Author Topic: 23mb for analisys  (Read 2806 times)

0 Members and 1 Guest are viewing this topic.

marcelo.petal

  • Guest
23mb for analisys
« on: December 07, 2011, 08:15:49 AM »
Hi there! I speak from Brazil, so I have some files to
analysis by experts, avast does not detect is very
difficult to remove it, because it creates many keys on the
regedit and freeze explorer.exe and taskmgr.exe after windows logon...
please help ...

zip with 23mb
http://www.mediafire.com/?cwriw1ikqlea65p
pw "admin"

combofix logs
http://www.mediafire.com/?4c2ubquuvy77vk7

marcelo.petal@gmail.com

thanks
marcelo

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: 23mb for analisys
« Reply #1 on: December 07, 2011, 12:16:23 PM »
It will not good to let your email public due to spammers.
I've tried to call virus analyst attention to these samples. Hope they post back.
The best things in life are free.

Offline Milos

  • Avast team
  • Super Poster
  • *
  • Posts: 2297
Re: 23mb for analisys
« Reply #2 on: December 07, 2011, 12:47:54 PM »
Hello,
there is a lot of junk files, also signed files (with valid signature).

EDIT:
Only suspicious files are signed by Iminent.

Milos
« Last Edit: December 07, 2011, 01:11:16 PM by Milos »

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: 23mb for analisys
« Reply #3 on: December 07, 2011, 12:57:17 PM »
Thanks Milos.
The best things in life are free.

marcelo.petal

  • Guest
Re: 23mb for analisys
« Reply #4 on: December 09, 2011, 05:41:42 PM »
hello, thanks for the analysis, I went into despair when some machines after logon, when he finished loading the winlogon.exe and explorer.exe, explorer froze and any program not run, nor the task manager open, and opened I could not kill the explorer process, and could kill when ordered to reopen as a new task task manager froze too, got desperate and started to analyze what was loaded on logon, with the DDS and GMER , I discovered that if I went into safe mode to uninstall avast, restart, entered in normal mode and everything was ok, then I reinstall avast and looks great, I think a bug should be the key that has some effect on the option of "delaying the start of the avast service" in the settings because I'm having this problem on multiple machines, and only decided this way. ComboFix only detects and deletes the folder "C: \ Windows \ CSC \ D6."
Comments?

thank you

Marcelo.