Author Topic: 4.8 finds infected file it wont remove  (Read 4070 times)

0 Members and 1 Guest are viewing this topic.

JTKWales1981

  • Guest
4.8 finds infected file it wont remove
« on: April 04, 2008, 11:50:18 PM »
I have sorted my problem by manually removing Avast 4.7 and all registry stuff and then doing a manual reinstallation of 4.8 but now when i run 4.8 it says that i have an infected file in the memory but wont remove it or move to the chest.

The file is...

c:\windows\system32\msasno.dll

infected with

Win32:Agent-UBX [trj]

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89061
  • No support PMs thanks
Re: 4.8 finds infected file it wont remove
« Reply #1 on: April 05, 2008, 12:16:22 AM »
What error message are you getting when you try to move it to the chest ?

Normally when avast finds malware in memory it offers the user the option of scheduling a boot-time scan, that is probably the best option, and send the file to the chest when detected in the boot-time scan.

If it isn't giving that option you can select it.
If you have XP, vista32bit or Win2k, you could enable a boot time scan. Right click the avast icon, select Start avast! Antivirus, Menu, 'Schedule boot-time scan...' Or see http://www.digitalred.com/avast-boot-time.php.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

JTKWales1981

  • Guest
Re: 4.8 finds infected file it wont remove
« Reply #2 on: April 05, 2008, 12:39:24 AM »
i did a boot time scan and it still wouldnt remove.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33903
  • malware fighter
Re: 4.8 finds infected file it wont remove
« Reply #3 on: April 05, 2008, 01:18:59 AM »
Hi JTKWales1981,

This file can perform following behavior.

- Usualy created by unsafe process.

- Registered as a Dynamic Link Library File.

- Usualy have random filename and refers to many versions of a dynamic link library.

- Can be injected/attached to the legitimate Windows process such as explorer.exe or other.

1. COVERT ANALYSIS OF: MSASNO.DLL

    * File Names Used: 2
    * Paths Used: 1
    * Common File Name: MSASNO.DLL
    * Common Path: %WINDIR%\SYSTEM32\
    * Vendor Information: No Vendor details specified
    * File Name Structure: Normal
    * File and Path Structure: Normal

2. RELATIONSHIP ANALYSIS OF: MSASNO.DLL

    * No relationship details available for this object

3. ACTIVITY ANALYSIS OF: MSASNO.DLL

    * No activity has yet been observed for this object

4. PROPAGATION ANALYSIS OF: MSASNO.DLL

    * Object Propagation Rate: Very Low (minimal spread)
    * Copyright Prevx Limited 2005, 2006

You can delete this file in SafeMode, follow instructions here: http://www.pchell.com/support/undeletablefiles.shtml

Also consider this info here: http://www.trojaner-board.de/51325-win32-agent-ubx-trj.html

polonus
« Last Edit: April 05, 2008, 01:31:04 AM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Vlk

  • Avast CEO
  • Serious Graphoman
  • *
  • Posts: 11658
  • Please don't send me IM's. Email only. Thx.
    • ALWIL Software
Re: 4.8 finds infected file it wont remove
« Reply #4 on: April 05, 2008, 01:24:10 AM »
Again, what error message are you getting, exactly?
If at first you don't succeed, then skydiving's not for you.

JTKWales1981

  • Guest
Re: 4.8 finds infected file it wont remove
« Reply #5 on: April 05, 2008, 01:14:32 PM »
all i get is a message saying its unable to move the file to the chest or to delete the file and to run a boot scan which i did and in the boot scan i get an error saying unable to repair or delete the file.

JTKWales1981

  • Guest
Re: 4.8 finds infected file it wont remove
« Reply #6 on: April 05, 2008, 11:03:12 PM »
I just did another full system scan and it didnt detect it.

I just opened up Avast and the memory test found it, closed Avast and reopened it and it didnt find it, closed Avast again and reopened and it found it again.

Its really weird.

CharleyO

  • Guest
Re: 4.8 finds infected file it wont remove
« Reply #7 on: April 06, 2008, 09:17:29 AM »
***

Did you follow Polonus' advice?


***

JTKWales1981

  • Guest
Re: 4.8 finds infected file it wont remove
« Reply #8 on: April 06, 2008, 01:30:17 PM »
yes and this is whats happening now as i explained.  problem is i cant referr back to it that often cos i dont have my friend who can speak german here all the time!
« Last Edit: April 06, 2008, 01:31:48 PM by JTKWales1981 »