Author Topic: Win32:Spambot-EI[Trj] in Quicken program folder: FP?  (Read 4752 times)

0 Members and 2 Guests are viewing this topic.

Bolt

  • Guest
Win32:Spambot-EI[Trj] in Quicken program folder: FP?
« on: August 06, 2009, 07:30:58 AM »
Avast! identified the file, iBill.dll, located in the Quicken program folder (Quicken 2008) as infected by Spambot-EI[Trj] yesterday evening, using VPS 090805-1.  Virus Total indicates just Avast! and GData identify it as malware (see here: www.virustotal.com/analisis/15bcd684322594ab080e5a74eeeabe60c0e3520d9b05587062eee36bf33f364e-1249524385 ).

I moved the suspect file to the Chest, and it broke Quicken  :'( -- even restoring it from the Chest would not repair Quicken, so I had to do a re-install.

I also sent a copy of the suspect file to Avast! with a request that it be examined as a likely FP.

Has anyone else encountered this issue?  Any other thoughts?

Offline nmb

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3054
Re: Win32:Spambot-EI[Trj] in Quicken program folder: FP?
« Reply #1 on: August 06, 2009, 08:04:18 AM »
Hello bolt,

nothing to worry. just do a manual update after you have clicked the send email icon (if you have sent using avast chest) so that the file reaches avast now!. and you don't have to wait longer for the fix. someone from the alwil team "may" post here regarding this. after the update is released you can scan the file in chest and if it is no more detected as a virus then you can safely restore it.
« Last Edit: August 06, 2009, 08:08:10 AM by nmb »

douglas9

  • Guest
Re: Win32:Spambot-EI[Trj] in Quicken program folder: FP?
« Reply #2 on: August 06, 2009, 01:47:29 PM »
Avast! identified the file, iBill.dll, located in the Quicken program folder (Quicken 2008) as infected by Spambot-EI[Trj] yesterday evening, using VPS 090805-1.  Virus Total indicates just Avast! and GData identify it as malware (see here: www.virustotal.com/analisis/15bcd684322594ab080e5a74eeeabe60c0e3520d9b05587062eee36bf33f364e-1249524385 ).

I moved the suspect file to the Chest, and it broke Quicken  :'( -- even restoring it from the Chest would not repair Quicken, so I had to do a re-install.

I also sent a copy of the suspect file to Avast! with a request that it be examined as a likely FP.

Has anyone else encountered this issue?  Any other thoughts?

Received the same trojan warning when scanning my PC this a.m. Had downloaded the latest Avast Program update prior to scan.
« Last Edit: August 06, 2009, 01:54:23 PM by douglas9 »

Online DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89690
  • No support PMs thanks
Re: Win32:Spambot-EI[Trj] in Quicken program folder: FP?
« Reply #3 on: August 06, 2009, 02:15:29 PM »
If it is indeed a false positive, it seems this way according to the VirusTotal results, exclude them until the problem is corrected and submit the file to avast:

Add it to the exclusions lists: Standard Shield, Customize, Advanced, Add and Program Settings, Exclusions (right click the avast ' a ' icon) Restore it to its original location, periodically check it (scan it in the chest), there should still be a copy in the chest even though you restored it to the original location. When it is no longer detected then you can also remove it from the Standard Shield and Program Settings, exclusions.

Send the sample to virus@avast.com zipped and password protected with the password in email body, a link to this topic might help and undetected malware in the subject.
 
Or you can also add the file to the User Files (File, Add) section of the avast chest (if it isn't already in the chest) where it can do no harm and send it from there. A copy of the file/s will remain in the original location, so you will need to take further action and can remove/rename that.
 
Send it from the User Files section of the chest (select the file, right click, email to Alwil Software). It will be uploaded (not actually emailed) to avast when the next avast auto (or manual) update is done.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD - 27" external monitor 1440p 2560x1440 resolution - avast! free  24.9.6130 (build 24.9.9452.762) UI 1.0.818/ Firefox, uBlock Origin Lite, uMatrix/ MailWasher Pro/ Avast! Mobile Security

douglas9

  • Guest
Re: Win32:Spambot-EI[Trj] in Quicken program folder: FP?
« Reply #4 on: August 06, 2009, 07:02:58 PM »
Restored the file from the infected file section of virus chest without problems. However the "copy" remained in the chest. How do i remove the "copy from the chest". Thanks.

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67183
Re: Win32:Spambot-EI[Trj] in Quicken program folder: FP?
« Reply #5 on: August 06, 2009, 07:54:24 PM »
Restored the file from the infected file section of virus chest without problems. However the "copy" remained in the chest. How do i remove the "copy from the chest". Thanks.
Right click it and choose "Delete".
The best things in life are free.