Author Topic: w32.dumaru.ab help URGENT  (Read 4568 times)

0 Members and 1 Guest are viewing this topic.

sanctuary24

  • Guest
w32.dumaru.ab help URGENT
« on: November 07, 2007, 09:38:32 PM »
My firewall blocked an attempt on port 10000 saying that it could be w32.dumaru.ab so I went to check it out at symantec.co.uk and the explanation page was infected with it as Avast warned me to abort connection whats going on? Is symantecs website infected or something?????
« Last Edit: November 08, 2007, 12:01:41 AM by sanctuary24 »

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: w32.dumaru.ad help URGENT
« Reply #1 on: November 07, 2007, 10:01:38 PM »
Seems a false positive...
The best things in life are free.

sanctuary24

  • Guest
Re: w32.dumaru.ad help URGENT
« Reply #2 on: November 07, 2007, 10:04:22 PM »
www.symantec.com/security_response/ writeup.jsp?docid=2004-020314-4015-99 this is the exact web address DONT CLICK can someone check this specific page with a scanner please (I have put a space in it so it wont be accidenttly clicked the space should be removed after security_response/

how do I get Avast to ckeck if its a false positive
« Last Edit: November 07, 2007, 10:07:36 PM by sanctuary24 »

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: w32.dumaru.ad help URGENT
« Reply #3 on: November 07, 2007, 10:10:35 PM »
I turned back clean with Dr. Web again...
The best things in life are free.

sanctuary24

  • Guest
Re: w32.dumaru.ad help URGENT
« Reply #4 on: November 07, 2007, 10:13:02 PM »
Can someone from the Alwil team please look into this as my Firewall picked up an attack on port 10000 which is what this virus uses.

How do I get someone from Alwil to check this out, do I e-mail them?

ps how do you get that dr web to work when I try it says busy, file too big etc
« Last Edit: November 07, 2007, 10:19:34 PM by sanctuary24 »

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89029
  • No support PMs thanks
Re: w32.dumaru.ad help URGENT
« Reply #5 on: November 07, 2007, 10:29:43 PM »
Did your firewall not go to the length of saying what file name it was that was trying to connect ?

It may be a false positive on the symantec site, but you would have to chesk the detection by the firewal outbound check.

It is possible there is some information about the infection that matches an avast signature but that is speculation.

the actual writeup.jsp proved clean when downloaded and scanned by avast, VT shows 0/32 on writeup.jsp.

DrWeb shows clean on the URL link for Technical Details tab which is what avast is alerting on.

I have sent a FP email so we will have to see if they pick it up.
« Last Edit: November 07, 2007, 10:32:46 PM by DavidR »
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89029
  • No support PMs thanks
Re: w32.dumaru.ad help URGENT
« Reply #6 on: November 08, 2007, 12:03:51 AM »
Hi guys,

Just got a response and this FP is sorted.

Quote
Hello,
this false alarm was repaired by VPS update 071107-7
Best regards Cernik

I assume the -7 is a typo as the latest VPS is 071107-0 as this VPS update corrects the FP, having just visited the Technical Details tab and no alarm.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

sanctuary24

  • Guest
Re: w32.dumaru.ab help URGENT
« Reply #7 on: November 08, 2007, 02:24:14 PM »
so it was a false positive, if that the case I rest easy
one other thing how come my firewall blocked the port that this virus uses yet at another time it was appearing like a virus got through, is it something like it piggybacked a ride on a file and the other time it tried to force itself in?
« Last Edit: November 08, 2007, 02:29:17 PM by sanctuary24 »

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89029
  • No support PMs thanks
Re: w32.dumaru.ab help URGENT
« Reply #8 on: November 08, 2007, 02:37:28 PM »
You will have to check your firewall logs for that, but what was detected by the web shield will have been using port 80 and not 10,000 (no indication if that was a local or external port) that element if present wouldn't have been intercepted by the web shield.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security