Win32:Delall-B [Trj] in Gene6 FTP server

After the last virus definition update, I got a report on “Win32:Delall-B [Trj]” in my FTP servers.
Tried reinstalling the servers, but Avast still reports viruses in: libeay32.dll and libssl32.dll
??

To know if a file is a false positive, please submit it to JOTTI and let us know the result. If it is indeed a false positive, send it in a password protected zip to virus@avast.com

Please, mention in the body of the message why you think it is a false positive and the password used. :wink:


Could very well be a false positive as this trojan is old enough to have been in the database a couple of years at least.

Might it also be possible that there is some error with these 2 dll’s?


“JOTTI” is very busy at the moment…will try later…
The “Delall-B” was mentioned in the last definition update (0612-2) and I’ve downloaded the FTP server from Gene6 and reinstalled - same result, so it might be a false positive…

You could also check the offending/suspect file/s at: VirusTotal - Multi engine on-line virus scanner


Ok, if it was added recently, then maybe it’s a new variant. A Google search for this (Win32:Delall-B) produced results from at least 2 years ago.


JOTTI:
File: libeay32.dll
Status: MIGHT BE INFECTED/MALWARE (Sandbox emulation took a long time and/or runtime packers were found,
this is suspicious. Normally programs aren’t packed and don’t force the sandbox into lengthy emulation.
Do realize no scanner issued any warning, the file can very well be harmless. Caution is advised, however.)
MD5 eaccfcb8cb8410dffe9fc303348d902f
Packers detected: ASPACK
Scanner results
AntiVir Found nothing
ArcaVir Found nothing
Avast Found nothing
AVG Antivirus Found nothing
BitDefender Found nothing
ClamAV Found nothing
Dr.Web Found nothing
F-Prot Antivirus Found nothing
Fortinet Found nothing
Kaspersky Anti-Virus Found nothing
NOD32 Found nothing
Norman Virus Control Found nothing
UNA Found nothing
VirusBuster Found nothing
VBA32 Found nothing
*
VirusTotal: Found nothing either…
*
I’ve also tried the files from the previous version of Gene6 FTP with same results…

If you are getting a virus warning that you believe is a false positive, then if you can zip and password protect (‘virus’, will do) the suspect file and send it to virus @ avast.com (no spaces), or send from the chest.

Give a brief outline of the problem (possibly a link to this thread), the fact that you believe it to be a false positive and include the password in the body of the email. Some info on the avast version and VPS number (see about avast {right click avast icon}) will also help.

If it is indeed a false positive, add it to the exclusions lists (Standard Shield, Customize, Advanced and Program Settings, Exclusions) and check scan it periodically using the ashQuick scan (right click scan), when it is no longer detected then remove it from the exclusions.
Also see (Mini Sticky) False Positives

Done that… :slight_smile:
Thank you for your support… for now… :wink:

Hi OisteinR,

If this was the real trojan nuker it could be very destructive to your computer, read:
http://www.pestpatrol.com/zks/pestinfo/t/thrill_kill.asp

Check to see if the process mentioned there is running. Hopefully it is a FP, but make sure.

polonus

No extra processes are running. :slight_smile:

Ok OisteinR,

So much the better for you, better off without a nuker. Those are the nastiest and most destructive pieces of malware that exist. Stay malware free,

polonus

Hi OisteinR,

Just to make sure, check your particular file against the info here:
http://fileadvisor.bit9.com/services/extinfo.aspx?filename=libeay32.dll

I am almost 100% certain the checksum of your file =libeay32.dll
can be found among these, then it is fully legit and no malware.
Stay malware free, and greets,

polonus

Case closed…?
The “Delall-B” is not mentioned in the last definition update (0612-3)

…anyway, the problem does not exist anymore. :slight_smile: