Author Topic: Saturday 14 Worm detected  (Read 7083 times)

0 Members and 1 Guest are viewing this topic.

Arup

  • Guest
Saturday 14 Worm detected
« on: March 23, 2005, 03:41:24 PM »
Something strange happened today, decided to try out the avast external control tool and while doing a thorough memory scan I got the notice that my memory is infected with Saturday the 14 Worm.

Is this a false alarm? I have been using Avast since the last two years and do regular offline scans with it, however, being this is a memory resident worm, I guess it went undetected.

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67183
Re: Saturday 14 Worm detected
« Reply #1 on: March 23, 2005, 04:50:49 PM »
Most probably, a false positive...
Is it a file or just on memory (running process)?

If it's a file, can you submit it to JOTTI and let us know the result.
If it is indeed a false positive, send it in a password protected zip to virus@avast.com
Please, mention in the body of the message why you think it is a false positive and the password used.
The best things in life are free.

Arup

  • Guest
Re: Saturday 14 Worm detected
« Reply #2 on: March 23, 2005, 04:58:23 PM »
Hi Technical,

Thanks for the fast response, the problem is that it is only indicated when I use the 3rd party Avast External Control tool and set it to thorough memory scan, it tells me to do a boot time scan which I have already done and nothing gets detected there. So my guess would be that it is a false positive, I use Jetico which pops up for any kind of net access so I would know if a worm is trying to connect out to the net but then if it is disguised as System app, it then becomes tricky.

Offline igor

  • Avast team
  • Serious Graphoman
  • *
  • Posts: 11873
    • AVAST Software
Re: Saturday 14 Worm detected
« Reply #3 on: March 23, 2005, 05:10:45 PM »
Where was it detected?

Online DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89679
  • No support PMs thanks
Re: Saturday 14 Worm detected
« Reply #4 on: March 23, 2005, 05:26:52 PM »
If it's a file, can you submit it to JOTTI and let us know the result.

The new url for Jotti is http://virusscan.jotti.org/
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD - 27" external monitor 1440p 2560x1440 resolution - avast! free  24.9.6130 (build 24.9.9452.762) UI 1.0.818/ Firefox, uBlock Origin Lite, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67183
Re: Saturday 14 Worm detected
« Reply #5 on: March 23, 2005, 10:35:02 PM »
Thanks for the fast response

Be used to  8)
avast forum is fast  ;)

The problem is that it is only indicated when I use the 3rd party Avast External Control tool and set it to thorough memory scan

If you start avast antivirus with the option for 'memory scan' checked, do you receive any error?
Can you send an IM to RejZor (the author of Avast External Control) and relate the fact?

The best things in life are free.

Arup

  • Guest
Re: Saturday 14 Worm detected
« Reply #6 on: March 24, 2005, 03:27:17 AM »
Hi Technical,

The detection only happens when I use the Avast external tool which has an option for thorough memory scanning, it doesn't happen if I start Avast conventionally, that is through the regular interface. It isn't a file, it is a certain block of memory, so technically, it cant be sent.

How do I IM Rejzor?

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67183
Re: Saturday 14 Worm detected
« Reply #7 on: March 24, 2005, 03:36:41 AM »
The detection only happens when I use the Avast external tool which has an option for thorough memory scanning, it doesn't happen if I start Avast conventionally, that is through the regular interface. It isn't a file, it is a certain block of memory, so technically, it cant be sent.

It seems that the application is scanning something 'different' way that from the splash screen of avast.
Better is contacting RejZor...

How do I IM Rejzor?
Clickhere  ;)

The best things in life are free.

Arup

  • Guest
Re: Saturday 14 Worm detected
« Reply #8 on: March 24, 2005, 04:19:04 AM »
Thanks Techincal, send him a IM, lets see what he says about this. I am interested, I have already done scans with BitDefender, Clam AV, a2, Ewido and KAV but none of them have detected anything so far.

Offline RejZoR

  • Polymorphic Sheep
  • Serious Graphoman
  • *****
  • Posts: 9412
  • We are supersheep, resistance is futile!
    • RejZoR's Flock of Sheep
Re: Saturday 14 Worm detected
« Reply #9 on: March 24, 2005, 07:48:28 AM »
Thorough Memory scan is also a part of avast! (it's NOT my invention hehe).
It's just that avast! doesn't have any menu controls for this mode,only Normal Memory scan which is perfromed every time before launching Simple Interface.
I belive only Alwil team can help you,because i'm no expert for memory resident malware.
Visit my webpage Angry Sheep Blog

Offline igor

  • Avast team
  • Serious Graphoman
  • *
  • Posts: 11873
    • AVAST Software
Re: Saturday 14 Worm detected
« Reply #10 on: March 24, 2005, 09:36:31 AM »
Arup, avast! shows the ID of the process where the virus was found. Can you identify the process executable (e.g. using the Windows Task Manager, if you use Windows NT/2000/XP)?

Arup

  • Guest
Re: Saturday 14 Worm detected
« Reply #11 on: March 24, 2005, 10:35:49 AM »
Process 992, memory block 0x00CF9000, block size 36864

This is quite interesting, the process identified is bdss.exe, part of the free BitDefender AV I had installed last week just to check if Avast is doing its job. Looks like either this is a false positive or BitDefender has infected program on their servers which I am sure is unlikely.

Offline igor

  • Avast team
  • Serious Graphoman
  • *
  • Posts: 11873
    • AVAST Software
Re: Saturday 14 Worm detected
« Reply #12 on: March 24, 2005, 11:16:39 AM »
I think it's quite likely that BitDefender is keeping decrypted virus signatures in memory. I believe Satuday 14th is an old DOS virus, so it really doesn't seem to be a real infection.

Arup

  • Guest
Re: Saturday 14 Worm detected
« Reply #13 on: March 24, 2005, 11:51:05 AM »
Thanks Igor, dont need BitDefender or any other, got Avast and it runs fine. False alarm or not, had me rattled for a while.