Wilders Security Forums  

Go Back   Wilders Security Forums > Archived Forums > Closed Sub-Forums > Archived ESET Support Forums > NOD32 version 2 Forum
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old September 22nd, 2006, 07:25 AM
seaephpea seaephpea is offline
Infrequent Poster
 
Join Date: Sep 2006
Posts: 8
Default Reporting suspected new trojan

I have a suspected trojan downloader on my PC and I have a reasonable hunch which file initially caused the infection, yet it is not being picked up by Nod32/Spybot/AdAware/Trojan Hunter.

Is there somewhere I could submit the file for analysis?

The chief symptom is that Firefox is starting (windowless) at startup and is trying to connect to pichingo.redirectme.net using TCP port 2000.

I e-mailed the "report abuse" address for "redirectme.net" and they have now disabled that account, which I presume means it is now "mostly harmless" at least.

Thanks,

cfp
  #2  
Old September 22nd, 2006, 08:10 AM
Joliet Jake's Avatar
Joliet Jake Joliet Jake is offline
Frequent Poster
 
Join Date: Mar 2005
Location: Scotland
Posts: 911
Default Re: Reporting suspected new trojan

Just two posts above your own...

http://www.wilderssecurity.com/showp...9&postcount=18

and welcome to the forum seaephpea.
__________________
Damn and blast
  #3  
Old September 22nd, 2006, 08:30 AM
seaephpea seaephpea is offline
Infrequent Poster
 
Join Date: Sep 2006
Posts: 8
Default Re: Reporting suspected new trojan

Ooops how embarassing. Sorry!

cfp
  #4  
Old September 22nd, 2006, 11:06 AM
ASpace
 
Posts: n/a
Default Re: Reporting suspected new trojan

Can you find the suspected file and submit to ESET as well as to VirusTotal .
  #5  
Old September 22nd, 2006, 03:15 PM
seaephpea seaephpea is offline
Infrequent Poster
 
Join Date: Sep 2006
Posts: 8
Default Re: Reporting suspected new trojan

I've already submitted it to Eset. I'll submit it to VirusTotal as well though.

cfp
  #6  
Old September 22nd, 2006, 03:23 PM
seaephpea seaephpea is offline
Infrequent Poster
 
Join Date: Sep 2006
Posts: 8
Default Re: Reporting suspected new trojan

Results removed due to forum rules. In short more antiviruses failed to find anything than did, and NOD32 was in the first group.

Last edited by seaephpea : September 23rd, 2006 at 06:49 AM.
  #7  
Old September 23rd, 2006, 05:17 AM
Londonbeat Londonbeat is offline
Frequent Poster
 
Join Date: Sep 2006
Posts: 348
Default Re: Reporting suspected new trojan

Hello seaephpea

You may want to modify your post as I don't think we are allowed to post any screenshots or info from virustotal or jotti on here anymore.
  #8  
Old September 23rd, 2006, 05:54 AM
ASpace
 
Posts: n/a
Default Re: Reporting suspected new trojan

Quote:
Originally Posted by Londonbeat
Hello seaephpea

You may want to modify your post as I don't think we are allowed to post any screenshots or info from virustotal or jotti on here anymore.

I know we are some kind of forbidden to post VT's reports but the point here is not to show who detect this and who doesn't but to see if this is not a False Positive . Obviously , it is not as wee see however ESET will add it when they find it appropriate (http://www.wilderssecurity.com/showp...9&postcount=18)

Quote:
Originally Posted by seaephpea
I've already submitted it to Eset.
Thank you !

Seaephpea , I recommend you check your NOD32 settings with Blackspear's tutorial and perform full scan with NOD32 . Also run Ewido Micro .

Good luck !
  #9  
Old September 23rd, 2006, 06:08 AM
Marcos Marcos is online now
Eset Moderator
 
Join Date: Nov 2002
Posts: 14,193
Default Re: Reporting suspected new trojan

Quote:
Originally Posted by HiTech_boy
...but to see if this is not a False Positive . Obviously , it is not...

The fact that a file os flagged by more AVs does not automatically indicates that it's not a false positive. Actually, I've come across a bunch of files flagged by more AVs which were actually false positives. This does not seem to be the case, however, and detection will be added shortly.

Last edited by Blackspear : September 23rd, 2006 at 06:23 AM. Reason: Fixed quote bracket
  #10  
Old September 23rd, 2006, 06:55 AM
seaephpea seaephpea is offline
Infrequent Poster
 
Join Date: Sep 2006
Posts: 8
Default Re: Reporting suspected new trojan

I ran an Ewido Anti-Spyware scan yesterday and I think that has cleaned it. Firefox is no longer being started at log-in at least.

I'll give Ewido Micro a go too though to be safe.

cfp
  #11  
Old September 23rd, 2006, 07:11 AM
seaephpea seaephpea is offline
Infrequent Poster
 
Join Date: Sep 2006
Posts: 8
Default Re: Reporting suspected new trojan

Ahh Ewido Micro is Ewido Anti-Spyware. I hadn't realised.

cfp
  #12  
Old September 23rd, 2006, 09:41 AM
ASpace
 
Posts: n/a
Default Re: Reporting suspected new trojan

Quote:
Originally Posted by Marcos
The fact that a file os flagged by more AVs does not automatically indicates that it's not a false positive. Actually, I've come across a bunch of files flagged by more AVs which were actually false positives.

You are right , Marcos ! Sorry !



Quote:
Originally Posted by Marcos
, however, and detection will be added shortly
,
which is excellent !


Last edited by ASpace : September 23rd, 2006 at 10:02 AM.
  #13  
Old September 23rd, 2006, 11:22 AM
seaephpea seaephpea is offline
Infrequent Poster
 
Join Date: Sep 2006
Posts: 8
Default Re: Reporting suspected new trojan

OK the infected file gets put in C:\windows\system32\micorsoft.exe (note misspelling). I'm sure I looked at system32 by date modified, but I must have missed it.

cfp
  #14  
Old September 24th, 2006, 06:37 AM
pykko's Avatar
pykko pykko is offline
Very Frequent Poster
 
Join Date: Apr 2005
Location: Romania...and walking to heaven
Posts: 2,231
Default Re: Reporting suspected new trojan

Just send it to sample@eset.com
__________________

---------------------------------------------------
My security apps: Avira AntiVir Premium * Comodo Firewall PRO * Malwarebytes Anti-Malware * Firefox with Adblock and NoScript
  #15  
Old September 24th, 2006, 06:48 AM
Marcos Marcos is online now
Eset Moderator
 
Join Date: Nov 2002
Posts: 14,193
Default Re: Reporting suspected new trojan

I for one don't think it's still undetected :-)
  #16  
Old September 24th, 2006, 08:00 AM
pykko's Avatar
pykko pykko is offline
Very Frequent Poster
 
Join Date: Apr 2005
Location: Romania...and walking to heaven
Posts: 2,231
Default Re: Reporting suspected new trojan

that's a good news then.
__________________

---------------------------------------------------
My security apps: Avira AntiVir Premium * Comodo Firewall PRO * Malwarebytes Anti-Malware * Firefox with Adblock and NoScript
 

Wilders Security Forums > Archived Forums > Closed Sub-Forums > Archived ESET Support Forums > NOD32 version 2 Forum « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 05:05 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums