trojaner win32:qqpass-dy

hello there,

for about 2 hours i get the message from a few of my customers that avast! had
found the trojan win32:qqass-dy … this one is updated in the vps from this day.

… but my customers cannot remove it, avast! says everytime again that he found
this virus and then the system is totally blocked …

has anyone an idea. thankx for soon reply.

greetings marco.

Hello! I have the same problem since 05 pm. today and I don’t know what to do. Everytime I scan my system with Avast the warnings about the trojans appear. (I put them in the container everytime)

I hope that someone can help us soon :wink:

Domme

Please, post the name and path of the infected file(s).

Hello! I made a screenshot which you can find here :

http://img47.imageshack.us/my.php?image=unbenanntjp7.jpg

greetings

Domme

Hello :slight_smile:

Please update to the latest VPS - 0643-6 :wink:
There was a False Positive with win32:qqpass-dy today.
http://forum.avast.com/index.php?topic=24494 :wink:

Anyway, for further info, when a virus is replicant (coming and coming again), you should:

  1. Disable System Restore on Windows XP: http://support.microsoft.com/default.aspx?scid=kb;[LN];310405
  2. Clean your temporary files.
  3. Schedule a boot time scanning with avast. Start avast! > Right click the skin > Schedule a boot-time scanning. Select for scanning archives. Boot.
  4. Use a-squared, Free AVG Antispyware, SUPERantispyware or Spyware Terminator (trojan removers).

Allright. Thank you for your help ;D

You’re welcome.

Just a tip :slight_smile:

If you think you have a false positive do an online file scan by at least 2, or better more competitors of Avast. If their scans show op clean, you can exclude the file from being scanned in : Standard Shield - Configuration - Advanced … and add the path of the file. And when the false positive is solved with an update, you remove the path of the file.

Greetz, Red.

P.S. I use the Dutch version of Avast, so I hope my translation of the Avast Menu Items is right.