Author Topic: Win32:ShareAll-H [Trj]  (Read 5682 times)

0 Members and 1 Guest are viewing this topic.

cengliong

  • Guest
Win32:ShareAll-H [Trj]
« on: November 05, 2006, 05:30:50 AM »
Hi,

My VPS version was 0645-4, 03/11/2006. When I scanned my files with thorough scan, I found that I've got a Trojan Horse.

My warning log contains:
05/11/2006 11:06:51 Welly 2220 Sign of  "Win32:ShareAll-H [Trj]" has been found in
"C:\Program Files\iolo\System Mechanic Professional 6\SysMech6.exe\[ASPack]" file.

I've checked the file on http://virusscan.jotti.org/ and the result was infected by Trojan-Spy.Banker.69 (detected only by VBA32)

Your help would be appreciated

cengliong

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: Win32:ShareAll-H [Trj]
« Reply #1 on: November 05, 2006, 01:59:20 PM »
Seems a false positive.
As a workaround, please, add the file to the Standard Shield exclusion list untill you can receive new virus database (vps) updates.
The best things in life are free.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89161
  • No support PMs thanks
Re: Win32:ShareAll-H [Trj]
« Reply #2 on: November 05, 2006, 04:04:53 PM »
You could also check the offending/suspect file at: VirusTotal - Multi engine on-line virus scanner , this uses the Windows version of avast and has a greater number of different scanners, 27 at last count.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline igor

  • Avast team
  • Serious Graphoman
  • *
  • Posts: 11855
    • AVAST Software
Re: Win32:ShareAll-H [Trj]
« Reply #3 on: November 06, 2006, 11:26:06 AM »
Additionally, please pack the misdetected executable into a password-protected ZIP or RAR and send it to virus@avast.com, please (with a "False positive" subject, for example).

cengliong

  • Guest
Re: Win32:ShareAll-H [Trj]
« Reply #4 on: November 07, 2006, 12:12:48 AM »
The new VPS still detecting it as a trojan ( 0646-0, 06/11/2006 ). I've tried VirusTotal and it gave the same result :
  Avast  -> Win32:ShareAll-H
  VBA32 -> suspected of Trojan-Spy.Banker.69 (paranoid heuristics)

I've just sent the file to virus@avast.com

curried

  • Guest
Re: Win32:ShareAll-H [Trj]
« Reply #5 on: November 08, 2006, 10:35:49 AM »
Hi cengliong,

  the VPS of 1st November (0645-0) picked up ShareAll-H in SysMech6.exe for me,
and I got the same result as you when using the multi-scan, VBA32 found Spy.Banker.69 (paranoid heuristics), and commented "possibly infected/malware.  Might be false +ve".

Still not good for the blood pressure when you think you are clean!

I have SysMech6 locked in the Chest until safe to let it out to play....   

cengliong

  • Guest
Re: Win32:ShareAll-H [Trj]
« Reply #6 on: November 08, 2006, 11:28:10 AM »
Newer VPS (646-2, 07/11/2006) gives a clean result. Let us wait for VBA32 to update its database.

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: Win32:ShareAll-H [Trj]
« Reply #7 on: November 08, 2006, 11:31:48 AM »
Newer VPS (646-2, 07/11/2006) gives a clean result. Let us wait for VBA32 to update its database.
Well, we're not that bad  ;)
The best things in life are free.

cengliong

  • Guest
VBA32
« Reply #8 on: November 08, 2006, 03:24:40 PM »
My friend once said VBA32 is very good at detecting trojans. If its new database gives a clean result, then should I take it as if my file is safe?

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: VBA32
« Reply #9 on: November 08, 2006, 05:36:35 PM »
My friend once said VBA32 is very good at detecting trojans. If its new database gives a clean result, then should I take it as if my file is safe?
Most probably... but, after all, as you've done before, the better will be submitting the file to on-line scanners.
The best things in life are free.

cengliong

  • Guest
Re: Win32:ShareAll-H [Trj]
« Reply #10 on: November 09, 2006, 04:38:03 AM »
OK, thanx..