Author Topic: Backdoor Trojan not detectedn by Avast!  (Read 8577 times)

0 Members and 1 Guest are viewing this topic.

TrenchFOOT

  • Guest
Backdoor Trojan not detectedn by Avast!
« on: June 03, 2009, 11:27:21 PM »
I am a big fan of Avast! It's been very efficient ever since I first used it, but recently it failed me.
I noticed my Firewall (Comodo) logging suspicious behavior:
Explorer.exe was constantly trying to connect to the Internet, with an attempt every second. The external port Explorer.exe was trying to connect to was incremented with every attempt. When I first noticed it, the external port was 1346, which incremented after every attempt. The IP remained constant: 38.97.225.166.
Why would Explorer.exe constantly be trying to connect to 38.97.225.166? I thought. It could only be malicious.
I further noticed that every time I plugged a USB drive into my PC (Windows XP SP2), I new autorun.inf was created, together with a hidden folder called "Driver". This "Driver" folder contained a "Files" folder which resembled the Recycle Bin. This folder was empty, yet when I viewed its properties, it listed 2 files. I promptly deleted the autorun.inf and Driver folder, which was promptly recreated 2 seconds later. I scanned the USB drive, to no avail.
I did a complete boot-time scan of my PC, which came up clear. Avast! could find no threat.
I got Kaspersky Internet Security 2009. Needless to say I had to uninstall Avast! when I installed Kaspersky. When I scanned the USB drive with KIS it found a Trojan known as Backdoor.Win32.VB.iqo.
On Threatexpert.com it is described as:
A malicious backdoor Trojan that runs in the background and allows remote access to the compromised system:
http://www.threatexpert.com/report.aspx?md5=2adcaf95e8bda37bbb92e8e5f43e99bd
A malicious Trojan horse or bot that may represent security risk for the compromised system and/or its network environment:
http://www.threatexpert.com/report.aspx?md5=bcbd8ec75e1f60cf73415c4dbf8af1d6

McAfee also has some info:
http://vil.nai.com/vil/content/v_156344.htm

Why did Avast! not detect this Trojan.
I am writing this post just to inform those who can do something about this, so that Avast! users can be safe.

Kapersky Report (Not exhaustive):
C Drive:
  • 2009/06/01 03:27:48 PM   Detected: Backdoor.Win32.VB.iqo   File   C:\driver\files\   dt.exe
  • 2009/06/01 03:28:01 PM   Deleted: Backdoor.Win32.VB.iqo   File   HKLM\Software\Microsoft\Active Setup\Installed Components\{67KLN5J0-4OPM-01WE-AAX5-314CCA322142}\   {67KLN5J0-4OPM-01WE-AAX5-314CCA322142}
  • 2009/06/01 03:28:21 PM   Deleted: Backdoor.Win32.VB.iqo   File   C:\driver\files\   dt.exe
  • 2009/06/01 05:17:15 PM   Detected: Backdoor.Win32.VB.iqo   File   C:\System Volume Information\_restore{7A9E6E3C-536F-4108-AA0D-0A202ECEBB41}\RP134\   A0157323.exe

USB Drive:
  • 2009/06/03 08:02:13 PM   Deleted: Backdoor.Win32.VB.iqo   File   F:\Driver\Files\   DT.exe
  • 2009/06/03 08:02:13 PM   Deleted: Backdoor.Win32.VB.iqo   File   F:\Driver\Files\   DT.exe

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89675
  • No support PMs thanks
Re: Backdoor Trojan not detectedn by Avast!
« Reply #1 on: June 04, 2009, 12:00:04 AM »
No one program is going to catch 100% of all malware, which is why protection in depth as advisable, and your firewall is part of that to block unauthorised outbound connections. I block all connections for explorer.exe even though you can technically type a URL in the windows explorer address bar.

Send the sample to virus@avast.com zipped and password protected with the password in email body, a link to this topic might help and undetected malware in the subject.
 
Or you can also add the file to the User Files (File, Add) section of the avast chest (if it isn't already there) where it can do no harm and send it from there. A copy of the file/s will remain in the original location, so you will need to take further action and can remove/rename that.
 
Send it from the User Files section of the chest (select the file, right click, email to Alwil Software). It will be uploaded (not actually emailed) to avast when the next avast auto (or manual) update is done.

If you haven't already got this software (freeware), download, install, update and periodically run them.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD - 27" external monitor 1440p 2560x1440 resolution - avast! free  24.9.6130 (build 24.9.9452.762) UI 1.0.818/ Firefox, uBlock Origin Lite, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67183
Re: Backdoor Trojan not detectedn by Avast!
« Reply #2 on: June 04, 2009, 02:42:48 AM »
Nobody likes lack of detection... but as David said, not a software is perfect.
Thanks for helping improving avast detection.

Maybe you could run a full computer on-line scanning:
BitDefender
ESET NOD32
F-Secure

For detection-only, not cleaning:
Kaspersky
Trendmicro housecall
The best things in life are free.

Offline Dwarden

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1793
  • Ideas, that's ocean without borders!
    • Bohemia Interactive
Re: Backdoor Trojan not detectedn by Avast!
« Reply #3 on: June 04, 2009, 09:57:44 AM »
always send samples of such malware to Alwil! so they can tear it apart in lab and add detection if it's missing !
https://twitter.com/FoltynD , Tech. Community, Online Services & Distribution manager of Bohemia Interactive

cinchez

  • Guest
Re: Backdoor Trojan not detectedn by Avast!
« Reply #4 on: June 04, 2009, 03:08:32 PM »
As everybody says, No body or no thing is perfect, unfortunately that includes AVs as well^^ :)

Better send that sample to avast! to prevent future attacks^^ ;D

-AnimeLover^^

Offline .: L' arc :.

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1777
  • Thinking with Portals
Re: Backdoor Trojan not detectedn by Avast!
« Reply #5 on: June 05, 2009, 07:22:06 AM »
-= A layer of protection will help catch what the first, second, or so, layer missed..

(1) On-Access Antivirus [e.g. avast!]
(2) Firewall
(3) Anti-spyware/anti-malware [e.g. malwarebytes antimalware; SuperAntiSpyware]
(4) Other On-demand scanners & Utilities [e.g. Hijack This]
(5) You are also part of the protection layer since you are the one who controls the computer..

-= God bless..
Windows 7 (64-bit) Home Premium SP1
avast! 9 RC1

YoKenny

  • Guest
Re: Backdoor Trojan not detectedn by Avast!
« Reply #6 on: June 05, 2009, 12:38:30 PM »
-= A layer of protection will help catch what the first, second, or so, layer missed..

(1) On-Access Antivirus [e.g. avast!]
(2) Firewall
(3) Anti-spyware/anti-malware [e.g. malwarebytes antimalware; SuperAntiSpyware]
(4) Other On-demand scanners & Utilities [e.g. Hijack This]
(5) You are also part of the protection layer since you are the one who controls the computer..

-= God bless..

You forgot one:

Security monitor such as WinPatrol:
http://www.winpatrol.com

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67183
Re: Backdoor Trojan not detectedn by Avast!
« Reply #7 on: June 05, 2009, 05:19:14 PM »
A layer of protection
I'll call a layer of detection... only the first 2 are resident... (at least, free versions of them).
The best things in life are free.

Offline .: L' arc :.

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1777
  • Thinking with Portals
Re: Backdoor Trojan not detectedn by Avast!
« Reply #8 on: June 06, 2009, 09:32:07 AM »
-= ehehe.. ;D

-= Is my grammar wrong.. Sorry for bad english.. Layer of detection..
;D
Windows 7 (64-bit) Home Premium SP1
avast! 9 RC1