Avast Anti-Virus Is Acting Very Strange

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • dazuk1972
    Digital Video Specialist
    Digital Video Specialist
    • Jul 2005
    • 853

    Avast Anti-Virus Is Acting Very Strange

    I'm having very strange things happening with Avast Anti-Virus. Last week I downloaded some software and when it downloaded, I went into the folder where I downloaded to, right-clicked on it and did a single virus scan. No virus was detected. A few days later a did a full system scan that took about sixteen hours to complete and no virus was detected. Two days ago, when I closed my Internet Explorer a virus alert appeared where that software was reported with a virus. I never scanned anything that day, all I did was checked some e-mails and closed my Internet Explorer and the next thing I knew a virus was detected in that software that I downloaded a week before and that same software that was scanned twice previously that had no virus detected. Why was a virus detected all of a sudden after two successful scans?

    This morning, I booted up and my Messengers loaded themselves and I closed them down. Seconds after I closed down the Windows Live Messenger I got a virus alert that seems connected to the Windows Live Messenger and there can't be a virus in there. I never uploaded a photo from my photo as my IM photo because I've hardly used the Windows Live Messenger due to it messing me about a lot. Here are some images of those virus alerts.

    Avast Anti-Virus alert 1.



    Avast Anti-Virus alert 2.



    I'm hoping I don't have a virus lingering in my PC because the name of the virus looks the same as the virus that was detected in the software the other day that I downloaded last week. I'm also hoping it never put a virus in my PC that travels around in my hard drive from software to software. Avast should have detected the virus in that during that single scan as well as the full system scan and deleted it. On the other hand I might have caught another virus that has a name more-or-less the same as the other one.

    Does anybody have any suggestions and has anybody else had this strange happening.

    By the way, the full system scan should have done a grand job because it took about sixteen hours to complete and I've never known a virus scan to take well over a day before.

    Many thanks.

    Darren.
  • Chewy
    Super Moderator
    • Nov 2003
    • 18971

    #2
    This bot has the ability to perform a number of different actions on the host's machine, including:

    Executing programs
    Opening files
    Opening webpages in the host's default browser
    Downloading files
    Redirecting information sent to a local port to a remote port
    Sending system information from the local host, such as operating system, processor speed, free ram, etc.
    Sending network information from the local host, including connection type and the local IP address.
    start as a small trojan downloader and grow as they install more components

    avast may have updated itself or a new component was downloaded

    It's best to do a clean install of the OS and scan all possibly infected files

    the scan taking so long was probably because you were so badly infected


    many trojans won't show in a scan until they are installed

    Comment

    • dazuk1972
      Digital Video Specialist
      Digital Video Specialist
      • Jul 2005
      • 853

      #3
      Originally Posted by Chewy
      start as a small trojan downloader and grow as they install more components

      avast may have updated itself or a new component was downloaded

      It's best to do a clean install of the OS and scan all possibly infected files

      the scan taking so long was probably because you were so badly infected


      many trojans won't show in a scan until they are installed
      Many thanks for the help.

      I see what you mean about the update. I forgot the Trojan might be a new one hitting people's PCs and my Avast never had the update during the two earlier scan so it couldn't detect the virus and Avast created an update where my Avast could detect it that was last night. I'm going to run another scan.

      Sorry if this sounds like a dumb question. What part is the OS?

      When the virus scans with Avast take ages, it's not because my PC is running slow. I can use my PC OK while scanning, it's only the scan that takes ages.

      A friend of mine sent me an e-mail today about Messengers and she told me she hates MSN Messenger because she had a Trojan detected in it. As we all know, Windows Live Messenger has replaced the MSN Messenger and I find what she said very interesting. I'm wondering if MSN made a major blunder. Let's face it, they must have that's why a lot of people can't log into it and I can only log into it with an old ID.

      Many thanks, again.

      Darren.

      Comment

      • Chewy
        Super Moderator
        • Nov 2003
        • 18971

        #4
        dazuk,
        you are playing in the major leagues now, avast doesn't stand a chance against these guys, I tried with better programs and a lot more experience than you.

        download trojanhunter, update it, pull the plug on the internet

        boot into safe mode and run trojan hunter, follow all directions to the t

        run avast after reboot from safe mode again

        etc

        and maybe you will get rid of it

        and if they missed something, you would have saved time by just reloading

        I spent the better part of a day and a half fighting one of these, reload was not an option since the computer had to print payroll checks the next day, 6 months later we had to reload and save what we could

        anymore I just recover what data I can and do a clean install
        Last edited by Chewy; 7 Mar 2007, 02:01 PM.

        Comment

        • dazuk1972
          Digital Video Specialist
          Digital Video Specialist
          • Jul 2005
          • 853

          #5
          Originally Posted by Chewy
          dazuk,
          you are playing in the major leagues now, avast doesn't stand a chance against these guys, I tried with better programs and a lot more experience than you.

          download trojanhunter, update it, pull the plug on the internet

          boot into safe mode and run trojan hunter, follow all directions to the t

          run avast after reboot from safe mode again

          etc

          and maybe you will get rid of it

          and if they missed something, you would have saved time by just reloading

          I spent the better part of a day and a half fighting one of these, reload was not an option since the computer had to print payroll checks the next day, 6 months later we had to reload and save what we could

          anymore I just recover what data I can and do a clean install

          Many thanks for the help.

          When you mentioned Safe Mode, do you mean run the Avast virus scan while I'm in Safe Mode or do you mean reboot and boot-up in Safe Mode, reboot afterwards in the normal way then do the Avast virus scan?

          Many thanks.

          Darren.

          Comment

          • Chewy
            Super Moderator
            • Nov 2003
            • 18971

            #6
            do all scans in safe mode, keeps most nasties from loading

            Comment

            • dazuk1972
              Digital Video Specialist
              Digital Video Specialist
              • Jul 2005
              • 853

              #7
              Originally Posted by Chewy
              do all scans in safe mode, keeps most nasties from loading
              Many thanks for the help. the reason why I asked was to be sure because I found out ages ago that some things have to be done in Safe Mode.

              Just a quick other question. Will Trojanhunter conflict with my Avast because of the rule about not installing two Anti-Virus programs at once?

              Many thanks.

              Darren.

              Comment

              • Chewy
                Super Moderator
                • Nov 2003
                • 18971

                #8
                you can turn off trojanguard at bootup, your demo will soon expire anyway

                and without updates the program soon loses it's effectiveness


                I leave it and norton's dormant on my computer till I want to scan something

                avast running didn't do you any good at all
                Last edited by Chewy; 7 Mar 2007, 11:06 PM.

                Comment

                • doctorhardware
                  Lord of Digital Video
                  Lord of Digital Video
                  • Dec 2006
                  • 1907

                  #9
                  Also turn off system restore so that it will be completely removed. Then when you are sure that it has been removed turn back on the system restore, and then create a new restore point.
                  Star Baby Girl, Born March,1997 Died June 30th 2007 6:35 PM.

                  Comment

                  • dazuk1972
                    Digital Video Specialist
                    Digital Video Specialist
                    • Jul 2005
                    • 853

                    #10
                    Originally Posted by Chewy
                    you can turn off trojanguard at bootup, your demo will soon expire anyway

                    and without updates the program soon loses it's effectiveness


                    I leave it and norton's dormant on my computer till I want to scan something

                    avast running didn't do you any good at all
                    Many thanks for the help.

                    I downloaded Trojanguard but I haven't installed it yet because I think I got rid of the viruses with Avast and also because I don't want to waste the trail while not needing it so far. After a scan, I started another straight afterwards to be sure and nothing was detected. I'm keeping Trojanguard ready for if the viruses show again.

                    Many thanks for your help.

                    Darren.

                    Comment

                    • dazuk1972
                      Digital Video Specialist
                      Digital Video Specialist
                      • Jul 2005
                      • 853

                      #11
                      Originally Posted by doctorhardware
                      Also turn off system restore so that it will be completely removed. Then when you are sure that it has been removed turn back on the system restore, and then create a new restore point.
                      Many thanks for the help.

                      I forgot some things require the System Restore to be disabled.

                      As I said to Chewy, I think the viruses are gone now. I just have to see what happens next. What I mean is, I suspected the virus brings itself back and moves about and multiplies.

                      Many thanks.

                      Darren.

                      Comment

                      • src2206
                        Super Member
                        Super Member
                        • Jan 2007
                        • 234

                        #12
                        Hello dazuk1972

                        I suggest you do the following:

                        download HijackThis . This program will help me determine if there are any spyware/malware as well as SDBot is present on your computer. Double-click on the file you just downloaded. Click on the "Unzip" button to install. It will by default install to the directory - C:\PROGRAM FILES\HIJACKTHIS\ Run a scan and save the log file and post the content of the log file here [using COPY-PASTE].

                        Once I see the log, I shall help you out of this. SDBot can not be cleaned effectively by any AV tools.

                        So go ahead if you can trust me

                        Comment

                        • dazuk1972
                          Digital Video Specialist
                          Digital Video Specialist
                          • Jul 2005
                          • 853

                          #13
                          Originally Posted by src2206
                          Hello dazuk1972

                          I suggest you do the following:

                          download HijackThis . This program will help me determine if there are any spyware/malware as well as SDBot is present on your computer. Double-click on the file you just downloaded. Click on the "Unzip" button to install. It will by default install to the directory - C:\PROGRAM FILES\HIJACKTHIS\ Run a scan and save the log file and post the content of the log file here [using COPY-PASTE].

                          Once I see the log, I shall help you out of this. SDBot can not be cleaned effectively by any AV tools.

                          So go ahead if you can trust me
                          Many thanks for the help.

                          Before I do this, will the program conflict with my Avast? I have to be careful because of things being a bad idea having two Anti-Virus programs installed at once.

                          Many thanks.

                          Darren.

                          Comment

                          • src2206
                            Super Member
                            Super Member
                            • Jan 2007
                            • 234

                            #14
                            Do not worry Darren

                            It is not an AV, but an analysis tool, so no question of conflict.

                            One more thing, after you download and install HijackThis, do not run it.

                            Instead use the following program, which will automatically run HJT, and will provide me more detailed report about your system's condition.

                            Download ComboScan to your Desktop.

                            1. Close all applications and windows.
                            2. Double-click on comboscan.exe to run it, and follow the prompts.
                            3. When the scan is complete, a text file will open - ComboScan.txt
                            4. Copy the contents of ComboScan.txt in your thread.
                            5. A folder, C:\ComboScan, will also open. In it will be another text file, Supplementary.txt.
                            6. Attach Supplementary.txt to your post. Its a file containing lot of info, so posting it here using copy paste, will make your post very lengthy. So I prefer it as an attachment.


                            Note: some firewalls may warn that sigcheck.exe is trying to access the internet - please ensure that you allow sigcheck.exe permission to do so . I would rather suggest that you keep your Firewall and AV disabled just to save you from allowing

                            Do not worry, these are tested tools, and does not conflict with AVAST or any other AV.
                            Last edited by src2206; 10 Mar 2007, 07:37 PM.

                            Comment

                            Working...