worse virus ever

i have just had to re-install windows after a virus deleted every single .exe, .mp3, .avi, .mpeg i had on my computer in about an hour.

I sat there and watched as they simply disappeared and avast! couldnt find a thing wrong. Neither did the online scan at Trend.

When i re-started my comp after seeing it first, nearly every running process crashed.

Some processes also started loading a c prompt before crashing.

none of my programs would load including avast!

all of my restore points had been deleted

some programs were changed back to original factory settings such as msn (i had 6.2) was suddenly 4.2

i would love to know what this was, and what i can do to stop it happening again. I have never seen anything like this before

Hate to say it, but i’ve seen a few trojans like this. In fact, I have many many samples of them. Most of which were sent to Avast a week ago and still aren’t in the doggon database! What up?

If you caught a name of it, let me know, i’ll check it with my records to see if its one of the hundreds I sent to Avast. Mighta prevented this maybe, ugh.

Unfortunately, many AV’s are 100% ITW, but hopelessly neglected threats from say 2 years ago, which the average joe are more likely to run into in my experiance. Gotta shore up those databases from the old threats too and not ignore them!

sorry i didnt get a name as nothing was found before i formatted. why arent they in the database? what are we paying for then??

Im sure they are in the process of added them, btw i was just like to ask how you came about finding these hundreads of trojens?

The people by working Avast are quite busy at the moment.You can see here http://www.avast.com/eng/viruses/vps_history.html What for virusses is in the database

not being rude, ok yes i am, but i couldnt care less whether they are busy or not. Thats what we pay for, or supposedly.

I am now re-installing everything including windows for the second time in 24 hours after it infected my backups too. I have lost years of work, photos and everything. Simply because they dont have old records added…what a joke guys. how about a refund?

That’s simply not true. We don’t really care about the age of the malware…

I doubt it was a Trojan either…

Of course, I agree.

Now I’d recommend focusing on the main thing – getting back the data.
Are you saying that your backups contain files that are already truncated/overwritten? What I’d need is some kind of trace from the beast. So that we could tell what it was. Is it still on the back ups then?

ok sorry for the above. have calmed down now. I went to a cyber cafe and transfered my data from one disc to another without touching any .exes.

they are running nortan anti virus and it picked it up straight away, labeling it as w32.axon.B

is this in our viruses and if so how come it didnt pick it up?

edit. i do have the file still on my back ups, but unless u want me to send a cd-r through the snail mail, i am afraid i am going no where near it

Seems like avast detects AXON(.A) as “Win32:Xenon”, but not AXON.B
That’s a pity…

I’m sorry about your files, hungrylilboy,
and avast SHOULD have detected it,
and you will neither like this, nor does it help you at present,
but as a hint for the future:

a) we don’t live in a perfect world:
b) FACT: no AV-scanner offers 100% detection/protection
c) if I look at your past postings & at the description of AXON.B:
"This virus has been distributed on peer-to-peer file-sharing networks, using deceptive filenames such as “Keygen.exe.”

→ you should exercise some more caution when using your PC & moving about the internet

P.S.: I hope your MP3 & AVI on (external ?) backup media are still intact ?

P.P.S: According to the date when Win32:XENON was included in avast’s database, it could also be that this includes BOTH AXON/XENON-variants ?
Mabe VLK could comment…

HLB: Your resident shield & P2P-Provider was always on & configured correctly ?


Is it possible that Avast! was infected and wasn’t working right? I know this happens to my dad’s norton quite often…

I don’t think so but it’s recommended by any antivirus to scan just after the installation or even before, by a clean CD :-\

hungrylilboy, is there anything more we can help you? :-\

If you haven’t already done so you should patch a vulnerability which this virus exploits.

Virus Prepends Itself to Files With .Exe Extensions

W32.Axon.B is a virus that prepends itself to the files with the .exe extension. It also deletes the files with .mp3 and .avi extensions.

Technical details are at this Symantec page.

Worm Exploits Microsoft Vulnerability

W32/Cycle.worm is a worm that spreads by exploiting a Microsoft Windows vulnerability [MS04-011 vulnerability (CAN-2003-0533)].

The worm copies itself to the Windows system directory as SVCHOST.EXE, for example:


It installs itself as a service (“Host Service”) on the victim machine:

HKEY_LOCAL_MACHINE\System\CurrentControlSet\ Services\Host Service

The service bears the following characteristics:
Display name: Host Service
Image path: %SysDir%\SVCHOST.EXE
Startup: automatic

A text file containing a political message is dropped to %WinDir% as CYCLONE.TXT:

%WinDir%\CYCLONE.TXT (3,316 bytes)

A side-effect of the worm is for LSASS.EXE to crash, by default such a system will reboot after the crash occurs.

The following Microsoft update should be installed to be protected from the exploit used by this worm. See this Microsoft page.

This patch has been on the MS windows update site for some time. Everyone should ensure that their OS is fully updated.


I was told by the virus guys that Axon is detected by avast as Win32.Xenon. I’m not sure about the .B variant, though… :-\

Looking over my data I see that I submitted Axon.b to Avast about a week ago.


hungrylilboy, do you have any idea about how you got infected (email, P2P, web download, …). The Axon virus is not exactly common… :-\

sorry been away.

1)my pc was fully up to date with windows update. This mean that the windows fix doesnt work?

2)i lost all my mp3 and avi file

3)i was looking for the netmeeting file, conf.exe and couldnt find it anywhere on google, so did end up using kazaa. Big mistake I know. (by formatting, i do have my real conf.exe back though! ;D) (just looked again to try and get a hash but cant find it. Had about 15 users, was “correctly” labelled - at least one person had anyway)

4)please can this be added as this is the nasiest virus i have ever encountered

5)sorry again for stressing earlier. Bit hard losing all that work (oh forgot to say that most of the mp3 were my own work)

6)avast! definately got infected. Think it was one of the first, because as soon as I realised I had somehing wrong, I tried to open it and it opened a c prompt and crashed.

7)avast! was running properly before this

  1. i dont use p2p much but i though avast! was set to automatically scan them?

Hi david,

I didn’t find any info on vulnerabilities related to AXON.B:
could you post a link ?

Always the lesser common ones I run into… Some kid pulling something off a VX site, then dropping it into a file and thinking hes funny.

I seldom run into ITW’s, so I consider 1-4 year old threats to be my nemesis… Even ones considered extinct I run into quite often!

hmm i just read on a site that compares and tests anti virus progs, that avast failed…why?

Now you asking, I started on google search and expanded from their, this is where I started. http://securityresponse.symantec.com/avcenter/venc/data/w32.axon.b.html

Then here http://www.esecurityplanet.com/alerts/article.php/3351651 and the info that I posted is at the bottom of the page.
