Page 3 of 4 FirstFirst 1234 LastLast
Results 21 to 30 of 38

Thread: Virtumond + Vundo ... Very Stubborn Viruses :(

  1. #21
    Member
    Join Date
    Oct 2007
    Posts
    67

    Default

    We are onto something here!

    CPsecure
    Found Troj.W32.Agent2.cdb

    Dr.Web
    Found Tool.Prockill

    F-Secure Anti-Virus
    Found Trojan.Win32.Agent2.cdb

    Kaspersky Anti-Virus
    Found Trojan.Win32.Agent2.cdb

    Quick Heal
    Found Trojan.Agent2.cdb

    Sophos Antivirus
    Found Mal/Generic-A

    VBA32
    Found Trojan.Win32.Agent2.cdb

  2. #22
    Security Expert: Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    29,374

    Default

    Do you recognize that file?

    I research a bit and it might be part of vista transformation pack.
    Microsoft MVP Consumer Security 2008-2011

    Member of ASAP and UNITE since 2006

  3. #23
    Member
    Join Date
    Oct 2007
    Posts
    67

    Default

    I did some looking around and found someone asking the same question, here is the reply they got:

    "kay to clarify one final time. Its a false positive.

    The files are not dangerous, when downloaded from an official source.

    They will show up under a decent virus scanner as dangerous and generic trojans as they stop Windows processes and modify them, and modify dll files.

    They don't harm the files, just modify them.

    So again, one final time: There is no virus in the VTP pack when downloaded from an official source. Period."

    I did download this from the official page of the program, and its not given me any trouble since i got it a few months ago. I believe this file is okay.

  4. #24
    Member
    Join Date
    Oct 2007
    Posts
    67

    Default

    As for your question, yes, it is part of the vista transformation pack and is marked as a trojan because it modifies windows files.

  5. #25
    Security Expert: Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    29,374

    Default

    Yes I think that as well.

    Empty this folder:

    C:\Qoobox\Quarantine

    Empty Recycle Bin.

    Still problems?
    Microsoft MVP Consumer Security 2008-2011

    Member of ASAP and UNITE since 2006

  6. #26
    Member
    Join Date
    Oct 2007
    Posts
    67

    Default

    Alright, qoobox quarantine is now completely empty. But what of all the things kaspersky found in system volume information?

  7. #27
    Member
    Join Date
    Oct 2007
    Posts
    67

    Default

    In addition to that last reply, there is still a wwshow.dll file in a wwshow folder located in program files that i did not put there myself. Searched it up on google and apparently its a virus, should i just go ahead and delete that?

  8. #28
    Security Expert: Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    29,374

    Default

    Those will get deleted during final instructions.

    Entire wwshow folder is a bad, so delete it not just file.

    Still some issues?
    Microsoft MVP Consumer Security 2008-2011

    Member of ASAP and UNITE since 2006

  9. #29
    Member
    Join Date
    Oct 2007
    Posts
    67

    Default

    Just deleted the wwshow folder.

    A lot of things have improved since we started, a great difference from what it was doing before. Im not longer getting those dll errors, and there are no longer any bubbles trying to make me install false antiviruses. My CPU is running at a normal rate, things arent going slowly anymore. Im also not getting the annoying popups that i would get even when not using the internet.

    The only thing left is the occasional popup when i open my web browser, but it doesnt happen that often.

    So whats left to do here?

  10. #30
    Security Expert: Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    29,374

    Default

    In which browser those popups take place?
    Microsoft MVP Consumer Security 2008-2011

    Member of ASAP and UNITE since 2006

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •