Author Topic: o no~ avast can't detect the worm.but others can!  (Read 5531 times)

0 Members and 1 Guest are viewing this topic.

locolyric

  • Guest
o no~ avast can't detect the worm.but others can!
« on: March 17, 2006, 06:20:06 PM »
why? avast can't detect the virus . but others software can do it....god ..... i have already with latest update..why still infect by virus ?

sad...and  >:(

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: o no~ avast can't detect the worm.but others can!
« Reply #1 on: March 17, 2006, 06:34:15 PM »
You're not helping us to help you that much...
Which is the virus name?
Which is the infected file and its path?
Which other 'software' you're talking about?
Which is your operational system, firewall...  8)
The best things in life are free.

CharleyO

  • Guest
Re: o no~ avast can't detect the worm.but others can!
« Reply #2 on: March 17, 2006, 06:51:16 PM »
***

Welcome to the forums, locolyric.    :)

I have to agree with Tech ... very little information given = very little help given.    ::)


***

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89029
  • No support PMs thanks
Re: o no~ avast can't detect the worm.but others can!
« Reply #3 on: March 17, 2006, 06:52:32 PM »
Sorry but we aren't clairvoyant so we will need more information, like what Tech asked for to try and help.

How do you know you are infected ?
What detected it ? and when/how ?

If you are not getting a virus warning that you believe is a new, undetected virus, then if you can zip and password protect ('virus', will do) the suspect file and send it to virus @ avast.com (no spaces), or send from the chest.

Give a brief outline of the problem (possibly a link to this thread), the fact that you believe it to be a either a new, undetected virus and include the password in the body of the email. Some info on the avast version and VPS number (see about avast {right click avast icon}) will also help.

You could also check the offending/suspect file at: Jotti - Multi engine on-line virus scanner if any other scanners here detect them it is less likely to be a false positive. You can't do this with the file in the chest, you will need to move it out.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33897
  • malware fighter
Re: o no~ avast can't detect the worm.but others can!
« Reply #4 on: March 17, 2006, 07:44:13 PM »
Hi locolyric,

Do not panic, it may be a false positive because you have two resident anti-virus programs running that are getting in each others' hair, or you have scanned with an online scanner that gives problems like Panda. Read the sticky in this forum what to do if a virus has been apparently found, and more than likely we can help you out

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

locolyric

  • Guest
Re: o no~ avast can't detect the worm.but others can!
« Reply #5 on: March 19, 2006, 10:54:05 AM »
i know i am not quite explain what happens with me . about the virus name . i don't know . it just create a exe same as the folder name.
i know it was the virus because my friend was run it unfortunely. and the virus will close all the anti virus application. when you want to enter the folder option. the explorer.exe will restart.

and you cannot run regedit and msconfig also.


my os is win XP.
and only use the avast software.i just test that virus at the others pc .

here are the virus files. thanks
actually it was a .exe files. but now it cannot be attach..so i rename it..
that virus won't effect before you double click it.

locolyric

  • Guest
Re: o no~ avast can't detect the worm.but others can!
« Reply #6 on: March 19, 2006, 10:59:02 AM »
o yes... actually it was not like virus .i think it was more like a worm.

additional information: the pc will running very slow .

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89029
  • No support PMs thanks
Re: o no~ avast can't detect the worm.but others can!
« Reply #7 on: March 19, 2006, 03:01:55 PM »
There is still too little to even take a stab at it.

Please try to give detailed answers this helps us.
How do you know you are infected - e.g. what was it called on your friends system ?
What detected it ? and when/how - what detected it on his system ?
What was the file name, where was it found example (C:\windows\system32\infected-file-name.xxx)?
This would at least allow for a google search on the infected/suspect file name and see if there is any known virus associated with it.

If you haven't already got this software (freeware), download, install, update and run it, Ewido Security Suite. It would probably be best to run it from safe mode. Once you have done that schedule a boot-time scan from within avast.

You could also try an on-line virus scanner.
Virus Scanners and other useful Links Security-Ops.eu.tt
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

locolyric

  • Guest
Re: o no~ avast can't detect the worm.but others can!
« Reply #8 on: March 19, 2006, 04:08:44 PM »
so sorry for i can't explain detail. when my friends pc infected.i found a xx.txt file show at c drive. my friend's pc same as me,win xp.
it similiar with brontok version..but it was not brontok.because there have no any information in"my pictures"
but when infected.the cpu usage keep running high .and with you double click the .exe file again. a ms dos box appear and write some thing like what show in brontok..

i already delete the file ..it was hard to told that what is that virus

locolyric

  • Guest
Re: o no~ avast can't detect the worm.but others can!
« Reply #9 on: March 19, 2006, 05:51:02 PM »
i using the Jotti online malware scanner.
here is the result
AntiVir                 Found Heuristic/Trojan.Downloader
(probable variant) 

BitDefender        Found BehavesLike:Trojan.RegistryDisabler (probable variant) 
Dr.Web               Found Win32.HLLM.Jowo 
NOD32                Found probably a variant of Win32/Pazetus 



Norman Virus Control  Found Sandbox: W32/Malware; [ General information ]

* **Locates window "` ` [class NULL]" on desktop.
* Creating several executable files on hard-drive.
* **Locates window "~Brontok~Log~ [class NULL]" on desktop.
* **Locates window "C:\WINDOWS\J6334922.EXE"" [class NULL]" on desktop.
* **Locates window "C:\WINDOWS\J6186422.EXE"" [class NULL]" on desktop.
* File length: 45120 bytes.

[ Changes to filesystem ]
* Creates directory C:\WINDOWS\ShellNew.
* Creates directory C:\WINDOWS\ShellNew\Spread.Mail.Bro.
* Creates directory C:\WINDOWS\ShellNew\Spread.Sent.Bro.
* Creates directory \dv6179820x.
* Creates file C:\WINDOWS\ShellNew\smss.exe.
* Creates file C:\WINDOWS\j6334922.exe.
* Creates file C:\WINDOWS\SYSTEM32\c_33492k.com.
* Creates file C:\WINDOWS\ShellNew\zh591798284y.exe.
* Creates file C:\WINDOWS\o4334927.exe.
* Creates file C:\WINDOWS\_default33492.pif.
* Creates file \dv6179820x\yesbron.com.
* Creates file C:\WINDOWS\j6186422.exe.
* Creates file C:\WINDOWS\SYSTEM32\c_18642k.com.
* Creates file C:\WINDOWS\o4186427.exe.
* Deletes file C:\WINDOWS\ShellNew\zh591798284y.exemsatr.bin.

[ Changes to registry ]
* Creates value "f2916Cur"=""C:\WINDOWS\ShellNew\zh591798284y.exe"" in key "HKCU\Software\Microsoft\Windows\CurrentVersion\Run".
* Modifies value "Hidden"="" in key "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced".
* Modifies value "HideFileExt"="" in key "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced".
* Sets value "ShowSuperHidden"="" in key "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced".
* Creates key "HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System".
* Sets value "DisableRegistryTools"="" in key "HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System". 


=============================
VBA32  Found Worm.Win32.Pazetus.G 


i think it was pazetus ....cause two software name it

hope avast will add this virus defination into antivirus programs

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89029
  • No support PMs thanks
Re: o no~ avast can't detect the worm.but others can!
« Reply #10 on: March 19, 2006, 07:03:11 PM »
avast can only add it to the virus detections when they have a sample of it, which is why I suggested this.
Quote
If you are not getting a virus warning that you believe is a new, undetected virus, then if you can zip and password protect ('virus', will do) the suspect file and send it to virus @ avast.com (no spaces), or send from the chest.

Give a brief outline of the problem (possibly a link to this thread), the fact that you believe it to be a either a new, undetected virus and include the password in the body of the email. Some info on the avast version and VPS number (see about avast {right click avast icon}) will also help.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security