avast!WEBforum
November 23, 2009, 01:33:45 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: avast! for PDA  - protect your PDA!!
 
   Home   Help Search Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Win32.Bagle.SWQ  (Read 482 times)
mclot
Newbie
*
Offline Offline

Italy Italy

Posts: 3


Personal Message (Offline)
« on: October 05, 2009, 09:40:35 AM »

 Angry

Our Avast 4.8 Professional hasn't found the Win32.Bagle.SWQ virus !!!
AVAST has been disabled (!!!) and other exe are no more recognized.
This virus uses the srosa2.sys file.

Regards.
Massimo
Logged
.: L' arc :.
avast! Evangelist
*****
Offline Offline

Gender: Male
Philippines Philippines

Posts: 1426



Personal Message (Offline)
« Reply #1 on: October 05, 2009, 09:49:57 AM »

Are you able to remove it? If not, please consider using the following:

(1) Malwarebytes Antimalware. Don't forget to update it before running a scan.

(2) Hijack This, how to use:

1. Please download HJTsetup.exe
2. Save HJTsetup.exe [preferably, in your desktop.]
3. Install Hijack This to C:\Program Files\Hijack This.
3. Continue to click Next in the setup until you get to see Select Addition Tasks.
4. Put a check on Create a desktop icon then click Next. Continue following the next prompts until you reach the last part.
6. On the last part, click Finish. Hijack This Main Menu will appear.
7. Click on the Do a system scan and save a logfile button. A scan will be processed and when its done, notepad will appear.
8. On notepad, copy the entire log through clicking on Edit > Select All then click on Edit > Copy.
9. Head back here in the forums and paste the copied files onto your next reply.

NOTE: DO NOT let Hijack This fix anything yet.
Logged
mclot
Newbie
*
Offline Offline

Italy Italy

Posts: 3


Personal Message (Offline)
« Reply #2 on: October 05, 2009, 10:06:14 AM »

Yes, we've been able to remove it using BitDefender online version.
Many other antivirus software can detect it.
I really hope that Avast add support for this very dangerous worm asas.
It isn't nice that a virus can disable Avast !!!
Logged
Sirmer
ALWIL team
Newbie
*
Offline Offline

Czech Republic Czech Republic

Posts: 4


Personal Message (Offline)
« Reply #3 on: October 05, 2009, 10:17:07 AM »

Hello,
viruses are able to disable more antiviruses then just avast.
Can u post this file here pls? zip it with some password like virus and write this password to your post.
Thanks.
Logged
DavidR
avast! Überevangelist
******
Online Online

Gender: Male
United Kingdom United Kingdom

Posts: 37853



Personal Message (Online)
« Reply #4 on: October 05, 2009, 01:33:34 PM »

Send the sample to virus@avast.com zipped and password protected with the password in email body and undetected malware in the subject.
 
Or you can also add the file to the User Files (File, Add) section of the avast chest (if it isn't already in the chest) where it can do no harm and send it from there. A copy of the file/s will remain in the original location, so you will need to take further action and can remove/rename that.
 
Send it from the User Files section of the chest (select the file, right click, email to Alwil Software). It will be uploaded (not actually emailed) to avast when the next avast auto (or manual) update is done.
Logged

Core2Duo E8300/ 2GB Ram/ WinXP ProSP3/ Avast 4.8.1356 Home/ Outpost Firewall Pro 2009/ Firefox 3.5.5 NoScript/ MailWasher Pro 6.5.4/ SuperAntiSpyware Pro/ MalwareBytes AntiMalware/ WinPatrol/ HiJackThis /Drive Image 7.1 /OE6 /SnagIt 9.1 Image Capture
Tech
avast! translator
avast! Technical
******
Offline Offline

Gender: Male
Spain Spain

Posts: 47062



Personal Message (Offline)
« Reply #5 on: October 05, 2009, 01:52:47 PM »

Sirmer, welcome to avast team!
Logged

avast Settings - FAQ - Links
Help me helping you! Sign up & use Mozy to get 2,200 Mb for free remote backup. Enjoy its safety!
mclot
Newbie
*
Offline Offline

Italy Italy

Posts: 3


Personal Message (Offline)
« Reply #6 on: October 05, 2009, 01:57:18 PM »

No doubt about the fact other antiviruses can be disabled by certain viruses    Cry
More, obviously other more celebrated antiviruses will not find this and other viruses too.
But I'm using Avast ... and Avast didn't find this one.
And this the only fact that matters to me as I'm wasting time trying to recover my pc.
That's why I have pointed out the problem, in the hope you'll add something in Avast to avoid this in the future.

I sent to virus@avast.com the zip file "Win32_Bagle.zip", password protected.

Thanks a lot.
Massimo
Logged
DavidR
avast! Überevangelist
******
Online Online

Gender: Male
United Kingdom United Kingdom

Posts: 37853



Personal Message (Online)
« Reply #7 on: October 05, 2009, 02:26:10 PM »

Thanks for trying to help improve detections.
Logged

Core2Duo E8300/ 2GB Ram/ WinXP ProSP3/ Avast 4.8.1356 Home/ Outpost Firewall Pro 2009/ Firefox 3.5.5 NoScript/ MailWasher Pro 6.5.4/ SuperAntiSpyware Pro/ MalwareBytes AntiMalware/ WinPatrol/ HiJackThis /Drive Image 7.1 /OE6 /SnagIt 9.1 Image Capture
CharleyO
avast! Evangelist
*****
Offline Offline

Gender: Male
United States United States

Posts: 4998


avast!4 just keeps getting better all the time!


WWW Personal Message (Offline)
« Reply #8 on: October 05, 2009, 05:42:21 PM »

***

Welcome to the forums, mclot, and thanks for helping with detections.   Smiley

Welcome to the avast team, Sirmer.   Smiley


***
Logged

Thanks to SASHA For My Nice Avatar!
~ It is not important what other people think about you.
    It is important what you truly know about yourself. ~
AMD 64 3200+
Gigabyte GA-K8NS Ultra-939
1 gb RAM
GeForce FX 5800 w/256 ram
XP/SP3 Home
Avast Pro 4.8, Spybot-S&D, SpywareTerminator, ZA Free
M_Arkus
Newbie
*
Offline Offline

Argentina Argentina

Posts: 1


Personal Message (Offline)
« Reply #9 on: November 07, 2009, 02:34:41 PM »

Is really a shame that one month after, avast not detect the Win32.Bagle.SWQ. My computer was infected yesterday and the BitDefender Rescue disk cant solve the problem (sorry for my bad English).
Logged
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.10 | SMF © 2006-2009, Simple Machines LLC Valid XHTML 1.0! Valid CSS!
Page created in 0.079 seconds with 17 queries.