Author Topic: Avast! still can't Detect it  (Read 4136 times)

0 Members and 1 Guest are viewing this topic.

Esecurity

  • Guest
Avast! still can't Detect it
« on: March 10, 2008, 12:03:39 PM »
HI

i got a backdoor server in my flash memory

when i am scanning it it says file clean but in other computers Avira , Kaspersky Says it's

Backdoor.Win32.Agent.fjn

i did online scan but avast! still can't Detect it and i have sent it to Submission via email still can't Detect in for 3 days ago.

how can avast! Detect it?

Esecurity

  • Guest
Re: Avast! still can't Detect it
« Reply #1 on: March 10, 2008, 01:33:00 PM »
any body here?

Esecurity

  • Guest
Re: Avast! still can't Detect it
« Reply #2 on: March 10, 2008, 02:09:54 PM »
any virus researcher of avast here , can help me! :(

junax

  • Guest
Re: Avast! still can't Detect it
« Reply #3 on: March 10, 2008, 02:20:19 PM »
[why not to try AVG anti virus?

Offline Maxx_original

  • Moderator
  • Super Poster
  • *
  • Posts: 1479
Re: Avast! still can't Detect it
« Reply #4 on: March 10, 2008, 02:34:58 PM »
send the file to virus[at]avast[dot]com with a short description.. ;)

Esecurity

  • Guest
Re: Avast! still can't Detect it
« Reply #5 on: March 10, 2008, 02:40:48 PM »
thank you sir

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34029
  • malware fighter
Re: Avast! still can't Detect it
« Reply #6 on: March 10, 2008, 05:54:51 PM »
Hi Esecurity,

Let us try and cleanse it.

      Download Trend Micro Hijack This from  http://download.bleepingcomputer.com/hijackthis/HJTInstall.exe
      Doubleclick on HJTInstall.exe
      Hijackthis is being installed onto your PC, an icon is being placed onto the desktop.

      HijackThis will open after installation.
      Click on "Do a systemscan and save a logfile".
      A Notepad window will open, press the  CTRL and  A key toets at a time, all is being selected.
      Then push both CTRL and C key at a time, all is being copied.

      Log into the virus and worms section of this forum and look for "reply"
      Now attach the HJT logfile through CTRL-V
      In your case we have to rename hijackthis as follows:

Rename HijackThis.exe to pol.exe by doing the following;

    * Navigate here using Windows Explorer (windows button + E) or My Computer -> Local Disk C: -> C:\Program Files\Trend Micro\HijackThis
    * Right-click on the HijackThis.exe
    * Choose from the pull-down menu; "Rename"
    * And now Rename HijackThis.exe to pol.exe
    * When you've renamed HijackThis, open HijackThis again.
    * Take a fresh HijackThis log (click Do a system scan and save a log file)
    * Post the fresh HijackThis log here.

__________________
1. Download combofix from one of this links and save it to Desktop:
http://download.bleepingcomputer.com/sUBs/ComboFix.exe
2. Double click combofix.exe & follow the prompts.
3. When finished, it shall produce a log for you. Post that log in your next reply

Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall

Combofix should never take more that 20 minutes including the reboot if malware is detected.
If it does, open Task Manager then Processes tab (press ctrl, alt and del at the same time) and end any processes of findstr, find, sed or swreg, then combofix should continue.
If that happened we want to know, and also what process you had to end.

Post as Attachments:

- a fresh HijackThis log
- combofix report
__________________

pol
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Esecurity

  • Guest
Re: Avast! still can't Detect it
« Reply #7 on: March 11, 2008, 10:18:30 AM »
my system is clean

I just want to send the sample to Avast! Lab till it can be detected later,

also I have sent it to virus(@)Avast(.)com it for 3 days ago & it seems submission via email doesn't work

so i need any virus researcher email to send it to Directly. 8)

ThanX

Offline Maxx_original

  • Moderator
  • Super Poster
  • *
  • Posts: 1479
Re: Avast! still can't Detect it
« Reply #8 on: March 11, 2008, 11:50:48 AM »
the submission works of course.. but we don't use an auto-responder... the detection will be added to VPS ;)