Author Topic: Malware warnings  (Read 3738 times)

0 Members and 1 Guest are viewing this topic.

sunsets

  • Guest
Malware warnings
« on: July 30, 2008, 06:22:07 PM »
When visiting two web sites, I got the malware warnings, and I aborted the connection both times. After checking the warning log report, this is what was listed:



[L] HTML:Agent-L [Expl] (0)
[L] VBS:Malware-gen (0)

My question is was I protected or did they get on my system?
« Last Edit: July 30, 2008, 07:40:19 PM by sunsets »

wyrmrider

  • Guest
Re: Malware warnings
« Reply #1 on: July 31, 2008, 01:09:47 AM »
OK
what program served up the warnings? Avast?
  what OS?  what firewall? any anti spyware etc installed what else?
are these now in quarantine?  please do not delete/remove but allow your software to put in safe place
can you post a copy of your log?

if you have these two in chest upload to virus total for analysis

then
run a manual update by rt clicking the ball
then schedule a boot time full scan by rt clicking the ball
reboot and scan
post a new log

The C:\Program Files\Alwil Software\Avast4\DATA\report\aswBoot.txt providers a more user friendly summary of the boot-time scan and it should list any detections.
post it back here

here are the instructions to send result to virus total shamelessly copied from DavidR

You could also check the offending/suspect file at: VirusTotal - Multi engine on-line virus scanner and report the findings here. You can't do this with the file securely in the chest, you need to extract it to a temporary (not original) location first, see below.

Create a folder called Suspect in the C:\ drive, e.g. C:\Suspect. Now exclude that folder in the Standard Shield, Customize, Advanced, Add, type (or copy and paste) C:\Suspect\* That will stop the standard shield scanning any file you put in that folder. You should now be able to export any file in the chest to this folder and upload it to VirusTotal without avast alerting.

If it is indeed a false positive, see http://forum.avast.com/index.php?topic=34950.msg293451#msg293451, how to report it to avast! and what to do to exclude them until the problem is corrected.

hopes this gets you started

sunsets

  • Guest
Re: Malware warnings
« Reply #2 on: July 31, 2008, 03:24:12 AM »
Avast served the warnings, while I was on two web sites. I chose to abort the connection. I'm using Vista HP SP1. I'm using Windows Defender Firewall, Spy Sweeper, Spybot S&D, and Ad-Aware Alert.

They are not in quarantine or chest.

I update and run Avast scans daily. It hasn't found them. This morning I tried to do a boot-time scan. In the middle of it, it turned off my computer and had to do a system repair.

The log viewer says they were found in a link to the web sites, not on my computer.

Since I'm new to Avast and trying to figure it out still, I would like to know, if there was a chance of them being on my computer despite me clicking on abort connection, the log viewer saying they were in a link to the web site and not on my computer, and Avast scans not showing anything.

I know these may be stupid questions, but I honestly don't know.

wyrmrider

  • Guest
Re: Malware warnings
« Reply #3 on: July 31, 2008, 03:33:17 AM »
a couple of questions
you have ad-aware paid version
and
spysweeper paid version

correct?
do you have them both "installed" to work in real time- start at boot time?
or do you have one or both of them configured as a "on demand" scanners such as free spybot?

If you have both of them loading at boot time they can conflict with each other)
(but not with avast- that would be two seperate AV's)
so I'll ask that question
have you ever had another AV on your system or did it come with an AV or a Suite installed and if so which one?

you are not likely to be infected- avast's internet download scanner intercepted them
I'd run ccleaner or similar to clean temp files
if they ever try and run the avast run time scanner will catch them again- move to chest next time

let's try that boot time scan again- not completing concerns me

If we can't get it to complete perhaps an avast expert will join us :)
did you see the thread below?
http://forum.avast.com/index.php?topic=37510.0
any dust bunnies - lots of airflow?

sunsets

  • Guest
Re: Malware warnings
« Reply #4 on: July 31, 2008, 03:56:32 AM »
I have the free versions of Ad-Aware and Spy Sweeper. I have Spy Sweeper do a check status at startup. Ad-Aware is not set to start at startup.

When I bought my computer it came with Norton's Internet Security 2008. I deleted it and used the Norton's Removal Tool.

I run CCleaner every night before I turn off my computer.

I don't know about doing a boot-time scan again because of having to do a system repair.

No dust bunnies and good airflow.

wyrmrider

  • Guest
Re: Malware warnings
« Reply #5 on: July 31, 2008, 04:23:25 AM »
YOU USED NORTON REMOVAL TOOL  APPLAUSE
major problem is those that do not or do not think it is necessary
http://forum.avast.com/index.php?topic=37482.0

nothing wrong with the free versions of ad-aware and spy sweeper- they will not conflict with Avast
did you say what browser you use?
If IE I recommend spywareblaster
Immunize since you have spybot- update every Wednesday- today
If IE you can turn on Spybot SD-Helper and try T-timer for real time anti malware protection
any problems post over in the Safernetworking forum :)
Scotty the Win Patrol watchdog takes little resources and will monitor critical system points
ad aware is getting less and less useful but no harm no foul
Malware bytes anti malware is more useful as an on demand scanner
I am not familiar with its real time capabilities -if any in the free version
If it has any do not use at the same time as T-timer

you will find this forum very responsive- post back anytime
how much resources does spy-sweeper use after start up scan is done?
am I correct that you can update spy-sweeper and it will report but not remove anything?
if so not bad to keep around as a back up- they all find different sets of things

sunsets

  • Guest
Re: Malware warnings
« Reply #6 on: July 31, 2008, 04:43:41 AM »
I learned to use the Norton Removal Tool here. I had a couple of false positives earlier this month.

I'm using Firefox and keep it updated. Sorry, I didn't mention it.

Regarding Spybot, do you mean immunize once a week or definition update? If it's definition update, I do it every Friday before I do a scan.

Spy Sweeper, I don't know how much resources it takes or how to check. Yes, with the free, I can get updates (every day) and will do scans. I'm assuming it will report but don't know for sure. With my old XP computer, I had the paid version. So far, the free version has blocked 479 items.

Over the years, I've learned that not one specific program will find everything.

I was looking over my logs and found a boot scan from the day I bought my computer. The scan was aborted in the middle of it. Since it's been over a month since it happened, I can't remember as to the reason why, either by me or my computer shut off.  So, who knows.