Author Topic: Win32:Otwycal-Z [Wrm]  (Read 10345 times)

0 Members and 1 Guest are viewing this topic.

Aztec

  • Guest
Re: Win32:Otwycal-Z [Wrm]
« Reply #15 on: June 13, 2008, 07:07:42 PM »
Personally I would confirm the detection is good or not first.

You could also check the offending/suspect file at: VirusTotal - Multi engine on-line virus scanner and report the findings here.
You can't do this with the file securely in the chest, you need to extract it to a temporary (not original) location first, see below.

Create a folder called Suspect in the C:\ drive, e.g. C:\Suspect. Now exclude that folder in the Standard Shield, Customize, Advanced, Add, type (or copy and paste) C:\Suspect\* That will stop the standard shield scanning any file you put in that folder. You should now be able to export any file in the chest to this folder and upload it to VirusTotal without avast alerting.

I've done this.  Here is the link:  http://www.virustotal.com/analisis/14eedbe1be86cb0c4185b436d41f3bc6

Also, why does a "Google" only yield 2 links, and both to Avast's forum's?  Is this a 'worm' that I and others should be worried about?  I'm so confused.
« Last Edit: June 13, 2008, 07:12:01 PM by Aztec »

PiotrW

  • Guest
Re: Win32:Otwycal-Z [Wrm]
« Reply #16 on: June 13, 2008, 07:33:01 PM »
My Avast just alerted me to the same worm. The program says it infected... wmplayer.exe (yes, the Windows Media Player main file).

Is this a real threat or another false positive by Avast?

Chunker

  • Guest
Re: Win32:Otwycal-Z [Wrm]
« Reply #17 on: June 13, 2008, 08:02:49 PM »
It does and it is called Restore, see image.
Open the chest, select the Infected files if it was a detection by avast and you select the file you want to restore, right click and select Restore.

It would have been better to have asked this question before jumping in with a system restore.

David, If you would read and understand my post, avast gave "no" option to restore those two files on the recovery drive.  That option was greyed out on both.  The one for the file from the c drive was there, but none for the d drive!

neojudgment

  • Guest
Re: Win32:Otwycal-Z [Wrm]
« Reply #18 on: June 13, 2008, 08:37:52 PM »
Hi all,

Today I received the same alert during download 'SIM Manager' from the official Website in Australia : http://www.simmanager.com.au/

 ;D


Chunker

  • Guest
Re: Win32:Otwycal-Z [Wrm]
« Reply #19 on: June 13, 2008, 10:45:16 PM »
It does and it is called Restore, see image.
Open the chest, select the Infected files if it was a detection by avast and you select the file you want to restore, right click and select Restore.

It would have been better to have asked this question before jumping in with a system restore.

David, If you would read and understand my post, avast gave "no" option to restore those two files on the recovery drive.  That option was greyed out on both.  The one for the file from the c drive was there, but none for the d drive!

Now it seems that it was indeed a false positive and has been fixed my avast.  But too late, the damage has already been done in my case.  I did exactly what I was supposed to do and moved 3 infected files into the chest for further inspection.  I returned the one file off the c drive with no problem.  But the two files that came from the d (recovery) drive, avast gave me "no" option of restoring them.  Even on right clicking those files while in the chest and choosing properties, It said those files were unrestorable.  Now they are lost forever and my recovery drive has been corrupted, no thanks to avast!!  I will never trust avast again.

Offline Bellzemos

  • Avast Evangelist
  • Poster
  • ***
  • Posts: 621
Re: Win32:Otwycal-Z [Wrm]
« Reply #20 on: June 15, 2008, 02:40:38 PM »
I did a boot scan and there was no virus found. But one file is corrupted:

File C:\WINDOWS\Driver Cache\i386\driver.cab\kdh00001.ppd Error 42127 {CAB archive is corrupted.}

Why is that so? Thank you!
Intel Core i7 Q 740 @ 1.73 GHz, 6 GB RAM, Windows 7 Ultimate x64 SP1, Avast! Free Antivirus, Malwarebytes Anti-Malware (free version) and Sandboxie (paid version).

Online DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89178
  • No support PMs thanks
Re: Win32:Otwycal-Z [Wrm]
« Reply #21 on: June 15, 2008, 03:06:43 PM »
Nothing to worry about even if the file is corrupt there is nothing that you as a user can do about it. However, it is possibly that avast can't fully unpack it to scan it and the error message is reporting corruption as the cause which may not be 100% correct.

The main thing to remember it is just unable to be scanned, nothing else, not infected, etc.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security