Wir sind hier um Ihnen zu helfen

Dialog boxes - ideas and suggestions

Kommentare

3 Kommentare

  • Avatar
    Mark Manning

    Just wanted to add - the first item says TR/Crypt_XPACKG.... on C:\DOS\groff\bin\soelim.exe.

     

    This is a DOS program which I've had for years yet - now it has a Trojan on/in it? This is a part of the groff (unix-for-windows) package and has been around for years.

    0
  • Avatar
    Customer Service

    Hello mark.

     

    Thank you for your Feedback about the Files in quarantine dialog box.

    We will give this feedback to the regarding department for a further reviewing of that to change something in the future.

    For the other problem it seems your system is infected if you said you had nothing and now 163.

    You can read more about the TR/Crypt-XPACKG here (In english):

    https://support.avira.com/hc/en-us/articles/360000293278-Welche-Ma%C3%9Fnahmen-kann-ich-gegen-MBR-Ransomware-TR-Crypt-XPACK-Gen-ergreifen-

     

    I recommend to do a Full Scan with our Antivirus Software and check what messages you get from that.

     

    Best,

    Felix Bär

    Avira Customer Service Engineer

    0
  • Avatar
    Mark Manning

    Ok. Let's assume a program I have had for over ten years and as far as my backups go (I keep a five year backup) has exactly the same program - now - has a trojan. So does that mean the trojan has been there for over five years or more or maybe just came that way?

    That was my first question. The second question is - how come Avira (or any other anti-virus program) does not FIX the problem rather than just "Let's just throw this program away"? As a programmer myself, in assembly, it would be very easy to just insert NO-OP (or NOP or NOOP or whatever you want to call it) commands into the code where the trojan is located with a single RET at the end. So the trojan basically gets replaced with a do-nothing (or No Operation) set of commands with a single return (RET) at the end. In this way, anything that triggers the trojan gets nothing back at all.

    Just wondering because there are databases out there with the EXACT code for the virus. I mean, after all, you have to have that just to find the virus. So why not wipe out the virus and leave the program?

    0

Bitte melden Sie sich an, um einen Kommentar zu hinterlassen.