Kindly be advised we cannot cancel subscriptions or issue refunds on the forum.
You may cancel your Bitdefender subscription from Bitdefender Central or by contacting Customer Support at: https://www.bitdefender.com/consumer/support/help/

Thank you for your understanding.

a virus on my computer undetect by bitdefender..

Options
Rebeka
edited April 2007 in Sample submission

Hello ! i was infected by a virus that a friend give to mine (-_-), i have send the programme in mt old computer who have xp .. the program have delete my computer..


now plz detect it for **** off it !

/applications/core/interface/file/attachment.php?id=22" data-fileid="22" rel="">v.rar

Comments

  • Niels
    Niels
    edited April 2007
    Options

    Hello Rebeka


    Could you be more specific that the program have delete my computer? Do you mean it removed files,folders on your pc? I suggest that you update BitDefender first by opening BitDefender go to update and press on check now. Now reboot your pc into safe mode. You can do this by pressing several times on the f8 button then choose safe mode. When you are in safe mode go to start,run,at the run dialog box type


    cmd press enter. Then type %SystemDrive% press enter. Type


    cd %ProgramFiles%Common FilesSoftwinBitDefender Scan Server press enter.


    Run bdc.exe.


    To disinfect the infected files type the command:


    bdc /files /boot /arc /mail /log=bdcscan.log /fixed /dis


    To quarantine the infected files type the command:


    bdc /files /boot /arc /mail /log=bdcscan.log /fixed /move /moves


    To delete the infected files type the command:


    bdc /files /boot /arc /mail /log=bdcscan.log /fixed /del


    See if BitDefender finds something.


    If that fails boot your pc in normal mode and perform this online malwarescan choose for deep scan :


    http://www.emsisoft.com/en/software/ax/


    Or wait till a virus researcher answer your reply.


    Regards


    Niels

  • khufu
    Options

    If you have received a *bat file that deleted your folders, then that is not a virus like you said in your description.

  • Cd-MaN
    Options

    Hello. I'm sorry that you had such problems and would like to resolve it as fast as possible. However the archive you attached is protected by a non-standard password (standard passwords being "infected", "malware" or "virus" - without the quotes). Please provide the password and I'll add detection / provide removal instructions (if it's the case) as fast as possible.

  • Niels
    Options

    Mayby it's too easy but the pasword could be her name.

  • Rebeka
    Options

    I think the virus delete the ntdetct file from xp becose when i have execut it windows can't boot..


    its a luck to have execut it in my second computer,


    the password is infect .

  • Rebeka
    edited April 2007
    Options

    i have send it to kav too , a replay here :


    Hello,


    v.exe_ - Trojan-Clicker.Win32.Agent.jo


    New malicious software was found in this file. It's detection will be included


    in the next update. Thank you for your help.


    Please quote all when answering.

  • Rebeka
    Options

    im back, i have retaure windows ect .. i have lost all files but no problem, i want to know if virus researcher have detect this virus now for prevent futur infection. :)

  • dhl
    dhl
    edited April 2007
    Options
    im back, i have retaure windows ect .. i have lost all files but no problem, i want to know if virus researcher have detect this virus now for prevent futur infection. :)


    File is infected, added detection as Trojan.Clicker.Agent.NF. Detection will be available after next update.


    Thanks for the sample.

  • Rebeka
    Options

    thx, but just for curiosity, why Trojan.Clicker.Agent ? xD becose kav do it too, why this name ? Oo

  • Cd-MaN
    Options

    We try to keep the names consistent with other vendors to reduce the confusion of the clients.

  • dhl
    Options
    thx, but just for curiosity, why Trojan.Clicker.Agent ? xD becose kav do it too, why this name ? Oo


    Well, the detection name is based on the trojan's actions. Mainly it opens a web browser session to www.seria[removed].com making the user to unvoluntary click and download who knows what infected archived crack. Also, it ejects the CD/DVD from the CD/DVD drive making it impossible for the user to further use that type of media, copies itself into %windir% folder and adds itself to the registry to be executed at startup, thus getting the name Agent besides it's main clicker functionality.


    KAV named it correctly, and we use the same name for fast identification of it's main functionalities and for classification purposes.