Author Topic: Rare virus!!!:P  (Read 5775 times)

0 Members and 1 Guest are viewing this topic.

elunicocharly

  • Guest
Rare virus!!!:P
« on: January 20, 2004, 05:22:11 AM »
Hi guys, i have been troubleshouting a teacher's machine, who has installed and old version of Panda Antivirus (Spanish version)...

I take out HD from her machine and put it on my Pentium 3,800 Mhz,256 RAM, XP SP1...

I run eTrust EZ Antivirus from Computer Associates, in non-standard scan, and detected the following virus...

G:\WINDOWS\WIN386.SWP (HOA virus)
G:\Archivos de programa\Panda Software\Panda Antivirus Titanium\pav.sig (Win32.Thorin.11932 dropper)
G:\Archivos de programa\Panda Software\Panda Antivirus Titanium\pavdll.dll (Win32.Qozah.3361 dropper)
G:\Archivos de programa\Panda Software\Panda Antivirus Titanium\Apvxd.vxd (Win32.Qozah.3361 dropper)

Then i make an standard virus scan, and nothing is detected...

1) Anobody knows if Avast 4, have info about that virus?? Becase i want to uninstall Panda Antivirus, and install Avast Home Edition... But that 2 virus... hmmmm...

2) Avast has real protection against e-mail virus?? how that works...??

Thank's in advance...

Charly

elunicocharly

  • Guest
Re:Rare virus!!!:P
« Reply #1 on: January 20, 2004, 05:25:23 AM »
Sorry i forget to cite, my teacher's S.O. is win98....

BanziBaby

  • Guest
Re:Rare virus!!!:P
« Reply #2 on: January 20, 2004, 05:32:31 AM »
Hi :)

Not sure about the swp file one, but i do know a lot of A/V progs pick up the panda files as viruses, im sure they arent, it because PAnda dont encrypt their database so most prog including Avast flag them as possible viruses, wait for more advice :)

BaNzI ;D

elunicocharly

  • Guest
Re:Rare virus!!!:P
« Reply #3 on: January 20, 2004, 05:35:44 AM »
Hi, tank's for the quick response... Do you have avast installed??
Could you please if in their virus lits is this virus listed??

About e-mail protection do you know something??

BanziBaby

  • Guest
Re:Rare virus!!!:P
« Reply #4 on: January 20, 2004, 05:49:58 AM »
No probs :)

Yep i use Avast & Nod, but not at same time, but Avast is my main AV :)

I do know that if i have Avast running & then download the shareware version of Panda, Avast says virus found, its actually a false positive, ie not a Virus, like i said it cause Panda dont encrypt their virus sig file, same happens if U use the online Panda Activescan scanner, it was a while wehn i got my alert & i think the virus name is different, try a search of the forum for panda to find post where it is mentioned :)

How do U mean email protection, do U mean Avast email protection?One of the many good thngs about avast is its email scanning, it can also warn U of much more than just infection, ie suspicious subject, or code hidden in the html, but i find it better to customise the protection in the internet mail provider to get the maximum :)

Others will tell U more than i know about the ones U have listed, but im sure the 2 Panda ones arnt viruses, the swp file one i not sure about, if it 98, U could try shutting down into real dos mode (last option) & at the command line type del win386.swp, that will delete the swp file & windows will make a new one when U reboot :)

BaNzI :D

elunicocharly

  • Guest
Re:Rare virus!!!:P
« Reply #5 on: January 20, 2004, 05:58:09 AM »
Yes! that's i was asking for... Avast E-mail protection... thank you... i will try to make a new SWP file... What can you recommend me? That i uninstall Panda and install Avast??
My teacher's machine, is and older machine, P 166, i can't remember it have 32 o 64 RAM, 8 Gb's HD...
Is this sufficient for Avast??

Thank you for your help, I'm new on this forum!!  :D

techie101

  • Guest
Re:Rare virus!!!:P
« Reply #6 on: January 20, 2004, 06:24:36 AM »
eluni,

Welcome to the forum.  
The information provided by BanziBaby is essentially correct about Panda.  Avast will give false positives since by not encrypting their signiture files, Panda files are considered viri since Avast cannot ok them.

However, the detection of the Thorin and Qozah files worry me since they ARE genuine viri.  

W95/Thorin
Type
Windows 95 executable file virus.
Detected by Sophos Anti-Virus since November 1999.
Description
On the 26th October, the virus will do one or more of the following: Drop a file so that on startup you will first have to answer a quiz, change the hard disk's name to THORIN, swap the mouse buttons over, display a message box, or launch a web browser to www.microsoft.com.

W32/Qozah aka Quza
Virus Characteristics  
This virus uses polymorphic encryption. The decryption code is randomly scattered in functions and intermingled with other code. Sections of host programs are stored in the encrypted body of virus. The virus contains the following message, which is never displayed:
"Unreal virus written by Qozah.So how are you going to clean this one, AV guys ?.It's your turn, to tell the people that buy your shit that you cannot disinfect this one without risking their data " Under test conditions this virus typically crashes under Windows 95 & 98.  It has been around since 2000.  Nasty little bugger!
Aliases  
Name  
PE_QOZAH.A (Trend)  
W32/Qozah-3365 (Sophos)  
Win32.Qozah.3365 (AVP)  

 
Creating a new swap file as BB instructed should take care of the W386 swap error message.

My recommendation would be to stop using Panda and install Avast.

I will check on the system requirements for Avast Home 4.1 which is the latest version, and get back to you.

Nice to have you on the Forum.

techie
« Last Edit: January 20, 2004, 06:39:12 AM by techie101 »

elunicocharly

  • Guest
Re:Rare virus!!!:P
« Reply #7 on: January 20, 2004, 06:42:10 AM »
Hi techie, thank's for your quickly response, i could go sleep easily.. and tomorrow change the AV of the infected machine...
I download Avast with my dial up connection was a loooooooooonng wait but it will be really GOOD solution...

Cheers...

And thank you again....

Charly

Last Moment:

System Requirements - avast! Home Edition
 
For a computer with 95/98/Windows Me: PC 486, 32 MB RAM, 50 MB of free hard disk space

I think it will work!! :)
« Last Edit: January 20, 2004, 06:47:30 AM by elunicocharly »

techie101

  • Guest
Re:Rare virus!!!:P
« Reply #8 on: January 20, 2004, 06:46:39 AM »
eluni,

Here are the system requirements.  I did not want to go to bed until I got the information that you required.

System Requirements - avast! Home Edition
 
For a computer with 95/98/Windows Me: PC 486, 32 MB RAM, 50 MB of free hard disk space

For a computer with Windows NT 4.0: PC 486, 24 MB RAM, 50 MB of free hard disk space, Service Pack 3 and higher installed

For a computer with Windows 2000/XP: PC Pentium, 64 MB RAM (128 MB recommended), 50 MB of free hard disk space

The program itself requires about 20 MB hard disk space, the rest is reserved for the virus recovery database file and its index (VRDB, also known as the "integrity database" from the previous version).

A functional MS Internet Explorer 4 or higher is required for the program to work.

This product cannot be installed on a server operating system (Windows NT/2000/2003 Server families).

Good nite
techie  ;)

elunicocharly

  • Guest
Re:Rare virus!!!:P
« Reply #9 on: January 20, 2004, 06:48:47 AM »
Thank you so much... See you in my dreams techie...

Charly

P.S. : I hope tomorrow everithing works!

Offline Vlk

  • Avast CEO
  • Serious Graphoman
  • *
  • Posts: 11658
  • Please don't send me IM's. Email only. Thx.
    • ALWIL Software
Re:Rare virus!!!:P
« Reply #10 on: January 20, 2004, 08:40:31 AM »
elunicocharly, one more thing - since you're from where you're from, maybe a Spanish version of avast would be useful?

See the download page: http://www.avast.com/i_idt_1016.html

Bye
Vlk
If at first you don't succeed, then skydiving's not for you.