My scan this morning identified C:\prog files\symantec\liveupdate\DISreboot.exe as malware.
I sent it up to VirusTotal and it said it had already been analysed. I looked in these forums and found it identified as a false positive here
I’ve sent it again to, but find it strange that it has appeared again. Before I scanned, I received an error message to do with storage and the FAQs said I should change avast4.ini to Database=XML, which I did. I subsequently got the DISreboot.exe malware which I moved to chest. Could this have anything to do with it?
I Suggest
Try Avast Pro first make sure it’s up to date then performed an all system scan afterward delete the files which is contaminated with the malware/trojan
If Avast Fails to remove the malicious software then try the ffl scanner to remove it
the malicos program is some kind of malware/trojan so SuperAntiSpyware is able to detect it and delete it
Download SuperAntiSpyware
Install to System
Update to current Date
Look for program setting and check full system scan
If the malicious software is Detected then Delete it
It will require System Restart to take effect
Use the ffl Program if Avast dint succeed on deleting the malwere/trojan.
Not sure I understand your reply. Are you saying this is malware if DISreboot.exe is in the directory? Because mine isn’t. I’ve run SUPERantispyware and it came up clean. I’ve moved it ot the chest. Presume it’s safe there. What now?
What Symantec programs do you still have installed on your system ?
If none then technically you don’t need the live update function, take care there are programs that you might not expect are owned by Symantec. I have winfax pro (on my old system) and that was bought out by Symantec and as such I too have live update.
Check the symantec\liveupdate folder there will be some files that indicate what applications are covered by the live update process (open with notepad). I you no longer have any of those installed you can uninstall the live update.
You could also check the offending/suspect file at: VirusTotal - Multi engine on-line virus scanner and report the findings here. You can’t do this with the file securely in the chest, you need to extract it to a temporary (not original) location first, see below.
Create a folder called Suspect in the C:\ drive, e.g. C:\Suspect. Now exclude that folder in the Standard Shield, Customize, Advanced, Add, type (or copy and paste) C:\Suspect* That will stop the standard shield scanning any file you put in that folder. You should now be able to export any file in the chest to this folder and upload it to VirusTotal without avast alerting.
Thanks for replying David. Symantec products I use are Norton Utilities (Win98). It’s true I don’t ever use Live update so no problem with leaving it in the chest. Strange though, that it’s been on my PC for years and now it gets flagged up as malware.
I uploaded the file to VT and the results was that 7 out of 36 thought it was dodgy. They were
It is possible as many report this as adware-gen (a generic signature detection) and suspicious (heuristic detection), which are more prone to false positive.
However, there are a few with specific signatures AdWare.Win32.Alibabar, so it certainly needs further analysis and sending it to avast is the correct way. Whilst avast are quick to correct any FP when identified, it has to be first analysed and this takes a little more than a few hours.
