CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

backdoor.iroffer.3.ar found?

 
Post new topic   Reply to topic       All -> FavForums -> Grisoft AVG [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
dakikat

Cadet
Cadet


Joined: Jun 11, 2004
Posts: 6
Location: USA

PostPosted: Sat Feb 26, 2005 3:09 pm    Post subject: backdoor.iroffer.3.ar found?
Reply with quote

Not sure which form to post this in, so I figuredI'd start here.

I have the free version of AVG and this morning it found backdoor.iroffer.3.ar on both my pc and my huband's. Mine was found in a file called dh77.exe in a hidden recycler directory.

I haven't been able to find any information on this, aside from one usenet post indicating it was a false positive

Does anyone know if this is in fact a false positve from AVG? Or, is it something new?

Back to top
View users profile Send private message
Prince_Serendip

Site Moderator


Joined: Sep 07, 2002
Posts: 17542

1st Responders MIRT Moderators MVP Premium RootKit Detection Hosts Rootkit Experts Rootkit Responders

PostPosted: Sat Feb 26, 2005 8:34 pm    Post subject:
Reply with quote

Hi dakikat,

ZIP that thing up and email a copy of the file to virus@grisoft.cz with a brief explanation. You will get a reply. Then let us know too, because this thing is new.


Best regards


_________________
image
Microsoft MVP Consumer Security 2006, 2007 & 2008
Back to top
View users profile Send private message
allsoap

Cadet
Cadet


Joined: May 04, 2004
Posts: 5
Location: USA

PostPosted: Tue Mar 01, 2005 3:33 pm    Post subject: Same here, different file
Reply with quote

I received the same "BackDoor.IRoffer.3.AR" Trojan horse detected message from my free AVG this morning. It pointed to my downloaded installation file for WinRAR. Specificallly "wrar340.exe" and "wrar340.exe:\Default.SFX".

This file has been on my machine since Oct 2004 without triggering anything so I'm feeling this is a false positive?

Let me know if you need my files.

Thanks
Sherrie

Back to top
View users profile Send private message
Prince_Serendip

Site Moderator


Joined: Sep 07, 2002
Posts: 17542

1st Responders MIRT Moderators MVP Premium RootKit Detection Hosts Rootkit Experts Rootkit Responders

PostPosted: Tue Mar 01, 2005 5:42 pm    Post subject:
Reply with quote

Hi allsoap,

Welcome to our board and to this forum. Very Happy

Cannot hurt to get it checked. Could be a false-positive, but what if it isn't? Shocked Wink


Best regards


_________________
image
Microsoft MVP Consumer Security 2006, 2007 & 2008
Back to top
View users profile Send private message
allsoap

Cadet
Cadet


Joined: May 04, 2004
Posts: 5
Location: USA

PostPosted: Wed Mar 02, 2005 2:37 pm    Post subject:
Reply with quote

Thanks for the warm welcome! I mainly lurk, read and learn all that I can here.

I've sent the file and patiently await the diagnosis.

Thanks
Sherrie

Back to top
View users profile Send private message
Monkeh

Cadet
Cadet


Joined: Mar 02, 2005
Posts: 2
Location: UK

PostPosted: Wed Mar 02, 2005 5:11 pm    Post subject:
Reply with quote

'lo all..

AVG Free just popped up the same warning for a file I got from a safe source over a month ago (russianbonuspack2k4.exe). I'm currently trying to get it through to grisoft (it seems my SMTP server has locked me out temporarily.. God knows why).

Back to top
View users profile Send private message
Prince_Serendip

Site Moderator


Joined: Sep 07, 2002
Posts: 17542

1st Responders MIRT Moderators MVP Premium RootKit Detection Hosts Rootkit Experts Rootkit Responders

PostPosted: Wed Mar 02, 2005 5:51 pm    Post subject:
Reply with quote

Hi Monkeh,

Welcome to CastleCops. Very Happy

From Russia with Love? Rolling on the floor laughing...

Actually, we do not usually do this many posters, needing help all-in-one thread bit here at CastleCops. Laughing

But this is a special case so I'm allowing it. No point in having a bunch of seperate threads scattered all over. I may even "sticky" this one?

Just letting you know that if you try tacking on to other people's threads elsewhere at CastleCops you will get into hot water. Wink

Follow the instructions given, and please let us know here what Grisoft says to you? Thanks. Thumbs Up


Best regards


_________________
image
Microsoft MVP Consumer Security 2006, 2007 & 2008
Back to top
View users profile Send private message
Monkeh

Cadet
Cadet


Joined: Mar 02, 2005
Posts: 2
Location: UK

PostPosted: Wed Mar 02, 2005 8:00 pm    Post subject:
Reply with quote

Alright, sorry, I must've missed that bit Wink

If I manage to get the email through (my SMTP server still isn't letting me in, and the file is pretty big..), I'll let you know if I get a reply.

Edit: I think it was a false detection. I just updated AVG and it shows clean.

Back to top
View users profile Send private message
IP: 86.133.*.*

Guest






PostPosted: Thu Dec 20, 2007 6:07 pm    Post subject:
Reply with quote

Prince_Serendip wrote:
Hi dakikat,

ZIP that thing up and email a copy of the file to virus@grisoft.cz with a brief explanation. You will get a reply. Then let us know too, because this thing is new.


Best regards

I recently contact AVG at grisoft with an enquiry regarding 3 Trojan Horse viruses that AVG had discovered during a scheduled scan. I have just received their reply telling me that if I was running the free version they could not help me and gave me a link to Castlecops. How then could I send them the email with the appropriate file.
Could you also explain how to ZIP the virus up and email a copy of it to grisoft. The TH's are now in my virus vault. Regards

Back to top
Kodl

Private
Private


Joined: Mar 25, 2007
Posts: 42


PostPosted: Tue Dec 25, 2007 6:02 pm    Post subject:
Reply with quote

Anonymous wrote:
Prince_Serendip wrote:
Hi dakikat,

ZIP that thing up and email a copy of the file to virus@grisoft.cz with a brief explanation. You will get a reply. Then let us know too, because this thing is new.


Best regards

I recently contact AVG at grisoft with an enquiry regarding 3 Trojan Horse viruses that AVG had discovered during a scheduled scan. I have just received their reply telling me that if I was running the free version they could not help me and gave me a link to Castlecops. How then could I send them the email with the appropriate file.
Could you also explain how to ZIP the virus up and email a copy of it to grisoft. The TH's are now in my virus vault. Regards

Please have a look at the original post from Prince_Serendip again. The address that you should use is virus@grisoft.cz. You can send suspect false alarms as well as new suspicious files (suspect malware) to that e-mail without any limitations. It's only the techsupport that is not available for AVG Free.
BTW - I am not sure if they really suggested going to CastleCops (which they might) but there is also a discussion forum for AVG Free users at http://forum.grisoft.cz/freeforum/

Back to top
View users profile Send private message Visit posters website
Impulse

Trooper
Trooper


Joined: Apr 27, 2008
Posts: 13
Location: USA

PostPosted: Sat May 03, 2008 6:36 am    Post subject:
Reply with quote

May I offer 2 cents here? I believe that the backdoor.iroffer is a trojan and it could be quite possibly be related to a xdcc program called iroffer thats being used as a xdcc on mIRC.

Here's the website for further information: http://iroffer.org/

If you google the "iroffer" you'll come across several hits with links of people having issue with backdoor.iroffer, etc.

Back to top
View users profile Send private message
logicman_alf

Corporal
Corporal


Joined: Aug 18, 2006
Posts: 72
Location: UK

PostPosted: Mon Jun 09, 2008 9:12 pm    Post subject:
Reply with quote

I note that there have been no recent responses to this topic,
so here's my 2 pence/cents worth.


The iroffer website contains no new updates since 12/12/05.
The Mcafee web site lists iroffer as a known PUP since 06/12/2002.
(Potentially Unwanted Program)
http://vil.nai.com/vil/content/v_100976.htm

Mcafee Site Advisor also warns of PUP downloads.
http://www.siteadvisor.com/sites/iroffer.org?domain=iroffer.org&ref=safe&client_ver=FF_26.6_6265&locale=en-US&premium=false&client_type=FF&aff_id=0

The iroffer software is designed for file exchange.
Considering the age of this software, it is entirely possible that hacked versions exist. Hacked or not, I would not want it on my computer.

I would say to anyone: if you did not deliberately put this on your computer for a specific reason, remove it at once, or allow your anti-virus to delete it.

I hope this may help someone.

Back to top
View users profile Send private message
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Grisoft AVG All times are GMT
Page 1 of 1

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer