Author Topic: I have a virus that Avast couldn't detect - Help  (Read 5532 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
I have a virus that Avast couldn't detect - Help
« on: February 08, 2018, 01:05:23 PM »
Hello,

A guy sent me a virus, however Avast couldn't detect that virus, but it was detected with 11 other anti viruses.

What I did is I opened the virus with right click and notepad++, I am really not sure if it is still possible that I could be infected.

Please help

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: I have a virus that Avast couldn't detect - Help
« Reply #1 on: February 08, 2018, 01:07:57 PM »
Test the file at VT (https://www.virustotal.com) and post the link to the result here.
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

REDACTED

  • Guest
Re: I have a virus that Avast couldn't detect - Help
« Reply #2 on: February 08, 2018, 01:09:14 PM »
Hello,

Thanks for the prompt reply.

I tested already that's how I knew it was detected by 11 anti virus, link is here:

https://www.virustotal.com/#/file/d13d92c64332bfa52843fe30bf6e45f6e0a4f55fcf15d3256a9f81f87aa2ba9b/detection

Thanks

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: I have a virus that Avast couldn't detect - Help
« Reply #3 on: February 08, 2018, 01:13:32 PM »
You can report a suspicious/malicious sample (File/Website) here: https://www.avast.com/report-malicious-file.php
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

REDACTED

  • Guest
Re: I have a virus that Avast couldn't detect - Help
« Reply #4 on: February 08, 2018, 01:17:33 PM »
Ok Thanks, however I am scared to open any of my emails now, so I am afraid that the hacker can detect my passwords, so what to do?

Do I still have to report it and wait until they find a solution and make an update? Please help Asap, I need to work and I can not open any of my emails now.

Thanks

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: I have a virus that Avast couldn't detect - Help
« Reply #5 on: February 08, 2018, 01:26:23 PM »
Attach your basic diagnostic logs. (MBAM and FRST)
Instructions: https://forum.avast.com/index.php?topic=194892
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

REDACTED

  • Guest
Re: I have a virus that Avast couldn't detect - Help
« Reply #6 on: February 08, 2018, 01:29:58 PM »
Thanks your help is appreciated.

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: I have a virus that Avast couldn't detect - Help
« Reply #7 on: February 08, 2018, 01:51:21 PM »
Hi,

The scanned file is a RAR file. It is packed. Unless you've unpacked the file and run the VBS file, you're safe.

Can you upload that RAR file to www.mediafire.com (or another file sharing website) so I can take a look at the source code? Alternatively, I'll PM you my email address, just forward the email to it.

VBS files are usually 1 of 2 things. A prank file (contantly opening and closing your CD-ROM for example or something like a Forkbomb (recursively opening blank CMD's until you run out of RAM). Or it spreads a USB infection that doesn't (usually) do much harm.
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

REDACTED

  • Guest
Re: I have a virus that Avast couldn't detect - Help
« Reply #8 on: February 08, 2018, 02:13:06 PM »
Hi,

Yes I know it is packed, I unpacked it and I opened the VBS file with notepad++

But I knew it was a a virus after I opened the file, I sent you a private message, please check it.

Thanks for your help

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37533
  • Not a avast user
Re: I have a virus that Avast couldn't detect - Help
« Reply #9 on: February 08, 2018, 03:19:39 PM »
For suspicious mail check you can use this. See info here  >>  https://forum.avast.com/index.php?topic=198166.0



TrendMicro detection name of your file:  HEUR_RLOTRICK.B
File is using right to left (RTLO) extension spoofing

« Last Edit: February 08, 2018, 03:50:55 PM by Pondus »

REDACTED

  • Guest
Re: I have a virus that Avast couldn't detect - Help
« Reply #10 on: February 08, 2018, 05:10:52 PM »
Please find logs attached.

Thanks

REDACTED

  • Guest
Re: I have a virus that Avast couldn't detect - Help
« Reply #11 on: February 08, 2018, 05:11:27 PM »
Log2 attached

REDACTED

  • Guest
Re: I have a virus that Avast couldn't detect - Help
« Reply #12 on: February 08, 2018, 05:11:45 PM »
Log3 attached

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: I have a virus that Avast couldn't detect - Help
« Reply #13 on: February 08, 2018, 05:32:37 PM »
OK, now you've to wait for one of the malware experts...
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: I have a virus that Avast couldn't detect - Help
« Reply #14 on: February 08, 2018, 05:55:29 PM »
"C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"

Can you scan that file @ www.virustotal.com and post the results here?
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.