On scanning my laptop today the above apparent malware was detected which I duly transferred to the virus chest. The event viewer shows the entry:
Sign of ‘‘Win32:Trojan-gen{Other}’’ has been found in ‘‘C:\Windows\MOTA113.exe[tElock]’’ file.
Has anyone else reported this please? If you want to review my detection, please tell me precisely how to locate the chest entry and where to send it. Thanks.
You can open avast Chest and see the folder Infected files on it.
You do not have to deal with the files into Chest, let it there for a while to confirm it’s an infected file.
I’ve found out now how to access the virus chest and uploaded the file to virustotal.com which returned the result 0/39. Presumably that means a false positive?
I suppose you did not upload the file from Chest, but the original one. The file from Chest is encrypted and won’t be detected as infected (it is on the Chest folder of avast).
Indeed, if you send the original file, seems a false positive. Can you know from which program does it belong?
I uploaded the file from the Chest in my ignorance :-X Of course it is encrypted so my uploading to virustotal.com was crap…sorry. The only information I know of the detection is what the event log entry showed as quoted in my first post.
You can extract the file to a safe folder, do not execute the file, add it to avast exclusion lists and then upload to virustotal.
Can you tell me how to actually extract a copy of the file safely from the chest to a new ‘suspect’ folder please? I don’t see any right click option in the chest folder. You might have gathered that I’m a bit thick in certain areas
Hi Greenhatch,
I had a similar problem.
Create a folder called Suspect in the C:\ drive, e.g. C:\Suspect. Now exclude that folder in the Standard Shield, Customize, Advanced, Add, type (or copy and paste) C:\Suspect\* That will stop the standard shield scanning any file you put in that folder. You should now be able to export any file in the chest to this folder and upload it to VirusTotal without avast alerting.
taken from: http://forum.avast.com/index.php?topic=37451.0
Hope this helps.
Hi Greenhatch,
I had a similar problem.
Create a folder called Suspect in the C:\ drive, e.g. C:\Suspect. Now exclude that folder in the Standard Shield, Customize, Advanced, Add, type (or copy and paste) C:\Suspect\* That will stop the standard shield scanning any file you put in that folder. You should now be able to export any file in the chest to this folder and upload it to VirusTotal without avast alerting.taken from: http://forum.avast.com/index.php?topic=37451.0
Hope this helps.
Hi. Do you have the Pro version of Avast? I have the Free and the simple option of right click on the systray ‘a’ icon does not reveal an export line in the dropdown to me. So hopefully there is a simple step-by-step procedure Tech (or a mod) can advise me how to export a copy of the quarantined file from the chest to a suspect folder.
Hi,
I have the free version as well. I should put my specs on the signature part. That should speed up things.
Now back to you.
First off, right clicking on the A icon will not help in this case.
Here’s what you do. Start avast. Look for the icon/button that says Virus chest. Click on it. Once there look for the problem file. Select it, then right click and choose extract. After this, select (browse if you will) the file that has been excluded from the scanner. Did this Help?
Hi,
I have the free version as well. I should put my specs on the signature part. That should speed up things.
Now back to you.
First off, right clicking on the A icon will not help in this case.
Here’s what you do. Start avast. Look for the icon/button that says Virus chest. Click on it. Once there look for the problem file. Select it, then right click and choose extract. After this, select (browse if you will) the file that has been excluded from the scanner. Did this Help?
Simple when you know how, right, lol? Very helpful!
Great,
Glad to be of service. Keep us posted on what you find.
Tech and Avast staff:
I uploaded an unencrypted copy of the file to virustotal.com and got a result returned of 5/39. So I’ve set up the user/email facility to send Alwil the file on the next update for investigation just in case. Regards
greenhatch, can you post the link to the file into virustotal, I mean, the virus total results link?
We can analyze it.
greenhatch, can you post the link to the file into virustotal, I mean, the virus total results link?
We can analyze it.
https://www.virustotal.com/analisis/08816bf11f8403c244d934310c96465f
Hello All,
I too registered exactly the same item at exactly the same time. This smells like a false positive.
However I shall wait for the clearance from the experts and gurus.
Hope there’s a quick Avast response!
Avastfan1
PS: @Tech: I found this related thread by chance and it didn’t show up in the search function? :S
Hi Avastfan1,
Reassuring info here: http://spywarefiles.prevx.com/RRHJEF9220657/MOTA113.EXE.html
But also this: Super(R) is SPYWARE and MALWARE. Check c:\Windows directory, you will find files like meta4.exe, mota113.exe, x2.64.exe, system32\x.264.exe and others. Google those file-names, and pray you did not enter credit card info on your computer…owned:
Or upload the file in question to virustotal.com and give us the results,
polonus
Hi Polonus,
Thanks for the information. I was initially reassured with your first link. Then I read the second part about Super(R) and now feel very worried and scared
I did indeed find those files in my windows directory. Should I delete them?
I uninstalled Super(R) immediately following your advice.
However it didn’t uninstall those files. I have scanned my computer with the following programs and none of them recognised any of those files except Avast. I have had Super(R) installed for a long time and Avast NEVER once alerted me to spyware or adware.
Even the other anti-spyware/anti-malware programs (please see below) have never raised an issue with it.
Please help me Polonus!!
Thanks!!
Avastfan1
Malwarebytes - No infections
Kaspersky online scan - no infections
SuperantiSpyware - no infections
ZA Anti-spyware - no infections
Hijackthis Log - no red cross items (sent to http://www.hijackthis.de/)
Avast - refer to previous post
Rootalyzer - no infections
Blacklight anti-rootkit - no infections
Hi Polonus,
Here are the results for those files:
meta4.exe
jotti.org - found nothing
virustotal - only 2/39:
- CAT-QuickHeal found (Suspicious) - DNAScan
- eSafe found Suspicious File
x2.64.exe
jotti.org - found nothing
virustotal - only 3/39:
- CAT-QuickHeal found (Suspicious) - DNAScan
- eSafe found Suspicious File
- Sunbelt found Trojan.Win32.Packed.gen (v)
system32\x.264.exe
jotti.org - found nothing
virustotal - only 1/39:
- eSafe found Suspicious File
Please note: I can’t upload MOTA113.exe because when the Avast alert sounded - I ticked ‘no action’ and this seems to be preventing me from uploading the file.
PLEASE, PLEASE, PLEASE help me Polonus! I am not an expert at all, but I’ve always tried to keep my anti-virus, anti-spyware and anti-malware up to date.
Thanks!!
https://www.virustotal.com/analisis/08816bf11f8403c244d934310c96465f
It’s not easy to say… maybe a false positive, maybe on contrary avast in is the first ones to detect…