Win32:Trojano-228 [Trj] in corelsys.dll

Hey,

Just ran Avast! on my machine for the first time, and it got some known trojans other AVs couldn’t find.
:smiley: Well done, guys! :smiley:
It also found this one trojan I’ve not been able to find anything about.

It’s called Win32:Trojano-228 [Trj]
The infected files were:

c:\windows\system32\corelsys.dll c:\windows\corelsys.dll

Do you know anything about it?
Any special removal procedures?
Do I need to send it the Avast team for disection?

Cheers!
T

you can submit it herehttp://virusscan.jotti.dhs.org for a quick check on several a/v but it souds to me like a false pos
If it is indeed that then submit it in a password protected zip to Avast (link is in chest) and hopefully it will be corrected ,meanwhile you can add it to exclusions to stop it being detected

If avast detected it (there is no need to send it), the safest thing to do is move it to the chest. From here it can do no harm and gives you time to investigate. Generally trojans cant be repaired and delete is too severe a first step.

A google search returns some hits, enough to be suspicious of it being malware, http://forums.majorgeeks.com/printthread.php?t=39695 but confirm with Jotti.

Send files to Chest is a secure way to not make anything wrong…
Wait some days and be sure it’s not a ‘false positive’ (not a real infection).
After that, you can delete them.

Like David said, no, it’s not necessary in this cases :wink:

I tryed Jotty and it is malware.
Thanks, all. :slight_smile:

So, you can delete it from Chest if you want…

This really proves the rule, if in doubt ‘Move it to the Chest’ and investigate.

  1. Don’t leave it in situ.
  2. Don’t add it to exclusions unless you have confirmed it as an FP and even then it should be in the chest until confirmation.

It can’t do any harm in the chest, it can be checked out, it can be restored, it can be moved and finally it can be deleted all from the Chest.