A quick scan (full scan takes ages as I have millions of filesā¦) didnāt show up anything, nor did I notice anything in the logs.
HOWEVER I also have microsoft live family safety scanner running and the logs report
Program Description Web address Last visited ā¼ Visits
hiddenX.exe gDGTEvDF http://XXXhi5gallery.net 3/24/2009 6:54 PM 1
Edit: Iāve added XXX in that URLs above to prevent anyone accidentally going there!
SInce this isnāt web browsing per se it doesnāt block, only report. Also the above is 5 minutes after I received the first āspamā msn message but is the only remotely suspicious entry I can see
So questions include
Should avast have protected me?
Is there an issue with using MS FSS and avast together?
Am I likely infected?
What is the virus, how to clean?
Needless to say āeducationā is on my list too⦠Iām also planning to do some manual hunting with hijack this and a full scan tonight.
My hope is that whilst the .EXE was launched it would have been unable to update anything ⦠but if this was the case why didnāt avast real time scanning pick it up??
Just because you have an Anti-Virus installed, it doesnāt mean that it knows about every virus ever made. Sometimes viruses get through, it can happen to any A/V program.
If it is considered a virus, then it may be helpful to send it in a password protected zipped file to virus@avast.com with virus in the subject and the password to open the zip file in the body of the message.
I think that MSNās messenger program is ran either in a secure tunnel or the connection is encrypted, so that may be the reason that Avast wasnāt able to pick it up. Iām not totally sure about that one though.
Ran a full scan with avast (and spybot) and avast found a generic Win32:Trojan-gen in temporary internet files
No sign of it elsewhere. Nothing running. No signs of bad behaviour. No reoccurance (it only happened/got run once)
So I think whilst the exe was launched it couldnāt do anything (wasnāt running as admin)
⦠I hopeā¦
I did also double check by downloading the eicar test virus that the realtime scanner kicked in fine, so Iām still confused why the real time scanner may have missed this trojan