Author Topic: Win32:Sytro-AB [WRM]  (Read 3792 times)

0 Members and 1 Guest are viewing this topic.

uncle-buck

  • Guest
Win32:Sytro-AB [WRM]
« on: June 09, 2009, 07:01:58 PM »
Installed avast! this morning and had it scan my PC. It detected Win32:Sytro-AB [WRM] in a file called pagefile.sys that is located on a supplemental hard drive. I think that's the paging file from an old computer whose drive I added to my existing system.

I tried moving the file to the Virus Chest, but was not successful.

Is this a false positive? How do I determine whether or not that particular paging file is being used by my current system?

Thanks in advance for any help.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33933
  • malware fighter
Re: Win32:Sytro-AB [WRM]
« Reply #1 on: June 09, 2009, 07:34:10 PM »
Hi uncle-buck,

There has been reports of this being a false positive avast found with a ZoneAlarm update, is there a relation there with the supplemental hard-drive?
Aliases:
P2P-Worm.Win32.Sytro.g   VirusBlokAda Vba32
W32/Forlorn-D   Sophos SWEEP virus detection utility
W32/Sytro.G@p2p (exact)   F-PROT ANTIVIRUS for Linux
W32/Sytro.worm.gen!p2p    McAfee Virus Scan for Linux
Win32.HLLW.Sytro   Doctor Web Ltd, Dr.Web (R) for Linux
Worm.P2P.Sytro.G   Clam AntiVirus
Worm.P2p.Sytro.G   Bitdefender/Linux-Console
WORM/Sytro.G1   AVIRA Desktop for UNIX
WORM/Sytro.P2P.F   AVIRA Desktop for UNIX

Try to scan the file in question by uploading to virustotal.com and give us the results as an attached txt file to your next posting, if any of the above scanners at virustotal.com do not flag it and only avast flags it, it could be a false positive because of heuristic scanning,

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

uncle-buck

  • Guest
Re: Win32:Sytro-AB [WRM]
« Reply #2 on: June 09, 2009, 09:23:44 PM »
polonus, I turned off ZoneAlarm's anti-spyware feature, rescanned, and it was not detected - so I think you are correct about it being a false positive. Thanks for your help!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33933
  • malware fighter
Re: Win32:Sytro-AB [WRM]
« Reply #3 on: June 09, 2009, 09:38:32 PM »
Hi uncle-buck,

Thanks for checking that for us, so we could clear that particular issue here in this thread. Somehow because of earlier reactions on the forum that hunch came up with me, and I was right. Well, also thanks for stopping by here. Stay safe and secure on the World Wide Web is my wish and my command,

polonus (malware fighter)
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!