Win32:ctx / Win32:cholera-b[wrm]

This is really strange. I was researching the virus Win32:ctx on the Symantec website. I found their description and read what it does etc and then clicked the ‘Detailed’ tab and my avast (home edition) av sounded off that this site was trying to download Win32:Cholera-B[wrm]. It advised me to click ‘Abort Connection’ which obviously I did. I didn’t have to move any file to the chest.

The irony is that this is the last place that I would have expected to receive the virus that I was researching. I ran a full scan and nothing came up - rebooted, did another scan which was all clear.

Is there anything else I should be checking. I was wondering if there was any chance that the definitions might be giving a false alarm?

Geoff

Firstly the web shield block this before it can be downloaded and you only have the one choice, ‘abort connection’ so even if you wanted to send to the chest you couldn’t. So there was nothing on your system to find on your precautionary scans.

What was the full path to the infected file, ensure you break the link so it isn’t active, e.g. http :// www . example.com/example.htm, etc. etc. ?
Check the avast! Log Viewer (right click the avast ‘a’ icon), Warning section, this contains information on all avast detections.

With the full path it should be possible to check.

It’s normal. It was before any file was saved in the disk. This is how WebShield works.

I don’t think so.

If you update avast and try again, or, like David said, post here the link (edited), we can give it a try.

Hi David and Tech - thank you both for your swift replies. Looks like WebShield does a good job!

I found the warning section that you spoke of and the entry is:-

27/08/2007 20:22:32 1188242552 SYSTEM 1340 Sign of “Win32:Cholera-B [Wrm]” has been found in “http://www.symantec.com/security_response/writeup.jsp?docid=2000-121515-5132-99&tabid=2” file.

Tech - my definitions are right up to date, and were at the time this occurred. I am nervous of going in and trying it again, and would appreciate if you could check the link out please. I would be glad to know of the outcome as it would confirm whether my computer is safe or not.

Thanks again,
Geoff

Hi All,

thanks for useful information.

It’s false positive alert and will be solved in next VPS update (769-1)

Thanks misak - that is very reassuring. I’m glad we have this forum where we can investigate such matters.

Thanks to all

Geoff

As Misak said this is a false positive as the DrWeb link checker doesn’t detect anything. I also uploaded it to VirusTotal also and the results, only avast detects it.

Welcome to the forums.

Thanks David for all your checking. That confirms that it is just Avast saying it is a virus. It’s nice to have a forum like this to help us in our hour of need (or panic, should I say).

Geoff

This FP has been corrected in the latest VPS update.