Discussion:
What virus is this?
(too old to reply)
David H. Lipman
2004-11-20 12:51:39 UTC
Permalink
McAfee calls it "Downloader-SF" -- http://vil.nai.com/vil/content/v_130095.htm

Dave



"Shabam" <***@hotmail.com> wrote in message news:uYednb3ga67ElALcRVn-***@adelphia.com...
| I just saw this program attempt to connect to 216.218.240.58 on my machine.
| I was only browsing some pages and my browser actually crashed as a result
| too. Scanned my system and also scanned it at housecall.trendmicro.com.
| Found nothing.
|
| Anyone know what this program is? I'm attaching it. It's named "bla.exe"
| and was placed in my C:\ directory.
|
| Details:This one time, the user has chosen to "block" communications
| Outbound TCP connection
| Remote address,service is (216.218.240.58,http(80))
| Process name is "C:\bla.exe"
|
|
|
|
Marc
2004-11-20 14:09:46 UTC
Permalink
Post by David H. Lipman
Process name is "C:\bla.exe"
It's another trojan that eTrust, NOD32, and NAV missed!

This is the report of the scanning done over "bla.exe" file that
VirusTotal processed on 11/20/2004 at 13:17:57.

Antivirus Version Update Result
BitDefender 7.0 11.20.2004 BehavesLike:Trojan.Downloader
ClamWin devel-20041018 11.20.2004 -
eTrust-Iris 7.1.194.0 11.19.2004 -
F-Prot 3.15b 11.19.2004 could be infected with an unknown virus
Kaspersky 4.0.2.24 11.20.2004 Trojan-Downloader.Win32.Small.aaq
NOD32v2 1.928 11.19.2004 -
Norman 5.70.10 11.19.2004 W32/Downloader
Panda 7.02.00 11.19.2004 -
Sybari 7.5.1314 11.20.2004 Win32.Reckmess.A!downloader
Symantec 8.0 11.19.2004 -

http://www.virustotal.com/flash/index_en.html




----== Posted via Newsfeeds.Com - Unlimited-Uncensored-Secure Usenet News==----
http://www.newsfeeds.com The #1 Newsgroup Service in the World! >100,000 Newsgroups
---= East/West-Coast Server Farms - Total Privacy via Encryption =---
Loading...