i have here a virus, which hadn’t been detected by avast!
the symptoms are links on each web page on word like ‘Microsoft’,‘people’,‘download’ and other. if you click them, a site(‘www.ntsearch’) will appear. the start page of the internet explorer from microsoft will be each new reboot '“http://%6F%6B%6F%77%62%6A%2E%74%2E%6D%75%78%61%2E%63%63/%68%2E%70%68%70?%61%69%64=33”.
if you detect these symptoms you have to open your registry and on key [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] and remove “sys”=“regedit -s sys.reg”. next reboot you can delete the file “%windir%\sp.exe” and “%windir%\sys.reg”.
if some avast employeer read this, they can add these virus to their iAVS update.
i have a appended the virus files packed to zip-file with fake extension .jpg
i recommend not to open these files!
by Narrator