Re: How to get rid of trojan downloader



Art wrote:

On Wed, 26 Jul 2006 13:46:42 -0400, Ron Lopshire <notron@xxxxxxxx>
wrote:

3) I submitted your frog to KL in a password protected file. What a PITA! I had to disable all KAV protection in order to create the zipped file. KAV wouldn't even let me look at the sub-directory in which I had placed it. LOL.

I'm curious to know if they respond, and if so, what they have to
say. Please let us know.

Art, from KL:

***quote***

Hello.

This file is clear.

Sincerely yours,
Pavel Zelensky
Virus analyst

Kaspersky Lab Ltd
Moscow, Russia
Tel/Fax: +7 (495) 797-8700
E-mail: newvirus@xxxxxxxxxxxxx
Internet: http://www.kaspersky.com, http://www.viruslist.com

>> Attachment: Neutered_Frog.zip

***endquote***

The KAV File-AV and Web-AV still don't like the frog. Let's see what happens overnight.

FWIW, from Virus Total:

STATUS: FINISHED
Complete scanning result of "Neutered_Frog.jpg", received in VirusTotal at 07.31.2006, 03:32:08 (CET).
Antivirus Version Update Result
AntiVir 6.35.1.0 07.30.2006 no virus found
Authentium 4.93.8 07.29.2006 no virus found
Avast 4.7.844.0 07.29.2006 no virus found
AVG 386 07.28.2006 no virus found
BitDefender 7.2 07.31.2006 no virus found
CAT-QuickHeal 8.00 07.29.2006 no virus found
ClamAV devel-20060426 07.31.2006 no virus found
DrWeb 4.33 07.30.2006 no virus found
eTrust-InoculateIT 23.72.82 07.30.2006 no virus found
eTrust-Vet 12.6.2314 07.28.2006 Win32/Vxidl
Ewido 4.0 07.30.2006 no virus found
Fortinet 2.77.0.0 07.30.2006 no virus found
F-Prot 3.16f 07.28.2006 no virus found
F-Prot4 4.2.1.29 07.28.2006 no virus found
Ikarus 0.2.65.0 07.28.2006 no virus found
Kaspersky 4.0.2.24 07.31.2006 Trojan-Downloader.Win32.Tibs.gc
McAfee 4817 07.28.2006 no virus found
Microsoft 1.1508 07.27.2006 no virus found
NOD32v2 1.1684 07.29.2006 no virus found
Norman 5.90.23 07.28.2006 no virus found
Panda 9.0.0.4 07.30.2006 no virus found
Sophos 4.08.0 07.30.2006 no virus found
Symantec 8.0 07.31.2006 no virus found
TheHacker 5.9.8.183 07.30.2006 no virus found
UNA 1.83 07.28.2006 no virus found
VBA32 3.11.0 07.31.2006 no virus found
VirusBuster 4.3.7:9 07.30.2006 no virus found

Aditional Information
File size: 1738 bytes
MD5: 1e0cc6a87918a4c24cb94a8b28b323d7
SHA1: ff8e78489a667d8b06ac085e134f0bfd9c7a110c

Ron :)
.