Welcome to SecurityForumz.com!
FAQFAQ      ProfileProfile    Private MessagesPrivate Messages   Log inLog in

trojan-gen//Backdoor query

 
   Security Forums (Home) -> General Discussions RSS
Next:  Trojan BackDoor.Apdoor.J  
Author Message
sophie

External


Since: Sep 17, 2003
Posts: 4



(Msg. 1) Posted: Wed Sep 17, 2003 9:30 am
Post subject: trojan-gen//Backdoor query
Archived from groups: alt>comp>anti-virus (more info?)

avast detected and removed trojan-gen (aka Backdoor) from my pc. the
_only_ file I had received and opened since my last scan was an Excel
file which proved not to be infected.
Does this mean that the source of the infection is still on the pc, and
if so, how do I find it?

many thanks for any help,
--
sophie

 >> Stay informed about: trojan-gen//Backdoor query 
Back to top
Login to vote
FromTheRafters

External


Since: Sep 19, 2003
Posts: 1207



(Msg. 2) Posted: Wed Sep 17, 2003 7:38 pm
Post subject: Re: trojan-gen//Backdoor query [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

"sophie" <sophie-usenetNOSPAMTHANKYOU.RemoveThis@blueyonder.co.uk> wrote in message news:5$pq6RAquBa$EwBp@193.38.113.3...
>
> avast detected and removed trojan-gen (aka Backdoor) from my pc.

Where was this file found?
What was the files name?

> the _only_ file I had received and opened since my last scan was
> an Excel file...

You might think so, but.....

Many files are downloaded and "opened" as you browse the
internet. The generic trojan could have been detected in your
Temporary Internet Files folder, and in a file that your browser
security settings didn't allow to open.

Does your AV keep a log of its activities?
If so, does it tell you where the suspect file was found?
We don't have any way of determining whether the malware
in question was active or dormant (pre- activation).

Another possibility is if you have your AV set to automatically
delete suspect files, and you have WinME or WinXP with the
system restore feature active, the restore feature makes a backup
copy of the malware. The initial deletion by the AV goes unnoticed
by the user, but the next scan finds the malware in the _restore
folder where the AV may not be able to properly deal with it.

> which proved not to be infected.

Proved how? (anyway, I don't think the Excel file was the source
of the problem ~ but I can't know this without additional information).
Excel files can contain malware, and if it is *new* the AV won't be
able to detect it. Keep in mind that AVs cannot prove that something
is not malicious, they can only guess with a high probability that some
are.

"No virus found" in a file is not the same as "no virus within" a file.

> Does this mean that the source of the infection is still on the pc, and
> if so, how do I find it?

Unable to tell you anything at this point, but it is likely
that you were not actually a victim of active malware.
A lot depends on the filename, where it was found,
how up-to-date your AV is, and how new the suspected
malware is.

Don't panic ~ yet!

 >> Stay informed about: trojan-gen//Backdoor query 
Back to top
Login to vote
Display posts from previous:   
Related Topics:
Damn trojan in my temp (probably). Advice needed. - Ok , this is how the situation has. 3 days my firewall poped up and an application in my C:\Documents And Settings\Administrator\Local Settings\temp wanted to connect at port 80 of an address. It had a weird icon and a weird name ( Rar1.exe). I denied....

Running a trojan program and Virus programs a waste of time? - Thanks for opinions of the knowledgable ones:>) Regards Buddy B

Poss trojan? - I just updated my AVG database, and it picked up a back door Ap trojan. Details are: C:\Windows\system32\XUDERSD.exe. When I try to remove it to quarantine, a message says the file cannot be removed. I checked it with V.3.5 of The Cleaner, which doesn't...

church trojan - Last week it was discovered our church computer(s) have a trojan virus. There are three networked together. The internet provider phoned the secretary and told her that a port was open. I looked for suspicious .exe files and found "pipecmdsvr.exe&q...

deltee trojan - hi all ive just done a full system virus check and Norton has found what it calls the deltree trojan, it says the file it has infected (delete.bat) cannot be repaired or deleted so its been put into quarantine. what do i do now, can i leave it there..
   Security Forums (Home) -> General Discussions All times are: Pacific Time (US & Canada) (change)
Page 1 of 1

 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum



[ Contact us | Terms of Service/Privacy Policy ]