trojan-gen//Backdoor query

S

sophie

avast detected and removed trojan-gen (aka Backdoor) from my pc. the
_only_ file I had received and opened since my last scan was an Excel
file which proved not to be infected.
Does this mean that the source of the infection is still on the pc, and
if so, how do I find it?

many thanks for any help,
 
N

null

avast detected and removed trojan-gen (aka Backdoor) from my pc. the
_only_ file I had received and opened since my last scan was an Excel
file which proved not to be infected.

How was this proved? Through analysis by a competent expert? Or at
least the file was scanned by several high quality av products?
Does this mean that the source of the infection is still on the pc, and
if so, how do I find it?

Doesn't mean that at all. Are you sure you have no internet file
shares and/or open ports? What about browser and email apps and
security settings? What internet activities do you engage in besides
email, newsgroups and browsing?
many thanks for any help,

Hope this helps:

http://www.claymania.com/safe-hex.html


Art
http://www.epix.net/~artnpeg
 
F

FromTheRafters

sophie said:
avast detected and removed trojan-gen (aka Backdoor) from my pc.

Where was this file found?
What was the files name?
the _only_ file I had received and opened since my last scan was
an Excel file...

You might think so, but.....

Many files are downloaded and "opened" as you browse the
internet. The generic trojan could have been detected in your
Temporary Internet Files folder, and in a file that your browser
security settings didn't allow to open.

Does your AV keep a log of its activities?
If so, does it tell you where the suspect file was found?
We don't have any way of determining whether the malware
in question was active or dormant (pre- activation).

Another possibility is if you have your AV set to automatically
delete suspect files, and you have WinME or WinXP with the
system restore feature active, the restore feature makes a backup
copy of the malware. The initial deletion by the AV goes unnoticed
by the user, but the next scan finds the malware in the _restore
folder where the AV may not be able to properly deal with it.
which proved not to be infected.

Proved how? (anyway, I don't think the Excel file was the source
of the problem ~ but I can't know this without additional information).
Excel files can contain malware, and if it is *new* the AV won't be
able to detect it. Keep in mind that AVs cannot prove that something
is not malicious, they can only guess with a high probability that some
are.

"No virus found" in a file is not the same as "no virus within" a file.
Does this mean that the source of the infection is still on the pc, and
if so, how do I find it?

Unable to tell you anything at this point, but it is likely
that you were not actually a victim of active malware.
A lot depends on the filename, where it was found,
how up-to-date your AV is, and how new the suspected
malware is.

Don't panic ~ yet!
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top