Win32:Findbar...What is it??

I did a scan yesterday and came up with a couple of files infected with the Win32:Findbar trojan. I cannot find ANY information on ANY site about it.

Anyone else come across this one?

You will probably do better with the file name of the infected file as malware names can differe from one AV to the next.

What is the infected file name, where was it found e.g. (C:\windows\system32\infected-file-name.xxx) ? Check the avast! Log Viewer (right click the avast ‘a’ icon), Warning section, this contains information on all avast detections.

However, findbar also has the [ADW] suffix after the malware name indicating adware.

These were the files infected with the Findbar Adware:

C:_RESTORE\ARCHIVE\FS535.CAB
C:_RESTORE\ARCHIVE\FS535.CAB\W0081637.CPY
C:_RESTORE\ARCHIVE\FS1087.CAB\A0097988.CPY
C:_RESTORE\ARCHIVE\FS1087.CAB

try to send the files to jotti or virtotal :wink:

Links for VirusTotal - Multi engine on-line virus scanner I feel virustotal is the better option as it uses the windows version of avast (more packers supported) and there are currently 30 different scanners and Jotti - Multi engine on-line virus scanner if any other scanners here detect them it is less likely to be a false positive. Whichever scanner you use, you can’t do this with the file in the chest, you will need to move it out.


This was added to the avast database back in 2005. :slight_smile:

http://www.avast.com/eng/vps-content-2005.html

So, I am wondering how you managed to get this infection. ???


I didn’t used to have Avast. I used to have AVG and it never found it. I only installed Avast yesterday and did my first scan.

Sounds about right, when I switched from avg over three years ago avast found a couple of infected files that had been on my system for ages. Though you should try the virustotal scan as suggested to confirm.

Sometimes, one product fails.
Other times, other product.
There isn’t a 100% 24/7 product…