ClamWin Free Antivirus Forum Index
ClamWin Free Antivirus
Support and Discussion Forums
Reply to topic
IEXPLORE.EXE: Trojan.Downloader-25397 FOUND?
norman6810


Joined: 08 Mar 2008
Posts: 0
Location: PRChina
Reply with quote
I just begin to use Clamwin, and it told me that the IEXPLORE.EXE was infected by Trojan.Downloader-25397.
The following is the scanlog:

Scan Started Sat Mar 08 17:31:23 2008
-------------------------------------------------------------------------------

C:\Program Files\Internet Explorer\IEXPLORE.EXE: Trojan.Downloader-25397 FOUND

----------- SCAN SUMMARY -----------
Known viruses: 222441
Engine version: 0.92
Scanned directories: 4
Scanned files: 26
Skipped non-executable files: 0
Infected files: 1
Data scanned: 0.93 MB
Time: 4.953 sec (0 m 4 s)

I also send the sample to the virustotal, and 3 AVs alarmed,including Clamwin.
This is the webpage of the result:
https://www.virustotal.com/analisis/839933079b9816cc530eb32c3f80d3c1

Maybe it's a flase positive. Question
View user's profileSend private message
GuitarBob


Joined: 09 Jul 2006
Posts: 9
Location: USA
Reply with quote
Hello Norman:

It is very likely a false positive. Some ClamWin users (including me) had a similar notice a day or so ago. The thread about it is just a couple of titles down from your post, but here it is:https://forums.clamwin.com/viewtopic.php?t=1574 on the ClamWin forum.

They are getting a lot of false positivies lately--that's why it's probably best to configure ClamWin to Notify you of any infections (not Quarantine or Remove). That way, you can check the file out on Jotti or Virus Total to see if it is a false positive. If you Quarantine/Remove and it is a false positive, you could lose access to your computer if it is system file.

Regards,
View user's profileSend private message
re:Virus Scan Report
tobination


Joined: 12 Mar 2008
Posts: 0
Reply with quote
I am not sure whether it is a false report or not but it will be nice if you could contact the service people over there.May be you might have overlooked the installation procedure by missing out on some instructions.Definitely there will be an option to disable these false reports if you have received any.

Url removed
suggestions for alternative antivirus are not a problem, but a link means advertising
View user's profileSend private message
encountered the same problem
lovetide


Joined: 21 Apr 2008
Posts: 0
Location: China.ShenZhen
Reply with quote
I installed ClamWin 0.93, and scanned WINDOWS directory, it reports IE & notepad as Trojan:
Code:
Scan Started Mon Apr 21 09:15:32 2008
-------------------------------------------------------------------------------
C:\WINDOWS\ie7\iexplore.exe: Trojan.Downloader-25397 FOUND
C:\WINDOWS\NOTEPAD.EXE: Trojan.Dropper-1206 FOUND
C:\WINDOWS\system32\dllcache\notepad.exe: Trojan.Dropper-1206 FOUND
C:\WINDOWS\system32\notepad.exe: Trojan.Dropper-1206 FOUND
----------- SCAN SUMMARY -----------
Known viruses: 263176
Engine version: 0.93
Scanned directories: 2285
Scanned files: 18824
Infected files: 4

Data scanned: 6836.41 MB
Time: 2573.219 sec (42 m 53 s)
--------------------------------------
Completed
--------------------------------------


The sha1sum & md5sum of these files:
Code:

C:\cygwin\bin>sha1sum.exe c:\WINDOWS\ie7\iexplore.exe c:\WINDOWS\NOTEPAD.EXE c:\WINDOWS\system32\notepad.exe c:\windows\
system32\dllcache\notepad.exe
\5ca591fbe5acad31c3f1dc0334eff687b09c55d8 *c:\\WINDOWS\\ie7\\iexplore.exe
\1572b3c4d3dd39832ae500abccc1d2df27ef1b8c *c:\\WINDOWS\\NOTEPAD.EXE
\1572b3c4d3dd39832ae500abccc1d2df27ef1b8c *c:\\WINDOWS\\system32\\notepad.exe
\1572b3c4d3dd39832ae500abccc1d2df27ef1b8c *c:\\windows\\system32\\dllcache\\notepad.exe

C:\cygwin\bin>md5sum.exe c:\WINDOWS\ie7\iexplore.exe c:\WINDOWS\NOTEPAD.EXE c:\WINDOWS\system32\notepad.exe c:\windows\s
ystem32\dllcache\notepad.exe
\ecd35d17f66899882b9558f5b94c5798 *c:\\WINDOWS\\ie7\\iexplore.exe
\89fe32de8587b0dfd76efce00396eb56 *c:\\WINDOWS\\NOTEPAD.EXE
\89fe32de8587b0dfd76efce00396eb56 *c:\\WINDOWS\\system32\\notepad.exe
\89fe32de8587b0dfd76efce00396eb56 *c:\\windows\\system32\\dllcache\\notepad.exe

C:\cygwin\bin>


Did these files really infected?


Last edited by lovetide on Mon Apr 21, 2008 10:39 am; edited 1 time in total
View user's profileSend private message
alch
Site Admin

Joined: 27 Nov 2005
Posts: 0
Reply with quote
try scanning those on https://www.virustotal.com and see what other scanners find
View user's profileSend private message
sherpya


Joined: 22 Mar 2006
Posts: 0
Location: Italy
Reply with quote
I've already seen a trojan that replaces ie in dllcache and program files directory, but just to be sure it's better to use something like virustotal
View user's profileSend private message
lovetide


Joined: 21 Apr 2008
Posts: 0
Location: China.ShenZhen
Reply with quote
alch wrote:
try scanning those on https://www.virustotal.com and see what other scanners find


results from virustotal.com:

IE7
https://www.virustotal.com/zh-cn/analisis/c1c35000d4cce6f251c751ed72bcfd9e https://www.virustotal.com/zh-cn/analisis/c1c35000d4cce6f251c751ed72bcfd9e

Notepad
https://www.virustotal.com/zh-cn/analisis/6fb84558f0754176342b69cb9da2565e https://www.virustotal.com/zh-cn/analisis/6fb84558f0754176342b69cb9da2565e

The following is a copy of the result:
IE7
Code:

文件 iexplore.exe 接收于 2008.04.19 16:24:31 (CET)
当前状态: 完成

结果: 3/32 (9.38%)
 格式化文本 打印结果 
反病毒引擎 版本 最后更新 扫描结果
AhnLab-V3 2008.4.19.0 2008.04.18 -
AntiVir 7.8.0.8 2008.04.18 -
Authentium 4.93.8 2008.04.18 -
Avast 4.8.1169.0 2008.04.18 -
AVG 7.5.0.516 2008.04.19 -
BitDefender 7.2 2008.04.19 -
CAT-QuickHeal 9.50 2008.04.19 -
ClamAV 0.92.1 2008.04.19 Trojan.Downloader-25397
DrWeb 4.44.0.09170 2008.04.19 -
eSafe 7.0.15.0 2008.04.17 -
eTrust-Vet 31.3.5714 2008.04.19 -
Ewido 4.0 2008.04.19 -
F-Prot 4.4.2.54 2008.04.18 -
F-Secure 6.70.13260.0 2008.04.19 -
FileAdvisor 1 2008.04.19 -
Fortinet 3.14.0.0 2008.04.19 -
Ikarus T3.1.1.26 2008.04.19 Trojan.Win32.Patched.c
Kaspersky 7.0.0.125 2008.04.19 -
McAfee 5277 2008.04.18 -
Microsoft 1.3408 2008.04.19 -
NOD32v2 3040 2008.04.19 -
Norman 5.80.02 2008.04.18 -
Panda 9.0.0.4 2008.04.19 -
Prevx1 V2 2008.04.19 -
Rising 20.40.52.00 2008.04.19 -
Sophos 4.28.0 2008.04.19 -
Sunbelt 3.0.1056.0 2008.04.17 -
Symantec 10 2008.04.19 -
TheHacker 6.2.92.284 2008.04.18 Trojan/Downloader.Bagle.fw
VBA32 3.12.6.4 2008.04.16 -
VirusBuster 4.3.26:9 2008.04.18 -
Webwasher-Gateway 6.6.2 2008.04.18 -
附加信息
File size: 93184 bytes
MD5...: ecd35d17f66899882b9558f5b94c5798
SHA1..: 5ca591fbe5acad31c3f1dc0334eff687b09c55d8



Notepad
Code:

文件 NOTEPAD.EXE 接收于 2008.04.19 08:07:53 (CET)
当前状态: 完成

结果: 2/32 (6.25%)
 格式化文本 打印结果 
反病毒引擎 版本 最后更新 扫描结果
AhnLab-V3 2008.4.19.0 2008.04.18 -
AntiVir 7.8.0.8 2008.04.18 -
Authentium 4.93.8 2008.04.18 -
Avast 4.8.1169.0 2008.04.18 -
AVG 7.5.0.516 2008.04.18 -
BitDefender 7.2 2008.04.19 -
CAT-QuickHeal 9.50 2008.04.18 -
ClamAV 0.92.1 2008.04.19 Trojan.Dropper-1206
DrWeb 4.44.0.09170 2008.04.19 -
eSafe 7.0.15.0 2008.04.17 Win32.Fubalca
eTrust-Vet 31.3.5714 2008.04.19 -
Ewido 4.0 2008.04.18 -
F-Prot 4.4.2.54 2008.04.18 -
F-Secure 6.70.13260.0 2008.04.19 -
FileAdvisor 1 2008.04.19 -
Fortinet 3.14.0.0 2008.04.19 -
Ikarus T3.1.1.26 2008.04.19 -
Kaspersky 7.0.0.125 2008.04.19 -
McAfee 5277 2008.04.18 -
Microsoft 1.3408 2008.04.19 -
NOD32v2 3040 2008.04.19 -
Norman 5.80.02 2008.04.18 -
Panda 9.0.0.4 2008.04.19 -
Prevx1 V2 2008.04.19 -
Rising 20.40.50.00 2008.04.19 -
Sophos 4.28.0 2008.04.19 -
Sunbelt 3.0.1056.0 2008.04.17 -
Symantec 10 2008.04.19 -
TheHacker 6.2.92.284 2008.04.18 -
VBA32 3.12.6.4 2008.04.16 -
VirusBuster 4.3.26:9 2008.04.18 -
Webwasher-Gateway 6.6.2 2008.04.18 -
附加信息
File size: 66560 bytes
MD5...: 89fe32de8587b0dfd76efce00396eb56
SHA1..: 1572b3c4d3dd39832ae500abccc1d2df27ef1b8c

View user's profileSend private message
alch
Site Admin

Joined: 27 Nov 2005
Posts: 0
Reply with quote
I tested notepad.exe and iexplore.exe from english XP and Vista and it did not report a virus there. Are your files from a non-english Windows and what version?
View user's profileSend private message
lovetide


Joined: 21 Apr 2008
Posts: 0
Location: China.ShenZhen
Reply with quote
alch wrote:
I tested notepad.exe and iexplore.exe from english XP and Vista and it did not report a virus there. Are your files from a non-english Windows and what version?


I'm using a Simplified Chinese Windows XP operating system, IE7 is also a simplified chinese version
View user's profileSend private message
alch
Site Admin

Joined: 27 Nov 2005
Posts: 0
Reply with quote
could you please submit those false positive files at https://cgi.clamav.net/sendvirus.cgi Please specify it's a traditional chinese XP and put the virustotal.com result links in the comments too.

Thanks


Last edited by alch on Mon Apr 21, 2008 10:47 pm; edited 1 time in total
View user's profileSend private message
GuitarBob


Joined: 09 Jul 2006
Posts: 9
Location: USA
Reply with quote
For future reference: below is a link to a Chinese online file scanning site. They receive all kinds of files, of course, but you see more Chinese stuff there than on the other online scanning sites. Flower Pig is very helpful and always tries to have the latest version of ClamAV at the site.

https://virscan.org/

Regards
View user's profileSend private message
lovetide


Joined: 21 Apr 2008
Posts: 0
Location: China.ShenZhen
Reply with quote
alch wrote:
could you please submit those false positive files at https://cgi.clamav.net/sendvirus.cgi Please specify it's a traditional chinese XP and put the virustotal.com result links in the comments too.

Thanks

You mean 'simplified chinese XP' is it right? Razz
The false positive virus samples are submitted. Cool

GuitarBob wrote:
For future reference: below is a link to a Chinese online file scanning site. They receive all kinds of files, of course, but you see more Chinese stuff there than on the other online scanning sites. Flower Pig is very helpful and always tries to have the latest version of ClamAV at the site.

https://virscan.org/

Regards

Thank you GuitarBob, these are the result links from VirSCAN.org:

IE7 (Simplifed Chinese version for Windows XP SP2):
https://virscan.org/report/ecd35d17f66899882b9558f5b94c5798.html https://virscan.org/report/ecd35d17f66899882b9558f5b94c5798.html

Notepad.exe (Simplifed Chinese Windows XP SP2):
https://virscan.org/report/89fe32de8587b0dfd76efce00396eb56.html https://virscan.org/report/89fe32de8587b0dfd76efce00396eb56.html

And yes, there are more chinese AV stuffs on VirSCAN.org, include Duba(金山毒霸 https://www.duba.net https://www.duba.net)、Rising(瑞星 https://www.rising-global.com https://www.rising-global.com / https://www.rising.com.cn https://www.rising.com.cn)、KV(江民杀毒 https://www.jiangmin.com https://www.jiangmin.com) , I know them, they are popular in china mainland Laughing
View user's profileSend private message
IEXPLORE.EXE: Trojan.Downloader-25397 FOUND?
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
All times are GMT  
Page 1 of 1  

  
  
 Reply to topic