Author Topic: Possible Virus  (Read 3898 times)

0 Members and 1 Guest are viewing this topic.

Cutie Mark Surprise

  • Guest
Possible Virus
« on: April 11, 2008, 10:05:44 PM »
Avast picked up a rootkit in Chcfg.exe in windows/system32 and I sent it to avast for analysis. is it a real rootkit or false postive? Just Curious and I uploaded it to Virustotal and Avast is the only one that detected the rootkit in Chcfg.exe. Any ideas?
« Last Edit: April 11, 2008, 10:55:48 PM by Cutie Mark Surprise »

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34065
  • malware fighter
Re: Possible Virus
« Reply #1 on: April 11, 2008, 11:29:40 PM »
Hi Cutie Mark Surprise,

Yes the corrupted files were first seen in Malaysia. You can repair this corrupted file in, and get it from here: http://www.corruptedfilerepair.com/File-Information/ChCfg.exe--.asp
First do this: http://www.precisesecurity.com/how-to/ht-srxp.htm

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Cutie Mark Surprise

  • Guest
Re: Possible Virus
« Reply #2 on: April 11, 2008, 11:43:11 PM »
Is it a false Postive or a corrupted file? Thank you and Avast still flags it as a Rootkit.
« Last Edit: April 11, 2008, 11:48:18 PM by Cutie Mark Surprise »

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34065
  • malware fighter
Re: Possible Virus
« Reply #3 on: April 11, 2008, 11:54:59 PM »
Hi Cutie Mark Surprise,

I is more than likely a False Positive, but I would you to check on the file with IceSword from here:
http://majorgeeks.com/downloadget.php?id=5199&file=10&evp=0d36c3ec48c6373fd5daac78f0c6a417
manual to be found here: http://www.castlecops.com/ (register free to read it),

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Cutie Mark Surprise

  • Guest
Re: Possible Virus
« Reply #4 on: April 12, 2008, 12:38:20 AM »
I tried Ice Sword but it crashed my computer. Is there any other way to check that file?

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34065
  • malware fighter
Re: Possible Virus
« Reply #5 on: April 12, 2008, 12:59:20 AM »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67183
Re: Possible Virus
« Reply #6 on: April 12, 2008, 01:09:18 AM »
To be sure, the better will be test the file against on-line scanners. Submit the file to:
Virustotal
Jotti
There is also Kaspersky File Scanner (The file should not be larger than 1 MB).
The best things in life are free.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34065
  • malware fighter
Re: Possible Virus
« Reply #7 on: April 12, 2008, 01:12:12 AM »
Hi Cute Mark Surprise and Tech,

Check the file you have against the information found here:
http://www.spywaredata.com/spyware/malware/chcfg.exe.php
I lean towards a False Positive, very likely...

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Cutie Mark Surprise

  • Guest
Re: Possible Virus
« Reply #8 on: April 12, 2008, 01:18:01 AM »
On Dr Web it came up clean and I guess it is a false postive. Thank you and I hope they can fix that.  It is a false postive.
« Last Edit: April 14, 2008, 07:47:02 PM by Cutie Mark Surprise »