New virus (sample included) probably Sdbot

Hi, in attachment i send you a sample of virus that isn’t recognized by avast.
it is worm (probably variant of Sdbot) - generates a lot of traffic with destination port 139, when i kill process msnunin.exe this traffic stops. There was also entries in registry in Run keys to msnunin.exe.

FILE REMOVED

NEVER place a (possibly) infected file on this board nor put a link to it here.
Send it in a password protected zip to virus@avast.com and mention in the body of the mail the password and why you think it is malware.

i was trying to find such adress to report virus on avast homepage, but i couldn’t SORRY. file removed. i will post it via email as you propose.


AntiVir                          Found Worm/IRCBot.124928 
ArcaVir                         Found nothing
Avast                           Found nothing
AVG Antivirus               Found nothing
BitDefender                 Found Win32.P2P.SpyBot.2C8D68C4 
ClamAV                        Found nothing
Dr.Web                        Found Win32.HLLW.MyBot 
F-Prot Antivirus            Found nothing
Fortinet                        Found nothing
Kaspersky Anti-Virus    Found Backdoor.Win32.Rbot.gen 
NOD32                         Found Win32/Rbot 
Norman Virus Control 	Found nothing
UNA                              Found Backdoor.Rbot 
VBA32                          Found Backdoor.Win32.Rbot.gen

Movax, thanks for helping to improve avast! detection rate :wink:
Welcome to forums 8)

These are the charasteristics of this virus:
http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?id=43286

greets,

polonus