Microsoft Windows XP
Media Center Edition
Version 2002
Service Pack 3
Intel(R) Core™2 CPU
T5200 @ 1.60GHz
1.60 GHz,
1.99GB of RAM
Yesterday I performed a boot scan with avast antivirus home edition version 5.0.545.
Avast found two malwares but both of them were system files i.e. they were shipped with this product(Windows XP).
The found malwares were :-
dodo.exe—this file was found in Program Files/EASY Internet Sign UP
and another
was a trial version of a game which was sold with this product by HP.(Since the computer is manufactured by HP).
I know (and am sure) that none of them are malwares but avast has stored them into the virus chest.What can I do so that they are removed from the virus chest and ignored by avast antivirus on further scans?
I have already submitted it to the virus lab.
Second question, Does Avast antivirus has false positives during scan???
Get yourself a second opinion before restoring the files from chest…!!
Use free Mbam: http://www.malwarebytes.org/mbam.php
And yes, every AV has FPs sometimes, but avast rather seldom.
asyn
dodo.exe is a process that is registered as Backdoor.Fluxay.47. Such files, which usually end up becoming a spyware or viruses when landing in your PC often differ from the original file that is not a threat, because they are located in other directories and have a different digital signature. To determine whether this is a real threat or not, to undertake a review with the tool of detection like virustotal.com (upload dodo.exe there). What are the results?
The file “dodo.exe” is known to be created under the following filenames:
This file can also be found at following location(s) (can also be found with different file name(s)):
%systemdrive%\documents and settings\dodo.exe
This filename is associated with the Malware groups:
Trojan-Downloader
This file was found in the following Malware families by analysis team:
Trojan-Downloader.Losabel.bt
ype : Trojan-Downloader