Author Topic: avast blind  (Read 6671 times)

0 Members and 1 Guest are viewing this topic.

mantra

  • Guest
avast blind
« on: February 05, 2004, 12:58:30 PM »
hi folks!

i post a file , it's not a virus but avast detect like a trojan
« Last Edit: February 05, 2004, 01:29:04 PM by igor »

Offline igor

  • Avast team
  • Serious Graphoman
  • *
  • Posts: 11873
    • AVAST Software
Re:avast blind
« Reply #1 on: February 05, 2004, 01:49:20 PM »
Please, don't do this. Attaching files that avast! announces as infected is really not a good idea!

I don't know what makes you think that the file is clean. The file, though named .exe.jpg, is an executable file in fact. When started, it checks for a presence of a known AdWare (TMKSoft XPlugin), tries to download a file from a strange IP address, write it to system directory and start it (including possible planning to be started on next restart).
It really doesn't look like an innocent piece of code.

mantra

  • Guest
Re:avast blind
« Reply #2 on: February 05, 2004, 02:36:12 PM »
ops
sorry
i will never post files.. sorry

i tested this with kaspersky ,nod32 drweb and norton
every avs told me is ok!

mantra

  • Guest
Re:avast blind
« Reply #3 on: February 05, 2004, 02:44:50 PM »
i'm really sorry
where can i find how remove reg entry!

i started it (this trojan)

Offline raman

  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 1062
Re:avast blind
« Reply #4 on: February 05, 2004, 03:17:15 PM »
What is the name of that filem, where did you find it and what name does Avast give that "trojan"?

Or post a Hijackthis log: http://216.180.233.153/~merijn/files/HijackThis.exe
http://mjc1.com/mirror/hjt/
« Last Edit: February 05, 2004, 03:20:19 PM by raman »
MfG Ralf

Offline igor

  • Avast team
  • Serious Graphoman
  • *
  • Posts: 11873
    • AVAST Software
Re:avast blind
« Reply #5 on: February 05, 2004, 03:25:34 PM »
avast! detects it as Win32:Esednldr-B [Trj].
In my opinion, if it doesn't find the adware installed (HKLM\Software\TMKSoft\XPlugin), it doesn't do anything.

Offline raman

  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 1062
Re:avast blind
« Reply #6 on: February 05, 2004, 03:36:44 PM »
Who knows if it was installed on mantras pc or not? :)

@mantra:

if you want you can study this Link:
http://www.trendmicro.com/vinfo/virusencyclo/default2.asp?m=q&virus=TROJ_ESEPOR.A
 
MfG Ralf

whocares

  • Guest
Re:avast blind
« Reply #7 on: February 05, 2004, 03:43:29 PM »
Hi,
Mantra's sample was rather this Malware:
TROJ_ESEPOR.C ;)

mantra

  • Guest
Re:avast blind
« Reply #8 on: February 05, 2004, 04:26:00 PM »
thanks mates