CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

TR/Virtl.Breaker.SN (Found by AntiVir)

 
Post new topic   Reply to topic       All -> FavForums -> AntiVir Personal Edition Classic [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
Rasheed187

Trooper
Trooper


Joined: Jul 21, 2005
Posts: 10
Location: Netherlands

PostPosted: Mon Jul 25, 2005 8:16 pm    Post subject: TR/Virtl.Breaker.SN (Found by AntiVir)
Reply with quote

Hi,

I canīt seem to find any info about a trojan which was spotted by AntiVir perhaps someone can help me, this was the trojan:

TR/Virtl.Breaker.SN

TIA Wink

Back to top
View users profile Send private message
TopperID

Captain
Captain


Joined: Oct 14, 2004
Posts: 375
Location: UK

PostPosted: Mon Jul 25, 2005 10:01 pm    Post subject:
Reply with quote

Hi Rasheed187,

TR/Virtl.Breaker.SN is a Hacktool:-

http://www.symantec.com/avcenter/venc/data/hacktool.html

You can see some of the names it goes under here:-

http://www.viruslist.com/en/viruses/encyclopedia?virusid=65901

Some more details of Hacker Tools, Exploits and VirTools can be found here:-

http://www.viruslist.com/en/virusesdescribed?chapter=152540538#hack

Did the Guard pick this one up, or was it the scanner? I'm assuming AntiVir managed to deal with the problem O.K. and you are just posting out of curiosity; but if you are having problems removing it please give the full filepath and your operating system.

Back to top
View users profile Send private message
Rasheed187

Trooper
Trooper


Joined: Jul 21, 2005
Posts: 10
Location: Netherlands

PostPosted: Wed Jul 27, 2005 6:09 pm    Post subject:
Reply with quote

Hi,

It was found by the scanner, and I have deleted the file. But if it was in memory, AntiVir should have spotted it with the realtime Guard right? Because I didnīt get a warning.

However MSAS reported that the "restrict anonymous guest access" setting was trying to be changed so I think a hacker tried to exploit it.

But itīs a bit strange that I couldnīt find any details about this trojan, so thatīs why I asked. Itīs always interesting to see what a specific trojan can do exactly. Wink

Back to top
View users profile Send private message
TopperID

Captain
Captain


Joined: Oct 14, 2004
Posts: 375
Location: UK

PostPosted: Wed Jul 27, 2005 8:06 pm    Post subject:
Reply with quote

Quote:
It was found by the scanner, and I have deleted the file. But if it was in memory, AntiVir should have spotted it with the realtime Guard right?

How do you know it was running in memory? AV Guards are generally looking at files being written to and read from the HD, rather than running in memory, ATs like ewido do the memory scanning.

Unless you give the file path it is not possible to comment further, but there are numerous reasons why things may be found by the demand scanner and not by the Guard. For example:-

1) you may have had different configuration 'Search' settings for the Guard and main scanner;

2) the file may not have come to the Guard's attention since the definition was included in the sig base;

3) the Guard will not look into archives while the main scanner will;

4) the file may have been located in a cache inaccessible the the Guard.

I'm sure there are are other reasons too, if one thinks about it.

Provided the signature was in AntiVir's data base at the time, I'm sure the Guard would have pounced on this file if it was in a position to cause mischief on your system. Though a number of leading AVs (eg McAfee , AVG and CA VET) are, at the time of writing, apparently unable to find this malware at all!

Back to top
View users profile Send private message
Rasheed187

Trooper
Trooper


Joined: Jul 21, 2005
Posts: 10
Location: Netherlands

PostPosted: Tue Aug 02, 2005 8:52 pm    Post subject:
Reply with quote

Hi,

Thanks for the feedback, I was looking at my system events log and it seems like AntiVir spotted the trojan in my browser cache. Iīm not sure if the trojan was active at on point or not, but the MSAS notifications did make me a bit suspicious.

And yes, I forgot AntiVir doesnīt scan the memory. But at the moment there doesnīt seem to be any trojan active, will scan with A Squared and Ewido just to be sure. Wink

Back to top
View users profile Send private message
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> AntiVir Personal Edition Classic All times are GMT
Page 1 of 1

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer