Author Topic: DLLHOST.EXE not detected infected system  (Read 4285 times)

0 Members and 1 Guest are viewing this topic.

TinaGonzalez

  • Guest
DLLHOST.EXE not detected infected system
« on: February 21, 2004, 06:56:25 PM »
I have Avast 4 home user edition and have used it for several months without a problem.  The week of Feb. 2-17-04 my PC was starting to slow way down and then errors started when booting up.  My Virus scan was set for all available scans but somehow I got hit anyway.  I finally found some information on your site that it is MYDOOM variant w/trojans (DLLHOST.EXE.vir).  I can't seem to activate my Avast software now!  It did detect my virus after many hours of working in safe mode by closing processes one by one until my memory and processing speed was back to user speed!  Then scan was able to run, it allowed for deletion of the files, but it showed many corrupted files that it will not allow deletion of?  Is this something anyone can help me resolve?  The files are not usable but they are in compressed zip format does this have something to do with not being able to delete them?
Please see file attacted for report by Avast scan.

Offline igor

  • Avast team
  • Serious Graphoman
  • *
  • Posts: 11850
    • AVAST Software
Re:DLLHOST.EXE not detected infected system
« Reply #1 on: February 21, 2004, 07:28:23 PM »
I believe it is not Mydoom virus (it doesn't use the name DLLHOST.EXE) - it's rather the Nachi worm (aka Welchia). This worm doesn't spready by e-mail, but rather uses an error (buffer overflow) in the RPC network protocol (the same as the well-known Blaster worm does), and some other network exploits. Therefore, an ordinary antivirus is not able to catch it - it would have to be a firewall.

You should install the necessary window updates/patches to avoid repeated infection with this worm.

To disinfect the worm, you can use our avast! Virus Cleaner.

As for the other files - can you post their full names and the errors reported?