Author Topic: Avast can't pick up virus (crypt.exe). What to do?  (Read 6521 times)

0 Members and 2 Guests are viewing this topic.

luben

  • Guest
Avast can't pick up virus (crypt.exe). What to do?
« on: June 07, 2009, 11:49:35 PM »
Hi guys,

I have Avast 4.8 home with the latest iAVS running.  I've performed a thorough scan of all hard drives & have also done a on-start-up scan.  It hasn't picked up any viruses.

But when I insert an empty CF card into my computer, a file called crypt.exe and an autorun.inf files got copied onto it.  I guess that this is a virus trying to spread itself.

I've never had a situation that Avast would not be able to identify and clean a virus.  What can I do to clean my machine (short of reinstalling my XP SP3)?

Thanks in advance for your help

Luben

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34053
  • malware fighter
Re: Avast can't pick up virus (crypt.exe). What to do?
« Reply #1 on: June 07, 2009, 11:57:39 PM »
Hi luben,

You could check the files in question against virustotal.com, upload there and give us the results.
Consider this info on crypt.exe: http://www.threatexpert.com/files/crypt.exe.html

If you should have an autorun issue, you could use this, Flash Drive Disinfector,
Download Flash_Disinfector.exe by sUBs from > http://www.techsupportforum.com/sectools/sUBs/Flash_Disinfector.exe < and save it to your desktop.

    * Double-click Flash_Disinfector.exe to run it and follow any prompts that may appear.
    * The utility may ask you to insert your flash drive and/or other removable drives including
       your mobile phone. Please do so and allow the utility to clean up those drives as well.
    * Wait until it has finished scanning and then exit the program.
    * Reboot your computer when done.

Note: Flash_Disinfector will create a hidden folder named autorun.inf in each partition and every USB drive plugged in when you ran it. Don't delete this folder...it will help protect your drives from future infection.

Also see this link for more information on Flash Disinfector, http://experi3nc3.wordpress.com/2007/05/10/flash-disinfector-by-subs/

You could also perform a additional scan with stinger.exe: Free worm removal tool; McAfee Avert Stinger: http://vil.nai.com/vil/stinger/ Use the latest online version of it, you can use it alongside your resident avast av-solution,

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

luben

  • Guest
Re: Avast can't pick up virus (crypt.exe). What to do?
« Reply #2 on: June 08, 2009, 01:03:07 AM »
Hi there Polonus,

Thanks a lot for your swift and helpful response.  I uploaded the file to the Virustotal site you recommended and got this result:


What should I do next to clean my PC?

Thanks in advance

Luben

Offline !Donovan

  • Web Analyst
  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 2219
    • The WAR Against Malware
Re: Avast can't pick up virus (crypt.exe). What to do?
« Reply #3 on: June 08, 2009, 01:06:52 AM »
You can try sending the file to ALWIL.
Familiarize Yourself! | Educate Yourself! | Beautify Yourself! | Scan Yourself!
"People who say it cannot be done should not interrupt those who are doing it."

luben

  • Guest
Re: Avast can't pick up virus (crypt.exe). What to do?
« Reply #4 on: June 08, 2009, 01:12:16 AM »
I'd love to Donovan, but the Virus report link on the Avast website does not appear to work properly:

http://www.avast.com/%REPORT%

Luben

Offline !Donovan

  • Web Analyst
  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 2219
    • The WAR Against Malware
Re: Avast can't pick up virus (crypt.exe). What to do?
« Reply #5 on: June 08, 2009, 01:28:14 AM »
Try moving the file to the chest then sending it to alwil.
Familiarize Yourself! | Educate Yourself! | Beautify Yourself! | Scan Yourself!
"People who say it cannot be done should not interrupt those who are doing it."

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34053
  • malware fighter
Re: Avast can't pick up virus (crypt.exe). What to do?
« Reply #6 on: June 08, 2009, 01:46:01 AM »
Hi luben,

It still could be a false positive. Also send it here: http://anubis.iseclab.org/?action=home
Report the results here. As crypt.exe can be a FP, like to hear the verdict of the Vienna university scanner,

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89674
  • No support PMs thanks
Re: Avast can't pick up virus (crypt.exe). What to do?
« Reply #7 on: June 08, 2009, 01:58:45 AM »
I'd love to Donovan, but the Virus report link on the Avast website does not appear to work properly:

http://www.avast.com/%REPORT%

Luben

Send the sample to virus@avast.com zipped and password protected with the password in email body, a link to this topic might help and undetected malware in the subject.
 
Or you can also add the file to the User Files (File, Add) section of the avast chest (if it isn't already there) where it can do no harm and send it from there. A copy of the file/s will remain in the original location, so you will need to take further action and can remove/rename that.
 
Send it from the User Files section of the chest (select the file, right click, email to Alwil Software). It will be uploaded (not actually emailed) to avast when the next avast auto (or manual) update is done.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD - 27" external monitor 1440p 2560x1440 resolution - avast! free  24.9.6130 (build 24.9.9452.762) UI 1.0.818/ Firefox, uBlock Origin Lite, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89674
  • No support PMs thanks
Re: Avast can't pick up virus (crypt.exe). What to do?
« Reply #8 on: June 08, 2009, 02:01:22 AM »
Hi luben,

It still could be a false positive. Also send it here: http://anubis.iseclab.org/?action=home
Report the results here. As crypt.exe can be a FP, like to hear the verdict of the Vienna university scanner,

Given that it appears to be associated with autorun.inf, I would say it is highly suspect.

There is also the http://camas.comodo.com/cgi-bin/submit scanner too.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD - 27" external monitor 1440p 2560x1440 resolution - avast! free  24.9.6130 (build 24.9.9452.762) UI 1.0.818/ Firefox, uBlock Origin Lite, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34053
  • malware fighter
Re: Avast can't pick up virus (crypt.exe). What to do?
« Reply #9 on: June 08, 2009, 02:02:09 AM »
Hi DavidR,

I did a very extensive survey online for crypt.exe and this has lead me to believe rather strongly we have a false positive here. If not I am not going to eat my hat, but I will fast for a day at least.
Very curious after the anubis results. What is your view on the matter? Oh, I see you have given that above, well in that case we have a secondary infection of crypt.exe through the auto-run infector,

Damian
« Last Edit: June 08, 2009, 02:05:54 AM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89674
  • No support PMs thanks
Re: Avast can't pick up virus (crypt.exe). What to do?
« Reply #10 on: June 08, 2009, 02:09:50 AM »
Well there are some that may just be using a legit file to encrypt folders, etc. autorun.inf could launch an application, which in turn could use crypt.ext to encrypt folders/partitions, etc. Something along the ransomware attack (speculation though) ???
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD - 27" external monitor 1440p 2560x1440 resolution - avast! free  24.9.6130 (build 24.9.9452.762) UI 1.0.818/ Firefox, uBlock Origin Lite, uMatrix/ MailWasher Pro/ Avast! Mobile Security