Artūrs
April 7, 2017, 7:40am
1
Hello!
We are using Avast Endpoint Protection SUITE PLUS and once at week we scan our computers. {All harddisks, Operating memory of the computer, Auto-Start Programs (All Users)}
Almost in every scan we get some computers with something like this:
\{computer name}*PROCESS\1bf8\firefox.exe\22810000\13d000 Infection: Win32:VBCrypt-AGT [Trj]
\{computer name}*PROCESS\1164\excel.exe\eced000\1c6000 Infection: Win32:VBCrypt-AGT [Trj]
\{computer name}*PROCESS\a0c\winword.exe\b800000\ff000 Infection: Win32:VBCrypt-AGT [Trj]
\{computer name}*PROCESS\1d00\acrord32.exe\a70000\ff000 Infection: Win32:VBCrypt-AGT [Trj]
\{ComputerName}*PROCESS\820\explorer.exe\730000\ff000 Infection: ?
And more similar… On next scan there is not any infection {on same computer}, even boot scan not found anything…
Question is should I be worry about it and is there any suggestions?
Pondus
April 7, 2017, 7:54am
2
Upload and check file(s) here >> www.virustotal.com
If you see file as scanned before, click rescan for a fresh result
Artūrs
April 7, 2017, 8:01am
3
Hello! Thanks for quick answer!
Where is no files… Nothing in virus chest…
Pondus
April 7, 2017, 8:04am
4
\\{computer name}\*[b]PROCESS[/b]\1bf8\firefox.exe\22810000\13d000
have you changed default scan settings? ... and selected scan memory?
This may give some weird scan results, it used to be an issue with home versions, dont know about endpoint
Artūrs
April 7, 2017, 8:12am
5
Yes, as I wrote before where is set to scan “Operating memory of the computer”.
system
October 3, 2017, 12:15am
6
Artus, were you able to get to the bottom of this? I’ve been dealing with the same thing for several months…
Thanks.
system
November 6, 2017, 12:23pm
7
I’m getting the same problem on a fairly regular basis. The infected file is always swift-ddmmyyy[nnnn].ace
I’d really like to get to the bottom of this, too.
Cheers
Pondus
November 6, 2017, 3:58pm
8
I’m getting the same problem on a fairly regular basis. The infected file is always swift-ddmmyyy[nnnn].ace
I’d really like to get to the bottom of this, too.
Cheers
Do you use endpoint / business program? This is the business forum section
If you are a home user, start a topic in Viruses and Worms forum section
attach a screenshot of avast message, we need to see all info avast give