Recently, i come across a malware which stops avast antivirus services, after the execution of the malware.
Its an upx packed file: unpacked it and found the strings which are targeted to stop mainly avast services-
steps:
Already, Installed avast edition in windows xp environment or higher version.
Run that malware. After the restart of our system, we will find the following- avast services are stopped.
There is message we can see in the avast that system unsecured that avast antivirus program has been stopped and please restart the program.
There is option as start program in avast.
Then a process called visthaux.exe starts running in the process explorer. But that process unable to restart the avast service.
Even restarting the system and tried to start the avast process- it didn't start.
Ok, then i try to scan my system, but when i press the start scanning: it through the message as unable to start scan-
Only thing Avast need to do- is to detect that malware. Today it detects the malware (prevention is better than cure).
Regards,