" Standard Shield Exclusions.
?:\PageFile.sys
should be enough ;)

Also see http://forum.avast.com/index.php?topic=37651.msg315169#msg315169

To me, this begs the question: was there a recent Avast! update that is now seeing these files as Trojans, when older versions didn't?
To know if a file is a false positive, please submit it to VirusTotal and let us know the result. If it is indeed a false positive, send it in a password protected zip to virus@avast.com. VirusTotal has a file size limit of 10Mb. Please, mention in the body of the message why you think it is a false positive and the password used. Thanks.

Maybe you need to disable Hide protected operating system files and enable View hidden files and folders to manage the file(s).

As a workaround, you can add these files to the Standard Shield provider (on-access scanning) exclusion list.
Left click the 'a' blue icon, click on the provider icon at left and then Customize. Go to Advanced tab and click on Add button...
You can use wildcards like * and ?. But be careful, you should 'exclude' that many files that let your system in danger.
The best things in life are free.

Hektor

  • Guest
Re: I got 52 Trojan Horses?
« Reply #20 on: August 05, 2008, 02:27:28 PM »
Hi Tech,

I'm new to this forum and I apologise for raising this question below (but I don't know how elese to get my question to you).

I run home windows xp (service pack 3 is in) and i have upto date home edition avast.  my windows security centre shield is saying that i have no virus protection.  I tried your solution which you posted on september 10, 2006, rebooted twice & the shield is still there (saying i have no antivirus). 

do you have any suggestions?

thanks so much

regards
hektor

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: I got 52 Trojan Horses?
« Reply #21 on: August 05, 2008, 02:49:17 PM »
The best things in life are free.

wyrmrider

  • Guest
Re: I got 52 Trojan Horses?
« Reply #22 on: August 05, 2008, 11:48:30 PM »
Hecktor
for some background see this thread
http://forum.avast.com/index.php?topic=37637.0

C0731R

  • Guest
Re: I got 52 Trojan Horses?
« Reply #23 on: August 06, 2008, 10:03:38 AM »
 To know if a file is a false positive, please submit it to VirusTotal and let us know the result. [/quote]

What would you guys need to see from that screen in virustotal? I had a hard time figuring out what it all meant.

thx - cpr

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: I got 52 Trojan Horses?
« Reply #24 on: August 06, 2008, 05:16:20 PM »
What would you guys need to see from that screen in virustotal?
Click in the 'archive' button and browse for the file you want to upload/scan, click to continue... the scanning results will appear, one by one...
The best things in life are free.

C0731R

  • Guest
Re: I got 52 Trojan Horses?
« Reply #25 on: August 07, 2008, 06:08:14 PM »
Please pardon my ignorance, but "Archive" where?

thx - cpr

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: I got 52 Trojan Horses?
« Reply #26 on: August 07, 2008, 09:01:54 PM »
In Portuguese, arquivo.
In English, file.
Sorry, I've mess the words archive and file.
The best things in life are free.

C0731R

  • Guest
Re: I got 52 Trojan Horses?
« Reply #27 on: August 08, 2008, 06:26:41 AM »
What would you guys need to see from that screen in virustotal?
Click in the 'archive' (file) button and browse for the file you want to upload/scan, click to continue... the scanning results will appear, one by one...

So what information exactly do I need to post here? Do I cut/paste every detail of every result for every file scanned? that's my question. Is there some way to just post the results (like a quick & concise list) of what virustotal shows me? If there is, how do I do it.

As I said before, I'm new to this, so I think I may missing something in these steps. Basically, all virustotal tells me is what I stated in my earlier post. (Avast! is the only engine in all of virustotal that sees these as trojans.)

Lastly, if these aren't trojans, how do I get them back into operation so we can play games again? (in other words, out of the chest?) I'll go back and re-read this thread and make sure I'm not missing something.

thanks again for all the input here -

thx - cpr


Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89061
  • No support PMs thanks
Re: I got 52 Trojan Horses?
« Reply #28 on: August 08, 2008, 02:48:11 PM »
In your browsers address bar, just copy and paste the URL for the page with the VirusTotal results in the forum.

From the chest you can restore files, but simply doing that will have them detected again so you have to report them to avast for correction and exclude the files from scanning, etc.

So if it is indeed a false positive, see http://forum.avast.com/index.php?topic=34950.msg293451#msg293451, how to report it to avast! and what to do to exclude them until the problem is corrected.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

C0731R

  • Guest