| View previous topic :: View next topic |
| Author |
Message |
dakikat
Cadet

 Joined: Jun 11, 2004 Posts: 6 Location: USA
|
Posted: Sat Feb 26, 2005 3:09 pm Post subject: backdoor.iroffer.3.ar found? |
|
|
Not sure which form to post this in, so I figuredI'd start here.
I have the free version of AVG and this morning it found backdoor.iroffer.3.ar on both my pc and my huband's. Mine was found in a file called dh77.exe in a hidden recycler directory.
I haven't been able to find any information on this, aside from one usenet post indicating it was a false positive
Does anyone know if this is in fact a false positve from AVG? Or, is it something new?
|
|
| Back to top |
|
 |
Prince_Serendip
Site Moderator
 Joined: Sep 07, 2002 Posts: 17542
|
Posted: Sat Feb 26, 2005 8:34 pm Post subject: |
|
|
Hi dakikat,
ZIP that thing up and email a copy of the file to virus@grisoft.cz with a brief explanation. You will get a reply. Then let us know too, because this thing is new.
Best regards _________________
Microsoft MVP Consumer Security 2006, 2007 & 2008
|
|
| Back to top |
|
 |
allsoap
Cadet

 Joined: May 04, 2004 Posts: 5 Location: USA
|
Posted: Tue Mar 01, 2005 3:33 pm Post subject: Same here, different file |
|
|
I received the same "BackDoor.IRoffer.3.AR" Trojan horse detected message from my free AVG this morning. It pointed to my downloaded installation file for WinRAR. Specificallly "wrar340.exe" and "wrar340.exe:\Default.SFX".
This file has been on my machine since Oct 2004 without triggering anything so I'm feeling this is a false positive?
Let me know if you need my files.
Thanks
Sherrie
|
|
| Back to top |
|
 |
Prince_Serendip
Site Moderator
 Joined: Sep 07, 2002 Posts: 17542
|
|
| Back to top |
|
 |
allsoap
Cadet

 Joined: May 04, 2004 Posts: 5 Location: USA
|
Posted: Wed Mar 02, 2005 2:37 pm Post subject: |
|
|
Thanks for the warm welcome! I mainly lurk, read and learn all that I can here.
I've sent the file and patiently await the diagnosis.
Thanks
Sherrie
|
|
| Back to top |
|
 |
Monkeh
Cadet

 Joined: Mar 02, 2005 Posts: 2 Location: UK
|
Posted: Wed Mar 02, 2005 5:11 pm Post subject: |
|
|
'lo all..
AVG Free just popped up the same warning for a file I got from a safe source over a month ago (russianbonuspack2k4.exe). I'm currently trying to get it through to grisoft (it seems my SMTP server has locked me out temporarily.. God knows why).
|
|
| Back to top |
|
 |
Prince_Serendip
Site Moderator
 Joined: Sep 07, 2002 Posts: 17542
|
|
| Back to top |
|
 |
Monkeh
Cadet

 Joined: Mar 02, 2005 Posts: 2 Location: UK
|
Posted: Wed Mar 02, 2005 8:00 pm Post subject: |
|
|
Alright, sorry, I must've missed that bit
If I manage to get the email through (my SMTP server still isn't letting me in, and the file is pretty big..), I'll let you know if I get a reply.
Edit: I think it was a false detection. I just updated AVG and it shows clean.
|
|
| Back to top |
|
 |
IP: 86.133.*.*
Guest
|
Posted: Thu Dec 20, 2007 6:07 pm Post subject: |
|
|
| Prince_Serendip wrote: | Hi dakikat,
ZIP that thing up and email a copy of the file to virus@grisoft.cz with a brief explanation. You will get a reply. Then let us know too, because this thing is new.
Best regards |
I recently contact AVG at grisoft with an enquiry regarding 3 Trojan Horse viruses that AVG had discovered during a scheduled scan. I have just received their reply telling me that if I was running the free version they could not help me and gave me a link to Castlecops. How then could I send them the email with the appropriate file.
Could you also explain how to ZIP the virus up and email a copy of it to grisoft. The TH's are now in my virus vault. Regards
|
|
| Back to top |
|
 |
Kodl
Private

 Joined: Mar 25, 2007 Posts: 42
|
Posted: Tue Dec 25, 2007 6:02 pm Post subject: |
|
|
| Anonymous wrote: | | Prince_Serendip wrote: | Hi dakikat,
ZIP that thing up and email a copy of the file to virus@grisoft.cz with a brief explanation. You will get a reply. Then let us know too, because this thing is new.
Best regards |
I recently contact AVG at grisoft with an enquiry regarding 3 Trojan Horse viruses that AVG had discovered during a scheduled scan. I have just received their reply telling me that if I was running the free version they could not help me and gave me a link to Castlecops. How then could I send them the email with the appropriate file.
Could you also explain how to ZIP the virus up and email a copy of it to grisoft. The TH's are now in my virus vault. Regards |
Please have a look at the original post from Prince_Serendip again. The address that you should use is virus@grisoft.cz. You can send suspect false alarms as well as new suspicious files (suspect malware) to that e-mail without any limitations. It's only the techsupport that is not available for AVG Free.
BTW - I am not sure if they really suggested going to CastleCops (which they might) but there is also a discussion forum for AVG Free users at http://forum.grisoft.cz/freeforum/
|
|
| Back to top |
|
 |
Impulse
Trooper

 Joined: Apr 27, 2008 Posts: 15 Location: USA
|
Posted: Sat May 03, 2008 6:36 am Post subject: |
|
|
May I offer 2 cents here? I believe that the backdoor.iroffer is a trojan and it could be quite possibly be related to a xdcc program called iroffer thats being used as a xdcc on mIRC.
Here's the website for further information: http://iroffer.org/
If you google the "iroffer" you'll come across several hits with links of people having issue with backdoor.iroffer, etc.
|
|
| Back to top |
|
 |
logicman_alf
Corporal

 Joined: Aug 18, 2006 Posts: 72 Location: UK
|
|
| Back to top |
|
 |
|
|