AVAST Pro Missed this virus

hi guys i scan my hdd from my laptop using avast pro/ updated avast missed this virus? E:\d.com - ?? Win32/Pacex.Gen virus? ?this logs from nod32 2.7 :cry:

Can you send the samples to virus@avast.com ?
You can zip and password the files… Inform a link to this thread and the password used.
You can send the files to Chest and, from there, resend to Alwil for analysis.
Thanks for helping improving detection.

I’m sorry for the late reply… i don’t have the logs sorry :-\

Hmm… you mean the file, not the log?
Can avast detect it? Is your computer clean now?

yes i formatted already my computer :-[ i got this virus from the usb stick memmory.
anyway thanks for the reply :slight_smile:

more power AVAST team :wink:

Another one?

Datei H_tKeysH__k.DLL empfangen 2008.02.24 18:25:08 (CET)

Antivirus Version letzte aktualisierung Ergebnis
AhnLab-V3 2008.2.22.0 2008.02.22 Win-Trojan/Xema.variant
AntiVir 7.6.0.67 2008.02.22 -
Authentium 4.93.8 2008.02.24 -
Avast 4.7.1098.0 2008.02.23 -
AVG 7.5.0.516 2008.02.24 -
BitDefender 7.2 2008.02.24 -
CAT-QuickHeal 9.50 2008.02.22 CrackTool.HotHook.dll (Not a Virus)
ClamAV 0.92.1 2008.02.24 Trojan.W32.HotKeysHook.A-2
DrWeb 4.44.0.09170 2008.02.24 Tool.Hatkeys
eSafe 7.0.15.0 2008.02.21 -
eTrust-Vet 31.3.5557 2008.02.23 -
Ewido 4.0 2008.02.24 -
FileAdvisor 1 2008.02.24 High threat detected
Fortinet 3.14.0.0 2008.02.24 W32/Hotkeys.B!tr
F-Prot 4.4.2.54 2008.02.23 W32/Keylogger.BQ
F-Secure 6.70.13260.0 2008.02.23 W32/HotKeys.A
Ikarus T3.1.1.20 2008.02.24 Win32.KeyLogger.HatKeys
Kaspersky 7.0.0.125 2008.02.24 -
McAfee 5236 2008.02.22 -
Microsoft 1.3204 2008.02.24 -
NOD32v2 2898 2008.02.23 Win32/Keylogger.HotKeysHook.A
Norman 5.80.02 2008.02.22 W32/HotKeys.A
Panda 9.0.0.4 2008.02.24 -
Prevx1 V2 2008.02.24 Generic.Malware
Rising 20.32.62.00 2008.02.24 -
Sophos 4.26.0 2008.02.24 HotKeys Hook
Sunbelt 3.0.893.0 2008.02.23 -
Symantec 10 2008.02.24 -
TheHacker 6.2.9.228 2008.02.23 -
VBA32 3.12.6.1 2008.02.21 RiskWare.CrackTool.Win32.HotHook.dll
VirusBuster 4.3.26:9 2008.02.24 -
Webwasher-Gateway 6.6.2 2008.02.23 -

Did you send it to virus@avast.com for analysis?

Yes, i did.

And what about this one?

Datei deka-trn.exe empfangen 2008.02.24 18:32:48 (CET)

Antivirus Version letzte aktualisierung Ergebnis
AhnLab-V3 2008.2.22.0 2008.02.22 Win-Trojan/Clicker.1147051
AntiVir 7.6.0.67 2008.02.22 -
Authentium 4.93.8 2008.02.24 -
Avast 4.7.1098.0 2008.02.23 -
AVG 7.5.0.516 2008.02.24 -
BitDefender 7.2 2008.02.24 -
CAT-QuickHeal 9.50 2008.02.22 (Suspicious) - DNAScan
ClamAV 0.92.1 2008.02.24 Trojan.W32.HotKeysHook.A
DrWeb 4.44.0.09170 2008.02.24 Tool.GameCrack
eSafe 7.0.15.0 2008.02.21 -
eTrust-Vet 31.3.5557 2008.02.23 -
Ewido 4.0 2008.02.24 -
FileAdvisor 1 2008.02.24 -
Fortinet 3.14.0.0 2008.02.24 -
F-Prot 4.4.2.54 2008.02.23 W32/Keylogger.BQ
F-Secure 6.70.13260.0 2008.02.23 -
Ikarus T3.1.1.20 2008.02.24 -
Kaspersky 7.0.0.125 2008.02.24 -
McAfee 5236 2008.02.22 -
Microsoft 1.3204 2008.02.24 -
NOD32v2 2898 2008.02.23 Win32/Keylogger.HotKeysHook.A
Norman 5.80.02 2008.02.22 -
Panda 9.0.0.4 2008.02.24 -
Prevx1 V2 2008.02.24 Generic.Malware
Rising 20.32.62.00 2008.02.24 -
Sophos 4.26.0 2008.02.24 HotKeys Hook
Sunbelt 3.0.893.0 2008.02.23 -
Symantec 10 2008.02.24 -
TheHacker 6.2.9.228 2008.02.23 -
VBA32 3.12.6.1 2008.02.21 -
VirusBuster 4.3.26:9 2008.02.24 -
Webwasher-Gateway 6.6.2 2008.02.23 -

Hey… you’re browsing dangerously ;D

I don’t, but my brother-in-law :wink:

Hi ght1,

You can download the following program to your desktop and run it: http://www.techsupportforum.com/sectools/sUBs/Flash_Disinfector.exe
This program will close both Internet Explorer and Windows Explorer.
You will be asked to plug in your USB-disk. Repeat this for all the USB pen drives you own.

Download Combofix to your desktop from here: http://download.bleepingcomputer.com/sUBs/ComboFix.exe

If you have used Combofix before, remove the previous version, please, and download Combofix anew from the link mentioned above, because Combofix is being upgraded on a daily basis.

N.B.: whenever your AV or other realtime scanner alerts you during or after downloading Combofix or while using Combofix close down that scanner and download Combofix again. Some scanners consider ComboFix as riskware, and block or delete certain parts of it!

* Doubleclick  Combofix.exe
  Follow instructions, and accept the disclaimer by giving in "1" and confirm by giving "Enter".
  During running the tool, do NOT click inside, this could cause your computer to hang.

After the fix has been performed, a log combofix.txt will open.
Post this log as an attachment to your nect posrting, together with a fresh HijackThis log,

polonus

Hi don67,

In the case of Win32/Pacex.Gen virus here is a malware cleansing routine suggestion:
http://www.antispywareoffensief.nl/forum/showthread.php?t=33994

pol

Win32/Keylogger.HotKeysHook.A

I’ve seen a lot of these in otherwise perfectly clean trainers for games which use this library to hook keystrokes (when you activate/deactivate game cheats).

thanks a lot for the help sir :wink:

more power