Author Topic: How to interpret virus detection  (Read 4012 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
How to interpret virus detection
« on: February 16, 2015, 02:44:44 PM »
Hi,

my Avast (2015.10.0.2208 with signatures 150216-0) reports suspicious activity (see attachment). There are 2 files mentioned: One is the "object" (ctfxwlauncher) and one the "process" (rundll32). Now which one is the actual virus? Or what is so suspicious about them? Explicit scanning of both files did not find anything.

Thanks in advance,
Alex

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37534
  • Not a avast user
Re: How to interpret virus detection
« Reply #1 on: February 16, 2015, 03:06:38 PM »
win32:Evo-Gen [susp] = Suspicious ... a on access detection only and will not show in any scan

Process is the one starting the activity and Object is the detected file

upload (ctfxwlauncher.exe) and test file here  www.virustotal.com  if tested before, click rescan for a fresh result
post link to scan result here

« Last Edit: February 16, 2015, 04:58:17 PM by Pondus »

REDACTED

  • Guest
Re: How to interpret virus detection
« Reply #2 on: February 16, 2015, 03:32:33 PM »
Thanks for your quick reply and the explanation.
I've already tested the file on virustotal before. Here's the result:
https://www.virustotal.com/de/file/4b74e3aa3ade083f03984e87f8d67da72d9a7bbaaacef23dd1dd28dcfcd14dca/analysis/1424096044/

Rundll32 is also clean.
I'll have to check what it is executing next time the issue appears. Maybe some explorer plugin or the like.

Alex

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: How to interpret virus detection
« Reply #3 on: February 16, 2015, 03:34:47 PM »
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

REDACTED

  • Guest
Re: How to interpret virus detection
« Reply #4 on: February 16, 2015, 03:40:55 PM »
But if it's the interaction between rundll32 and ctfxwlauncher that is suspicious, then reporting ctfxwlauncher as FP could be misleading, couldn't it? I think I'll rather do some more investigation before.

Thanks,
Alex

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: How to interpret virus detection
« Reply #5 on: February 16, 2015, 03:47:25 PM »
1. But if it's the interaction between rundll32 and ctfxwlauncher that is suspicious, then reporting ctfxwlauncher as FP could be misleading, couldn't it?
2. I think I'll rather do some more investigation before.
1. Not really, as the guys in the viruslab have always the final word. ;)
2. Well, that's up to you.
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37534
  • Not a avast user
Re: How to interpret virus detection
« Reply #6 on: February 16, 2015, 04:55:19 PM »
Thanks for your quick reply and the explanation.
I've already tested the file on virustotal before. Here's the result:
https://www.virustotal.com/de/file/4b74e3aa3ade083f03984e87f8d67da72d9a7bbaaacef23dd1dd28dcfcd14dca/analysis/1424096044/

Rundll32 is also clean.
I'll have to check what it is executing next time the issue appears. Maybe some explorer plugin or the like.

Alex
ctfxwlauncher.exe  First submission 2013-11-13 01:07:14 UTC ( 1 year, 3 months ago )




REDACTED

  • Guest
Re: How to interpret virus detection
« Reply #7 on: February 16, 2015, 05:58:35 PM »
Hi Pondus,

sorry, but may I ask you to explain what your last post is supposed to tell me? I don't get it.

Alex

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37534
  • Not a avast user
Re: How to interpret virus detection
« Reply #8 on: February 16, 2015, 06:02:33 PM »
there should be lots of detections on a file that old if it was infected, if very new it may not be detected yet


Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37534
  • Not a avast user
« Last Edit: February 16, 2015, 06:11:23 PM by Pondus »

REDACTED

  • Guest
Re: How to interpret virus detection
« Reply #10 on: February 16, 2015, 06:08:11 PM »
Good point. So my intention was right to look for a different cause.