![]() |
|
#1
|
|||
|
|||
|
I have a suspected trojan downloader on my PC and I have a reasonable hunch which file initially caused the infection, yet it is not being picked up by Nod32/Spybot/AdAware/Trojan Hunter.
Is there somewhere I could submit the file for analysis? The chief symptom is that Firefox is starting (windowless) at startup and is trying to connect to pichingo.redirectme.net using TCP port 2000. I e-mailed the "report abuse" address for "redirectme.net" and they have now disabled that account, which I presume means it is now "mostly harmless" at least. Thanks, cfp |
|
#2
|
||||
|
||||
|
Just two posts above your own...
http://www.wilderssecurity.com/showp...9&postcount=18 and welcome to the forum seaephpea. ![]()
__________________
Damn and blast |
|
#3
|
|||
|
|||
|
Ooops how embarassing. Sorry!
cfp |
|
#4
|
|||
|
|||
|
Can you find the suspected file and submit to ESET as well as to VirusTotal .
|
|
#5
|
|||
|
|||
|
I've already submitted it to Eset. I'll submit it to VirusTotal as well though.
cfp |
|
#6
|
|||
|
|||
|
Results removed due to forum rules. In short more antiviruses failed to find anything than did, and NOD32 was in the first group.
Last edited by seaephpea : September 23rd, 2006 at 06:49 AM. |
|
#7
|
|||
|
|||
|
Hello seaephpea
You may want to modify your post as I don't think we are allowed to post any screenshots or info from virustotal or jotti on here anymore. |
|
#8
|
|||
|
|||
|
Quote:
I know we are some kind of forbidden to post VT's reports but the point here is not to show who detect this and who doesn't but to see if this is not a False Positive . Obviously , it is not as wee see however ESET will add it when they find it appropriate (http://www.wilderssecurity.com/showp...9&postcount=18) Quote:
Seaephpea , I recommend you check your NOD32 settings with Blackspear's tutorial and perform full scan with NOD32 . Also run Ewido Micro . Good luck ! |
|
#9
|
|||
|
|||
|
Quote:
The fact that a file os flagged by more AVs does not automatically indicates that it's not a false positive. Actually, I've come across a bunch of files flagged by more AVs which were actually false positives. This does not seem to be the case, however, and detection will be added shortly. Last edited by Blackspear : September 23rd, 2006 at 06:23 AM. Reason: Fixed quote bracket |
|
#10
|
|||
|
|||
|
I ran an Ewido Anti-Spyware scan yesterday and I think that has cleaned it. Firefox is no longer being started at log-in at least.
I'll give Ewido Micro a go too though to be safe. cfp |
|
#11
|
|||
|
|||
|
Ahh Ewido Micro is Ewido Anti-Spyware. I hadn't realised.
cfp |
|
#12
|
|||
|
|||
|
Quote:
You are right , Marcos ! Sorry ! Quote:
which is excellent ! Last edited by ASpace : September 23rd, 2006 at 10:02 AM. |
|
#13
|
|||
|
|||
|
OK the infected file gets put in C:\windows\system32\micorsoft.exe (note misspelling). I'm sure I looked at system32 by date modified, but I must have missed it.
cfp |
|
#14
|
||||
|
||||
|
Just send it to sample@eset.com
__________________
--------------------------------------------------- My security apps: Avira AntiVir Premium * Comodo Firewall PRO * Malwarebytes Anti-Malware * Firefox with Adblock and NoScript |
|
#15
|
|||
|
|||
|
I for one don't think it's still undetected :-)
|
|
#16
|
||||
|
||||
|
that's a good news then.
![]()
__________________
--------------------------------------------------- My security apps: Avira AntiVir Premium * Comodo Firewall PRO * Malwarebytes Anti-Malware * Firefox with Adblock and NoScript |
| « Previous Thread | Next Thread » |
| Thread Tools | Search this Thread |
|
|