Bzub-da

I have just done a quick scan and detected a virus called bzub-da. I cant find any info on it and Avast cannot delete it, rename it or remove it.
Has anybody heard of this virus and if its dangerous? If so how do you get rid of it?

It is a password stealing malware with keylogger and formgrabbing abilities. So you can call it dangerouse. Where does Avast find that malware.

What is the infected file name, where was it found e.g. (C:\windows\system32\infected-file-name.xxx) ?
Check the avast! Log Viewer (right click the avast icon), Warning section, this contains information on all avast detections.

Hi manta222,

Does this ring a bell?
http://www.f-secure.com/weblog/archives/archive-022007.html#00001112
the file could be this: C:\WINDOWS\system32\ipv6monl.dll → Logger.BZub.fg
for a variant of this see: http://www.sophos.com/security/analyses/trojcimuzar.html

polonus

Avast originally detection came up as windows/2 and when i tried to move or delete it came up as access denied. I have looked in the avast list and it has the location as c:windows. The name is 2.exe. the virus id is is win:32 Bzub-da(trj).
I whent searching for this file and found it in windows/system 32 I dleted it and it dissapeared so far it has not reapeared. Seems a bit to easy to me. I will do a full scan and post my findings.
I have also noticed previous scans have detected and moved Bzub-ch & Bzub-cg.

For the future if you experience problem with avast not being able to deal with a virus.

Windows in its infinite wisdom protects files in use (even malware) or in system folders, so it is likely that avast! can’t delete or move files in use. So schedule boot-time scan in avast’s menu if you have XP, win2k or NT, otherwise boot into safe mode and run an avast scan. This should ensure that the file isn’t in use and avast should be able to deal with it.

If you have XP or Win2k, you could enable a boot time scan. Right click the avast icon, select Start avast! Antivirus, Menu, ‘Schedule boot-time scan…’