Author Topic: Deleting virus from chest  (Read 4431 times)

0 Members and 2 Guests are viewing this topic.

myavastforum

  • Guest
Deleting virus from chest
« on: September 12, 2011, 05:02:05 AM »
Hi all.
I moved Win32:Malware-gen virus to avastpro chest on 31/08/2011. It was in C:\users\....\Downloads
Is delete the best way to remove the virus?
What about any alterations the virus might have created prior to chest?
 
Thanks in advance
« Last Edit: September 12, 2011, 05:12:47 AM by myavastforum »

Offline Shiw Liang

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1431
Re: Deleting virus from chest
« Reply #1 on: September 12, 2011, 05:11:49 AM »
Hello,

Can you provide us with more details about the detected file? (In case it is a FP)

If you think that you don't need that file, I believe removing it from the chest will do no harm but it is mostly recommended to keep it in the chest (if you are unsure)
« Last Edit: September 12, 2011, 05:16:58 AM by Shiw Liang »

myavastforum

  • Guest
Re: Deleting virus from chest
« Reply #2 on: September 12, 2011, 05:17:06 AM »
It show as activescan2_en.exe. Its original locations was in my downloads last changed on 9/10/2010. Thanks.

Offline Shiw Liang

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1431
Re: Deleting virus from chest
« Reply #3 on: September 12, 2011, 05:23:53 AM »
I have downloaded that file but it was not detected by any antivirus in virustotal :(

http://www.virustotal.com/file-scan/report.html?id=e960a43a0b9fb1c7986a8f18c20efd70420c12dbd8bd3226ac707d3ec611a49f-1315796976

Are you using the lastest version of avast ???

myavastforum

  • Guest
Re: Deleting virus from chest
« Reply #4 on: September 12, 2011, 05:33:53 AM »
Yes. Avast pro updated daily program version 6.0.1289.
Def update 110911-1 currently and was uptodate when moving virus to chest :)
Activescan2.0 shows up as Panda security folder in windows start search. The date is probably when it was last changed when I installed it some time ago.
The virus Win32:Malware-gen has been detected by a number of other avast forum users :)
« Last Edit: September 12, 2011, 06:14:57 AM by myavastforum »

Online DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89697
  • No support PMs thanks
Re: Deleting virus from chest
« Reply #5 on: September 12, 2011, 02:28:45 PM »
It looks like avast is alerting on Panda's unencrypted signatures or something along those lines.

Personally I wouldn't have Panda on my system, even if it is an on-demand scan. If it is anything like its on-line scanner it installs its unencrypted virus signature files in a sub-folder of the c:\windows\system32 folder. I think that is taking liberties doing that in the system32 folder, not to mention these unencrypted signatures are going to be detected by avast (or any other antivirus installed) when you scan that area and the system32 being an important system folder is going to be scanned by all scans.

Personally I would recommend uninstalling Panda's Activescan.

The avast Win32:Malware-gen is a generic signature (the -gen at the end of the malware name), so that is trying to catch multiple variants of the same type of malware. So seeing other avast users with this detection is not unusual.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD - 27" external monitor 1440p 2560x1440 resolution - avast! free  24.9.6130 (build 24.9.9452.762) UI 1.0.818/ Firefox, uBlock Origin Lite, uMatrix/ MailWasher Pro/ Avast! Mobile Security

myavastforum

  • Guest
Re: Deleting virus from chest
« Reply #6 on: September 12, 2011, 10:42:35 PM »
It looks like avast is alerting on Panda's unencrypted signatures or something along those lines.

Personally I would recommend uninstalling Panda's Activescan.

The avast Win32:Malware-gen is a generic signature (the -gen at the end of the malware name), so that is trying to catch multiple variants of the same type of malware. So seeing other avast users with this detection is not unusual.

myavastforum

  • Guest
Re: Deleting virus from chest
« Reply #7 on: September 12, 2011, 11:05:05 PM »
Thanks DavidR. I have removed Panda folders from my downloads. Hope this solves any further problems also.
Question remains: should I still remove malware from chest?

Thanks to all.  :)
« Last Edit: September 12, 2011, 11:16:07 PM by myavastforum »

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37700
Re: Deleting virus from chest
« Reply #8 on: September 12, 2011, 11:09:25 PM »
Quote
Is delete the best way to remove the virus?

Clean, Quarantine, or Delete?
http://antivirus.about.com/b/2007/03/11/clean-quarantine-or-delete.htm

myavastforum

  • Guest
Re: Deleting virus from chest
« Reply #9 on: September 12, 2011, 11:27:16 PM »
Quote
Is delete the best way to remove the virus?

Clean, Quarantine, or Delete?
http://antivirus.about.com/b/2007/03/11/clean-quarantine-or-delete.htm

Thanks Pondus. I removed Panda and have deleted the offending file from chest. Hope this fully resolves problem.

Thanks to all again.  :)

Online DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89697
  • No support PMs thanks
Re: Deleting virus from chest
« Reply #10 on: September 12, 2011, 11:30:53 PM »
Yes that should be the end of it.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD - 27" external monitor 1440p 2560x1440 resolution - avast! free  24.9.6130 (build 24.9.9452.762) UI 1.0.818/ Firefox, uBlock Origin Lite, uMatrix/ MailWasher Pro/ Avast! Mobile Security