
AVAST!
ANTIVIRUS.EXE PROCESS INFORMATION
Process
Name : avast!Antivirus.exe
Process
type : Trojan
Downloader
Malware
Name : TrojanDownloader.Win32.Agent.cdir
Threat
level :
Low
Process
Details
Avast!Antivirus.exe is dropped by
TrojanDownloader.Win32.Agent.cdir and it is
spammed via e-mail. It usually arrives with
attachment ecard.zip and it
contains ecard.exe.
The spammed
mail message body given below
Good day.
Your family member has sent you an ecard from 123greetings.com.
Send free ecards from 123greetings.com with your
choice of colors, words and music.
Your ecard will be available with us for the next
30 days. If you wish to keep the ecard longer,
you may save it on your c computer or take a
print.
To view your ecard, open attached zip file.
Best wishes,
Postmaster,
123greetings.com
When the infected e-mail
attachment is executed, it copies to Windows
system folder as avast!Antivirus.exe and modifies the registry
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet\Services\avast!Antivirus
to load automatically on next startup. It also
downloads serveral malicious files in the
infected system.
How can I protect my
system?
Solo has incorporated
avast!Antivirus.exe in its signature file to
protect users from this trojan attack. Solo
antivirus registered users are already protected
from this trojan. Make sure that you have
installed registered version of Solo Antivirus to
protect your system from all virus threats.
How
to remove this Trojan?
If
you are already infected with TrojanDownloader.Win32.Agent.cdir,
you can remove it from your computer using Solo
Antivirus software. Use the
following link to Download 30 day trial
version of Solo antivirus to remove
viruses from your computer.

Solo anti-virus not only
scans for all viruses, it contains a unique System
Integrity Checker to protect you from
New Internet Worms, Backdoors and
malicious VB, Java Scripts. It also
effectively removes all existing Internet Worms,
File viruses, malicious VB, Java scripts, Trojans,
Backdoors, boot sector, partition table and macro
viruses.
You can
purchase Solo antivirus using the link 

|