Author Topic: Virus detected  (Read 3405 times)

0 Members and 1 Guest are viewing this topic.

den21

  • Guest
Virus detected
« on: July 31, 2008, 09:53:56 PM »

Hello

I got a virus dectection when i was doing a standard scan today and i wasn't sure what i needed to do, when the file was shown ( Trogan win32:Agent-AA ) it told me to put into chest which i did.

Can someone tell me what i need to do know as this is my first virus.

Thankyou

wyrmrider

  • Guest
Re: Virus detected
« Reply #1 on: July 31, 2008, 10:04:27 PM »
two things
First upload the file to Virus Total for analysis
second rt click in the chest and fwd to avast for analysis

here is a copy of a post by davidR

You could also check the offending/suspect file at: VirusTotal - Multi engine on-line virus scanner and report the findings here. You can't do this with the file securely in the chest, you need to extract it to a temporary (not original) location first, see below.

Create a folder called Suspect in the C:\ drive, e.g. C:\Suspect. Now exclude that folder in the Standard Shield, Customize, Advanced, Add, type (or copy and paste) C:\Suspect\* That will stop the standard shield scanning any file you put in that folder. You should now be able to export any file in the chest to this folder and upload it to VirusTotal without avast alerting.

If it is indeed a false positive, see http://forum.avast.com/index.php?topic=34950.msg293451#msg293451, how to report it to avast! and what to do to exclude them until the problem is corrected.

den21

  • Guest
Re: Virus detected
« Reply #2 on: July 31, 2008, 10:33:11 PM »
Hi thankyou for the reply,

what happens if i just delete the file from the chest, i have the avast home ed and the only chest options listed were restore, delete, and exstract.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89061
  • No support PMs thanks
Re: Virus detected
« Reply #3 on: July 31, 2008, 10:56:08 PM »
Well effectively you can't carry out any investigation.

There is absolutely no point in sending a file to the chest and then promptly deleting it when it gets there (effectively deleting on detection).
The chest is an area where the infected/suspect file can do no harm.

Deletion isn't really a good first option (you have none left), 'first do no harm' don't delete, send virus to the chest and investigate.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

den21

  • Guest
Re: Virus detected
« Reply #4 on: August 01, 2008, 12:00:23 AM »
Well effectively you can't carry out any investigation.

Yes the options were has i listed above so by not deleting file, so which then? i had only three options when it was on chest delete, extract. restore files 

wyrmrider

  • Guest
Re: Virus detected
« Reply #5 on: August 01, 2008, 12:06:16 AM »
what then
do not panic the file is/was safe while in the chest

I can't tell if you deleted it yet but let's presume that you did not
go to my first post starting with
"you could also upload to virus total...

and go from there


I'd also update avast and schedule a boot time scan by rt clicking on the blue ball

then
The C:\Program Files\Alwil Software\Avast4\DATA\report\aswBoot.txt provides a more user friendly summary of the boot-time scan and it should list any detections.
post it back here

chin up you're doing fine

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89061
  • No support PMs thanks
Re: Virus detected
« Reply #6 on: August 01, 2008, 12:37:29 AM »
Well effectively you can't carry out any investigation.

Yes the options were has i listed above so by not deleting file, so which then? i had only three options when it was on chest delete, extract. restore files 

You select export (it copies the file and leaves a copy in the chest) and from the explorer style pop-up navigate to the c:\suspect folder that you should have created, select it and click OK.

That will have placed a copy in that folder from there you can go about uploading it to virustotal.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

wyrmrider

  • Guest
Re: Virus detected
« Reply #7 on: August 01, 2008, 07:15:24 PM »
den21
thanks for the kind note
did DavidR's post answer your question?
keep at it
you are actually doing quite well
you did the scan and did not delete/remove
keep up the good work
patience
it does take some time

Wyrmrider