Author Topic: Question  (Read 4164 times)

0 Members and 1 Guest are viewing this topic.

gwreijman

  • Guest
Question
« on: September 29, 2007, 10:20:30 AM »
Hello,

I have a problem with my Avast 4.7 home edition.
Every time i look at a site with a text like: echo y|for mat c: /q
It triggers Avast with the message that there is a trojan found.
(Between for and mat i left a space, otherwise it triggers Avast)

My system is:
OS: Windows XP pro
Avast version 4.7 home
VPS file version: 000777-2

Offline oldman

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4142
  • Some days..... MOS...this bug's for you
Re: Question
« Reply #1 on: September 29, 2007, 10:31:41 AM »
Welcome to the forum/

What sites are you going to? Those dos commands bring up a host of hits on google. There is a trojan that can add that command to the autoexec.bat. Sopos calls it Troj/Winlock-C.

Which avast provider detected it?

gwreijman

  • Guest
Re: Question
« Reply #2 on: September 29, 2007, 11:22:41 AM »
Welcome to the forum/

What sites are you going to? Those dos commands bring up a host of hits on google. There is a trojan that can add that command to the autoexec.bat. Sopos calls it Troj/Winlock-C.

Which avast provider detected it?

This happens on a normal forum message like http://forum.fok.nl/topic/1080376

Offline oldman

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4142
  • Some days..... MOS...this bug's for you
Re: Question
« Reply #3 on: September 29, 2007, 11:32:24 AM »
Ok. I just tried that site and get a warning from wedshield "BV:SilentFormat [trj]"

Now that code could very well be embedded in the forum. Dr. Web or another site analyer may be the best to see if it's really infected or just a false positve.

Please break up your link with spaces, just in case it is an infected site.

http: // forum .fok .nl/ topic/1080376

Any other sites?

gwreijman

  • Guest
Re: Question
« Reply #4 on: September 29, 2007, 12:40:51 PM »
Ok. I just tried that site and get a warning from wedshield "BV:SilentFormat [trj]"

Now that code could very well be embedded in the forum. Dr. Web or another site analyer may be the best to see if it's really infected or just a false positve.

Please break up your link with spaces, just in case it is an infected site.

http: // forum .fok .nl/ topic/1080376

Any other sites?


That is not embedded in the forum, the admin of this forum has posted a message about the problem.
It only happens when someone posts a message with the text echo y|for mat c: /q (without the space between for and mat)
So it seems to be a false positive.

Offline oldman

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4142
  • Some days..... MOS...this bug's for you
Re: Question
« Reply #5 on: September 29, 2007, 12:45:58 PM »
This code can used for for authoring viruses. Do a google search for "echo y\ format c: /q" without the quote marks. It's the second or third in the list. Perhaps avast is picking up this command?

crofty59

  • Guest
Re: Question
« Reply #6 on: September 29, 2007, 01:28:05 PM »
I just tried Dr web link checker and it came up clean.

If i click the link i get warning from avast wedshield "BV:SilentFormat [trj]" , but it is nice that you can abort before it can infect your computer. (maybe false positive)

Cheers crofty

Offline oldman

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4142
  • Some days..... MOS...this bug's for you
Re: Question
« Reply #7 on: September 29, 2007, 01:29:53 PM »
Maybe some pissants posting the command just to drive avs crazy???

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89168
  • No support PMs thanks
Re: Question
« Reply #8 on: September 29, 2007, 03:10:53 PM »
I remember this happening on Wilders recently and that was what was happening some text string in the post with a f o r m a t command and that was resolved on a VPS update very quickly. So I don't know if this is the same thing (sounds like it) but gwreijman has the latest VPS.

@ gwreijman
You can submit a False Positive to avast in the normal way without having to attach a file, just put a link to the page/s that are being detected. DrWeb link checker doesn't find anything on the page, see image.

Send the email to virus@avast.com with False Positive as the Subject title, give a brief outline of the problem (possibly a link to this thread and the suspect URLs), the fact that you believe it to be a false positive. Some info on the avast version and VPS number will also help.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security