Author Topic: More and more disappointed  (Read 8529 times)

0 Members and 1 Guest are viewing this topic.

wetabax

  • Guest
More and more disappointed
« on: August 24, 2005, 04:10:22 PM »
 :-[ - I thought always trust in avast!. Well, I sent allready more as 5 new infected files avast didn't recognize as virus. A week after, ok, avast alerts about these files.
Now, I found two files more, update everything in avast and only kasperksy labs recognize the files as virus.
Kaspersky labs log is:
msnmsgr[1].exe - infected by Trojan-Spy.Win32.Banker.abg
albumdefotos.scr - infected by Trojan-Downloader.Win32.Delf.un

Now I know the computer is infected, but I don't know how to clean it... no tool, no on-line scan, nothing that can normalize the situation.

and... of course, virus@avast.com didn't reply anything to me, regardless I ask for it.

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: More and more disappointed
« Reply #1 on: August 24, 2005, 05:45:54 PM »
Alwil team should listen the users crying here and everywhere to a better detection, submition samples, etc.  :'(
Vlk, where are the great news you've promissed us?  :-\
The best things in life are free.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89168
  • No support PMs thanks
Re: More and more disappointed
« Reply #2 on: August 24, 2005, 06:31:47 PM »
Check what is running on your system using HiJackThis also useful as a diagnostic tool - Download HiJackThis.zip - HJT Information HiJackThis Tutorial 1 or HiJackThis Tutorial 2
For an on-line analysis - HiJackThis Log file - On-line Analysis
Ignore any 023 reference to avast processes, this is a hiccup in the HJT 1.99.1 (especially missing file entry for avast), if you need any help with any of the analysis let us know.
OR HiJackThis Log file - On-line Analysis 2

Also see - Advice & Tools for virus/trojan/malware Removal & Prevention and Eddy's Website click the "HiJackThis Section" and also the "Malware removal instructions and applications" section, and follow the directions there and get back to us if you need more help....
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Spiritsongs

  • Guest
Re: More and more disappointed
« Reply #3 on: August 25, 2005, 06:40:42 PM »
 :) In addition to Avast, I also use the good & FREE "Ewido"
     available from www.ewido.net/en ; it "specializes" in
     detecting and removing trojans,worms,dialers, etc .

wetabax

  • Guest
Re: More and more disappointed
« Reply #4 on: August 25, 2005, 08:06:59 PM »
ok. now I'm using 4.6.691 / 0534-3 and this VPS checked both (mentioned in my first post) files correctly as virus.
But, and what about the svchosts files created by the virus? I'm away from the infected computer, but one of this virus creates a run line to svchosts.exe file...
I hope avast! will alert about these files too.

thanks for prompt updating... ::)

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89168
  • No support PMs thanks
Re: More and more disappointed
« Reply #5 on: August 25, 2005, 08:24:47 PM »
You should be able to se that in HJT and by ticking the fix box it should remove the run command.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

wetabax

  • Guest
Re: More and more disappointed
« Reply #6 on: September 01, 2005, 08:18:34 PM »
sorry to open this thread again, but only for your concern:

I sent to virus@avast, email below 25/august, and resent 28/august:
[...]
text sent in last message:
25/8/2005 20:38:58
I really don't know what happens with avast, but with avast completely updated, it can't recognize this file as virus, but norton does.
 
Origem: C:\Documents and Settings\Proprietário\Desktop\iexplore.exe
Clique para obter mais informações sobre essa ameaça: W32.IRCBot
[...]

Well, I gave name of the virus, file, password etc.

Only now, in VPS version 535-2, Avast noted that the file is a virus...

And how many posts did I receive from virus lab about all this issue?
none.
 ???

Offline Vlk

  • Avast CEO
  • Serious Graphoman
  • *
  • Posts: 11658
  • Please don't send me IM's. Email only. Thx.
    • ALWIL Software
Re: More and more disappointed
« Reply #7 on: September 02, 2005, 08:36:49 AM »
So, that means it was added 5 days after you submitted it. What do you dislike about this?
If at first you don't succeed, then skydiving's not for you.

Omar

  • Guest
Re: More and more disappointed
« Reply #8 on: September 02, 2005, 10:19:02 AM »
Vlk, didn`t you say that "Lots of things will change soon"?

could you give us some clues as to what this means ;D

Offline Vlk

  • Avast CEO
  • Serious Graphoman
  • *
  • Posts: 11658
  • Please don't send me IM's. Email only. Thx.
    • ALWIL Software
Re: More and more disappointed
« Reply #9 on: September 02, 2005, 10:30:03 AM »
To start, it means the following:

1. we're hiring new people to the virus lab. That should result in (at least) faster response times

2. we're working on a new virus submission system

3. we're making some changes to the structure of the VPS file as well as the processes that generate it.


I can't say much about the exact schedule because I don't directly manage this but it should be a matter of weeks (hopefully).
If at first you don't succeed, then skydiving's not for you.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33925
  • malware fighter
Re: More and more disappointed
« Reply #10 on: September 02, 2005, 10:52:04 AM »
Hi Vlk,

This is good news, well I think false positives is an important thing here too. Everything has to be checked. That is why it is a time consuming thing.
Isn't it?

greets,

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Omar

  • Guest
Re: More and more disappointed
« Reply #11 on: September 02, 2005, 11:48:47 AM »
That is very good news Vlk. This new file submission system-I hope it will mean that samples can be sent online ;)

I hope the new system will mean that samples are added much quicker than before. This will please many people. In addition I hope that all samples are added regardless of whether some are more dangerous than others.

Offline XMAS

  • Avast translator
  • Super Poster
  • ***
  • Posts: 1211
  • Santa is watching you ;)
    • avast! in Bulgarian
Re: More and more disappointed
« Reply #12 on: September 02, 2005, 01:21:05 PM »
:o :o :o
Well from your word Vlk I understand that there will be a lot of  new thing this autumn  ;D
I am very curious what will be the new virus submission system  ::)
« Last Edit: September 02, 2005, 01:23:03 PM by .:X:M:A:S:. »
You've Got To Get Close To The Flame To See What It's Made Of...

wetabax

  • Guest
Re: More and more disappointed
« Reply #13 on: September 02, 2005, 04:32:51 PM »
So, that means it was added 5 days after you submitted it. What do you dislike about this?

Well, Mr Vlk, if it were a new virus and avast! would be the first company to discover it, nothing. But, a virus still added in other softwares, and considered critical, sent to you with virus name, all information needed... I found 5 days a little too much. But maybe I'm wrong.

And sent twice - don't forget!

And no answer from viruslab (e.g.: email received, false positive, critical, danger, hi, goodbye - any word would be a nice word)

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: More and more disappointed
« Reply #14 on: September 02, 2005, 10:00:05 PM »
Well, Mr Vlk, if it were a new virus and avast! would be the first company to discover it, nothing. But, a virus still added in other softwares, and considered critical, sent to you with virus name, all information needed... I found 5 days a little too much. But maybe I'm wrong.
I think you're right... five days is too much for a known virus. Hope others could help on this hard work of making avast! better.

And no answer from viruslab (e.g.: email received, false positive, critical, danger, hi, goodbye - any word would be a nice word)
Ok, you won't... The policy is no automated answers. So, only if you really need an answer it will be sent to you.
Otherwise, the answer is on the VPS update  8)
The best things in life are free.