Page 1 of 2 12 LastLast
Results 1 to 10 of 19
Like Tree5Likes

Thread: Virus found in pendrive by ESET but avast and MBAM says is clean.

  1. #1
    Rookie
    Overall activity: 7.0%

    Join Date
    Jan 2009
    Location
    Malaysia
    Posts
    2,138
    Liked
    24 times
    Points
    44,879

    Virus found in pendrive by ESET but avast and MBAM says is clean.

    I plug my pendrive into my uni computer and their AV (ESET) said it detected a virus in my pendrive and I press clean but I think it didn't clean. They are using ESET v2.th turn

    So I came back and scan it with avast free and MBAM and both turn up clean. Decide to go further by openning it in sandboxie (my pendrive) and no prompt from avast or Comodo Defense +.

    Scan it with ESET Online Scanner and it gave me the following result :
    H:\alice.alc VBS/AutoRun.AO virus

    But when I open my pendrive, there is no alice.alc file even with show hidden files, folders and drives enable?

    How do I look for the file that is not there and upload it to virustotal or to avast for investigation?
    Thoughts are like a never ending ocean where it is deep, endless and dangerous

  2. #2
    Administrator
    Overall activity: 62.0%

    Join Date
    Nov 2006
    Location
    Malaysia
    Posts
    9,804
    Liked
    1656 times
    Points
    48,752
    Probably the file has system attribute.
    Go to Control Panel > Folder Options > Uncheck Hide protected operating system files.
    Check the file and see if it's there.

  3. #3
    Malware Hunter
    Overall activity: 0%

    Join Date
    Sep 2009
    Location
    Kolkata, India
    Posts
    485
    Liked
    104 times
    Points
    6,801
    Probably a false positive, since both avast and MBAM has better detection than ESET. Enable hidden file viewing as Raymond has suggested and upload it to Virustotal.

  4. #4
    Administrator
    Overall activity: 62.0%

    Join Date
    Nov 2006
    Location
    Malaysia
    Posts
    9,804
    Liked
    1656 times
    Points
    48,752
    Did a research on "alice.alc" and indeed it is a malware.
    It infects on USB and I believe autorun.inf is not present in Lunarwolf's USB drive, which is why MBAM and Avast did not detect it as threat.

  5. #5
    Rookie
    Overall activity: 7.0%

    Join Date
    Jan 2009
    Location
    Malaysia
    Posts
    2,138
    Liked
    24 times
    Points
    44,879
    Here is the virustotal link.

    http://www.virustotal.com/file-scan/...bff-1322299528

    From the results, it does look like a malware.

  6. #6
    Supernova
    Overall activity: 76.0%

    Join Date
    Feb 2010
    Location
    Calcutta, India, India
    Posts
    3,730
    Liked
    667 times
    Points
    48,426
    You better use some additional protection like No Autorun or Antirun because signature based anti malwares tend to miss things. Malwarebytes though very efficient but is not intended to be a replacement of an antivirus. I am surprised that Avast failed to detect it. You need to submit them the file (may be to Panda,Vipre too).
    I think comodo missed the file as you were using the firewall and you have opened the usb drive the file sandboxed. When you run anything through sandboxie actually the process doesn't comes into the process list and as sandboxie process is already allowed in Comodo you will not get any prompt.

    P.S: If autorun.inf is not present in your pen drive then No-Autorun and Antirun won't give any prompt.
    Every day brings a chance for you to draw in a breath, kick off your shoes, and dance.

  7. #7
    Rookie
    Overall activity: 7.0%

    Join Date
    Jan 2009
    Location
    Malaysia
    Posts
    2,138
    Liked
    24 times
    Points
    44,879
    I used panda usb vaccine and bitdefender usb immunisation.

    I actually happen to run it without sandboxie. (By accident) No prompt from avast behaviour shield (set it to ask), defense + nor winpatrol. The file is only about 7KB big.

  8. #8
    Supernova
    Overall activity: 76.0%

    Join Date
    Feb 2010
    Location
    Calcutta, India, India
    Posts
    3,730
    Liked
    667 times
    Points
    48,426
    Quote Originally Posted by LunarWolf View Post
    I used panda usb vaccine and bitdefender usb immunisation.

    I actually happen to run it without sandboxie. (By accident) No prompt from avast behaviour shield (set it to ask), defense + nor winpatrol. The file is only about 7KB big.
    hmm then might be autorun.inf was absent. I am sure that your system wasn't infected.

  9. #9
    Administrator
    Overall activity: 62.0%

    Join Date
    Nov 2006
    Location
    Malaysia
    Posts
    9,804
    Liked
    1656 times
    Points
    48,752
    Send the file to sujay and he has a "private tool" that can automatically send the sample to Avast and other vendors

  10. #10
    Malware Hunter
    Overall activity: 0%

    Join Date
    Sep 2009
    Location
    Kolkata, India
    Posts
    485
    Liked
    104 times
    Points
    6,801
    Quote Originally Posted by Raymond View Post
    Send the file to sujay and he has a "private tool" that can automatically send the sample to Avast and other vendors
    Raymond, if it's not too much to ask for, can I have one too? It's my hobby..

 

 
Page 1 of 2 12 LastLast

Similar Threads

  1. Eset Virus Signature Database Update 5418 may cause issues
    By leofelix in forum Spyware/Viruses
    Replies: 8
    Last Post: 09-06-2010, 12:02 PM
  2. Clean your junk files in one click with Quick Clean
    By riteshtechie in forum Software
    Replies: 4
    Last Post: 03-05-2010, 04:08 AM
  3. Can virus change the name of a pendrive?
    By LunarWolf in forum Spyware/Viruses
    Replies: 4
    Last Post: 07-19-2009, 02:55 PM
  4. ESET Anti Virus 4 Update Problem
    By YuMeng in forum Spyware/Viruses
    Replies: 4
    Last Post: 04-18-2009, 10:15 PM
  5. Pendrive virus problem!!
    By Doink in forum Hardware
    Replies: 4
    Last Post: 02-13-2008, 02:36 PM
All times are GMT +8. The time now is 10:01 AM.