Author Topic: doesn't Avast detect win32/mebroot.h trojan?  (Read 6336 times)

0 Members and 1 Guest are viewing this topic.

meck

  • Guest
doesn't Avast detect win32/mebroot.h trojan?
« on: July 15, 2008, 09:37:11 AM »
Can anybody explain if this is a false alarm?

http://www.virustotal.com/en/analisis/223a5f1a6ff39449f1095aebb695c0b7

That file i have had to copy from mbr:

---- Disk sectors - GMER 1.0.14 ----

Disk            \Device\Harddisk0\DR0        sector 61: malicious code @ sector 0x12a14c00 size 0x194

Thanks \o


I opened a Post in: http://forum.avast.com/index.php?topic=36981.0 where i have tried also to get a solution.
« Last Edit: July 16, 2008, 04:13:43 PM by meck »

sopadeajo

  • Guest
Re: doesn't Avast detect win32/mebroot.h trojan?
« Reply #1 on: July 15, 2008, 06:41:43 PM »
With a 30% detection rate i would consider the possibility of not a false positive.

http://www.daboweb.com/foros/index.php?topic=31030.0

and here is an online translation to english (hope it is good enough), in case it is necessary (hope it is not).

http://209.85.171.104/translate_c?hl=es&langpair=es|en&u=http://www.daboweb.com/foros/index.php%3Ftopic%3D31030.0&usg=ALkJrhixQ8jaTKyPVZUBLoGRvVHzzKIT1Q
« Last Edit: July 15, 2008, 07:05:59 PM by sopadeajo »

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89161
  • No support PMs thanks
Re: doesn't Avast detect win32/mebroot.h trojan?
« Reply #2 on: July 15, 2008, 09:41:47 PM »
I certainly wouldn't base a decision on if it is an FP on only 30% detected something, it is a little more complex than that.

With 4 of the 10 detections being heuristic or generic, leaving 6 detected by signature so it is certainly suspect and I would suggest it should be sent to avast for analysis, see below.

Are you getting any strange symptoms , e.g. what made you do an anti-rootkit scan ?

Send the sample to virus@avast.com zipped and password protected with the password in email body, a link to this topic might help and possible undetected malware in the subject.

Or you can also add the file to the User Files (File, Add) section of the avast chest (if it isn't already there) where it can do no harm and send it from there (select the file, right click, email to Alwil Software). No need to zip and PW protect when the sample is sent from chest. A copy of the file/s will remain in the original location, so any further action you take can remove that.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

wyrmrider

  • Guest
Re: doesn't Avast detect win32/mebroot.h trojan?
« Reply #3 on: July 16, 2008, 05:17:54 AM »
meck- did you post a link to your other thread in the Avast home/pro forum
do follow up on this

meck

  • Guest
Re: doesn't Avast detect win32/mebroot.h trojan?
« Reply #4 on: July 16, 2008, 03:53:41 PM »
meck- did you post a link to your other thread in the Avast home/pro forum
do follow up on this

i just do it. \o

meck

  • Guest
Re: doesn't Avast detect win32/mebroot.h trojan?
« Reply #5 on: July 22, 2008, 05:29:28 PM »
I certainly wouldn't base a decision on if it is an FP on only 30% detected something, it is a little more complex than that.

With 4 of the 10 detections being heuristic or generic, leaving 6 detected by signature so it is certainly suspect and I would suggest it should be sent to avast for analysis, see below.

Are you getting any strange symptoms , e.g. what made you do an anti-rootkit scan ?

Send the sample to virus@avast.com zipped and password protected with the password in email body, a link to this topic might help and possible undetected malware in the subject.

Or you can also add the file to the User Files (File, Add) section of the avast chest (if it isn't already there) where it can do no harm and send it from there (select the file, right click, email to Alwil Software). No need to zip and PW protect when the sample is sent from chest. A copy of the file/s will remain in the original location, so any further action you take can remove that.

Hi, I did it but i haven't received notification.

thanks \o

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: doesn't Avast detect win32/mebroot.h trojan?
« Reply #6 on: July 22, 2008, 05:33:04 PM »
Hi, I did it but i haven't received notification.
They usually do not send it, I mean, there isn't an automated system (robot) to answer.
They usually answer by correcting the detection in the virus database.
The best things in life are free.