Author Topic: [RESOLVED]- Rjump issue  (Read 38046 times)

0 Members and 1 Guest are viewing this topic.

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: Rjump issue
« Reply #45 on: June 15, 2007, 07:24:55 PM »
To quote a famous yellow skinned balding father of 2.
Who is it?

"DOH"
??? I'm not English-native... ???

NHS!
??? I'm not English-native... I'm not following you. Sorry.
The best things in life are free.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89205
  • No support PMs thanks
Re: Rjump issue
« Reply #46 on: June 15, 2007, 08:28:29 PM »
NHS!
??? I'm not English-native... I'm not following you. Sorry.

NHS = UK National Health Service.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Spyros

  • Guest
Re: Rjump issue
« Reply #47 on: June 16, 2007, 09:26:20 AM »
To quote a famous yellow skinned balding father of 2.

"DOH"
To quote a famous yellow skinned balding father of 2.
Who is it?

"DOH"
??? I'm not English-native... ???

Homer Simpson?  ;D

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: Rjump issue
« Reply #48 on: June 18, 2007, 12:12:50 AM »
NHS = UK National Health Service.
Sorry David, makes no sense for me at the original post. I still does not understand.

Homer Simpson?  ;D
Not following either ???
The best things in life are free.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89205
  • No support PMs thanks
Re: Rjump issue
« Reply #49 on: June 18, 2007, 01:28:04 AM »
It relates to the domain path which was preciously queried and a bit of a joke about the NHS in QEHNick's reference to faster, 'well not much faster' it is the NHS!, which isn't very fast.
In the UK, waiting lists to get treatment are long and waiting time in accident and emergency hours. So the comment is really only going to be understood by those in the UK.

Unfortunately you selective quote of NHS in isolation loses the context for saying NHS, so I only explained what you quoted.

Quote from: QEHNick
Websense is used at work, It does a very good job. Better than our old webfilter. Cheaper too. Anything I source these days has to fulfill those criteria. Better faster, cheaper; well not so much the faster, this is the NHS!

Quote from: mauserme
Do you recognize the domain in these lines
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = xqehkl.nhs.uk
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

QEHNick

  • Guest
Re: Rjump issue
« Reply #50 on: June 18, 2007, 09:23:49 AM »
Yes sorry for the confusing nomenclature.

And Homer simpson has 3 kids not 2, so my bad!

QEHNick

  • Guest
Re: Rjump issue
« Reply #51 on: June 18, 2007, 09:29:17 AM »
Now I might be speaking too soon but...
It appears that Ravmone.exe is now being detected "ON-ACCESS"!! :D ;D :-*

There have been at least two VPS updates this weekend, did one of them fix the issue?

Can you let us know Vik?

Nick

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: Rjump issue
« Reply #52 on: June 18, 2007, 09:28:42 PM »
Which is the virus name?
Check here: http://www.avast.com/eng/vps_history.html
The best things in life are free.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89205
  • No support PMs thanks
Re: Rjump issue
« Reply #53 on: June 18, 2007, 10:26:47 PM »
The virus name in in the previous posts, and was previously detected by avast on-demand scan but somehow failed to be detected by the on-access scanner.

This is just Nick giving feedback that it is now detected by the on-access scanner.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

QEHNick

  • Guest
Re: Rjump issue
« Reply #54 on: June 19, 2007, 09:16:57 AM »
Had a reply from Vik

Quote
Yes I think they made some changes that it is now being picked up as "Trojan-Gen" as well... The problem is quite tricky, actually. The RJump thing is actually written in Perl and the executable hosts a whole (redistributable) Perl interpreter engine. As a result, it's quite tricky to detect - and is found only during a deep scan (which is not enabled for on-access).

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89205
  • No support PMs thanks
Re: Rjump issue
« Reply #55 on: June 19, 2007, 01:12:45 PM »
Thanks for the update, very sneaky little beggar indeed. Hopefully this will have helped avast to get a handle on it now it is detected by the on-access scan as you mentioned previously.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security