Win32.Bagle.SWQ

:frowning:

Our Avast 4.8 Professional hasn’t found the Win32.Bagle.SWQ virus !!!
AVAST has been disabled (!!!) and other exe are no more recognized.
This virus uses the srosa2.sys file.

Regards.
Massimo

[font=Segoe UI] Are you able to remove it? If not, please consider using the following:

(1) Malwarebytes Antimalware. Don’t forget to update it before running a scan.

(2) Hijack This, how to use:

http://h1.ripway.com/chronoboi001/HJT.jpg
Please download HJTsetup.exe
2. Save HJTsetup.exe [preferably, in your desktop.]
3. Install Hijack This to C:\Program Files\Hijack This.
3. Continue to click Next in the setup until you get to see Select Addition Tasks.
4. Put a check on Create a desktop icon then click Next. Continue following the next prompts until you reach the last part.
6. On the last part, click Finish. Hijack This Main Menu will appear.
7. Click on the Do a system scan and save a logfile button. A scan will be processed and when its done, notepad will appear.
8. On notepad, copy the entire log through clicking on Edit > Select All then click on Edit > Copy.
9. Head back here in the forums and paste the copied files onto your next reply.

NOTE: DO NOT let Hijack This fix anything yet.

Yes, we’ve been able to remove it using BitDefender online version.
Many other antivirus software can detect it.
I really hope that Avast add support for this very dangerous worm asas.
It isn’t nice that a virus can disable Avast !!!

Hello,
viruses are able to disable more antiviruses then just avast.
Can u post this file here pls? zip it with some password like virus and write this password to your post.
Thanks.

Send the sample to virus@avast.com zipped and password protected with the password in email body and undetected malware in the subject.

Or you can also add the file to the User Files (File, Add) section of the avast chest (if it isn’t already in the chest) where it can do no harm and send it from there. A copy of the file/s will remain in the original location, so you will need to take further action and can remove/rename that.

Send it from the User Files section of the chest (select the file, right click, email to Alwil Software). It will be uploaded (not actually emailed) to avast when the next avast auto (or manual) update is done.

Sirmer, welcome to avast team!

No doubt about the fact other antiviruses can be disabled by certain viruses :cry:
More, obviously other more celebrated antiviruses will not find this and other viruses too.
But I’m using Avast … and Avast didn’t find this one.
And this the only fact that matters to me as I’m wasting time trying to recover my pc.
That’s why I have pointed out the problem, in the hope you’ll add something in Avast to avoid this in the future.

I sent to virus@avast.com the zip file “Win32_Bagle.zip”, password protected.

Thanks a lot.
Massimo

Thanks for trying to help improve detections.


Welcome to the forums, mclot, and thanks for helping with detections. :slight_smile:

Welcome to the avast team, Sirmer. :slight_smile:


Is really a shame that one month after, avast not detect the Win32.Bagle.SWQ. My computer was infected yesterday and the BitDefender Rescue disk cant solve the problem (sorry for my bad English).

What is really dissapointing is that no one here(avast team) seem to worry about the fact that AVAST doesn´t do the only thing we want it to do: protect from viruses

Couldn’t you at least give some explanation why avast can’t detect this MF virus after so long time?

In my case I managed to get away because I use to log in as a user that doesn’t have administrator rights. Then when the infection began I managed to log out, and log in again with the administrator user and restore to a previos “Restore point” before the virus took control of this user’s environment too.

So my advice is: don´t use your PC as an administrator user, in case your antivirus fails you still got a chance…

any antivirus can do something about bagle, this is a virus that you get when download a cracked program,
in the same moment you click the file exe the bagle infect your pc and believe me, is very hard to delete because bagle has more than 50 version.

More than 50 versions, I think that you underestimate that figure, avast’s virus database has 1020 different signatures for beagle and some of those are generic to attempt to catch multiple different variants. Even then there are new variants capable of getting past most AVs, it is an ongoing battle and one of catch-up.