server.exe. a virus yet undetected

Hi,

A few days ago, I read that server.exe is a Trojan virus (BiFrost). My computer has this and then when I scanned my PC, the scan detected nothing. So I wonder why server.exe is undetected in avast? And if anyone has a way to help me, please do. Thank you!

Please test the file at VT https://www.virustotal.com/ and post the result.

sorry for the pic. used paint

send the file to avast lab via your virus chest…open virus chest>>right click>>click add>>browse the file>>click open>>click ok to prmpt>>update virus definationations manually now to send it to them…after the next virus database update re-scan the file in chest via right clicking on it…and if it is yet not detected send it again

can u just post the link address to your virustotal results directly here please…

go ahead and i get a another layer of protection…try out Malwarebytes free scanner… www.malwarebytes.org

scan your computer once a week regularly u can go for malwarebytes pro which is great to run along side a antivirus…

Remember: no AV is 100%

Please attach your logs.
http://forum.avast.com/index.php?topic=53253.0

Thanks true_indian for the suggestion. added to virus chest and submitted to virus lab. hoping for a development in the following days

U should consider yourself to be lucky!! just by having only avast u got a trojan…it could have been something more worse :wink:

Best is it to have layered protection…see my signature for example

could you post the link to virustotal scan…as there are som info we cant see on a pic

here you go pondus

https://www.virustotal.com/file/1b058b1f7d408f3b228ab980685dd9d5aaf6568bee558f4e39a3bb8582689abf/analysis/

thanks! i traced the malware…i will report it further to avast!..

i hope you do. because while my MBAM is doing a quick scan, it detected 2 objects already. by the way I have my SuperAntiSpyware log. I will post it later

Malwarebytes Anti-Malware (Trial) 1.61.0.1400
www.malwarebytes.org

Database version: v2012.06.12.02

Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
Conrad :: ELTORO-01 [administrator]

Protection: Enabled

6/12/2012 4:44:27 PM
mbam-log-2012-06-12 (16-44-27).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 213865
Time elapsed: 5 minute(s), 57 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|HKLM (Backdoor.HMCPol.Gen) → Data: C:\Program Files\WinDir\server.exe → Quarantined and deleted successfully.

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 5
C:\WINDOWS\system32\host.exe (Trojan.Keylogger) → Quarantined and deleted successfully.
C:\WINDOWS\system32\hosthk.dll (PUP.Perflogger) → Quarantined and deleted successfully.
C:\Documents and Settings\Conrad\Start Menu\Programs\Startup\server.exe (Backdoor.RAT.Gen) → Quarantined and deleted successfully.
C:\WINDOWS\system32\inst.dat (Keylogger) → Quarantined and deleted successfully.
C:\Program Files\WinDir\server.exe (Backdoor.HMCPol.Gen) → Quarantined and deleted successfully.

(end)

Most of the stuff in your log…are the remanents of the bifrose trojan :slight_smile:

continue with the process given in link to topic by asyn

i’ve sent the sample to virus lab since it is in my virus chest. anyway, it SEEMS gone in my computer. for now… thanks for the help!