Author Topic: Backdoor.Win32.VB.boa  (Read 3414 times)

0 Members and 2 Guests are viewing this topic.

neogrey

  • Guest
Backdoor.Win32.VB.boa
« on: November 11, 2007, 05:49:46 PM »
I'm using Avast Home Edition...and it obviously skipped that one: Backdoor.Win32.VB.boa . Thank God, I have a firewall too, which reported that lsass.exe is trying to connect to the internet. the worm has been placed in C:/WINDOWS/Config/ directory - not a place for lsass.exe. I scanned the file with Kaspresky online scanner which told me that the file is a worm...is it what we get for FREE from Alwil Software - is it supposed to pass those viruses???

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67183
Re: Backdoor.Win32.VB.boa
« Reply #1 on: November 11, 2007, 05:51:28 PM »
The problem is not that avast is free or not, but that every software is not perfect and can miss some detections.
Can you send the samples to virus@avast.com ?
You can zip and password the files... Inform a link to this thread and the password used.
You can send the files to Chest and, from there, resend to Alwil for analysis.
Thanks for helping avast to improve detection.
The best things in life are free.

neogrey

  • Guest
Re: Backdoor.Win32.VB.boa
« Reply #2 on: November 11, 2007, 06:02:05 PM »
Sorry, I already trashed the file ...booted in Safe Mode and renamed it, then on the next restart I trashed it...it was stupid of me, I should be sending this to you, indeed. Sorry.

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67183
Re: Backdoor.Win32.VB.boa
« Reply #3 on: November 11, 2007, 06:24:25 PM »
Sorry, I already trashed the file ...booted in Safe Mode and renamed it, then on the next restart I trashed it...it was stupid of me, I should be sending this to you, indeed. Sorry.
Never mind. Next time you already know.
Welcome to avast forums. Feel free to come back any time you need help you just to change experiences 8)
The best things in life are free.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34054
  • malware fighter
Re: Backdoor.Win32.VB.boa
« Reply #4 on: November 12, 2007, 04:10:22 PM »
Hi Tech,

Here is the description for our forum members:
Trojan.Win32.Agent.boa
Type   Malware
Type Description   Malware ("malicious software") consists of software with clearly malicious, hostile, or harmful functionality or behavior and that is used to compromise and endanger individual PCs as well as entire networks.
Category   Trojan
Category Description   Trojan is a general term for malicious software that is installed under false or deceptive pretenses or is installed without the user's full knowledge and consent. Most Trojans exhibit some form of malicious, hostile, or harmful functionality or behavior.
Level   High
Level Description   High risks are typically installed without user interaction through security exploits, and can severely compromise system security. Such risks may open illicit network connections, use polymorphic tactics to self-mutate, disable security software, modify system files, and install additional malware. These risks may also collect and transmit personally identifiable information (PII) without your consent and severely degrade the performance and stability of your computer.
Advice Type   Remove
Release Date   Sep 21 2007
Last updated on   Sep 21 2007
File Traces   
    ie.exe
COMODO BoClean protects against this trojan boa

polonus
« Last Edit: November 12, 2007, 04:18:14 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!