koreninja
2008-08-31, 07:17
I think this may have been a false positive. The thing that scares me is that I was on mirc the day before, and now AGOBOT-KU came up (twice I think) but now it's gone.
The first time the registry change appeared was when I was installing my TI-84 calculator software, atleast I think it was. I just clicked allow without thinking because this is normal when you are installing software. Anyways, then I rebooted and noticed that popping up, looked at a little closer and saw that it was a worm. My anti-virus did not go off, I was using mirc the day before but nothing out of the ordinary was double clicked on so I don't see how the worm could have got into my system. My firewall didn't detect anything out of the ordinary, nothing named system32.exe tried to connect to the outside.
I'm going to assume it was a false positive but, not 100% sure because my laptop was acting weird for a while. I did a scan with nod32, and kaspersky and nothing came back positive. Also a scan with spybot, and checked my reg.
Was this more then likely a false positive? If it did infect my system I think nod32 would have tripped off right away, no? any ideas? My pc did start acting a bit funny until I rebooted. I'm not finding anything now though. Where should I be looking for 100% sure verification?
http://img337.imageshack.us/img337/7497/12763230dn6.jpg
The first time the registry change appeared was when I was installing my TI-84 calculator software, atleast I think it was. I just clicked allow without thinking because this is normal when you are installing software. Anyways, then I rebooted and noticed that popping up, looked at a little closer and saw that it was a worm. My anti-virus did not go off, I was using mirc the day before but nothing out of the ordinary was double clicked on so I don't see how the worm could have got into my system. My firewall didn't detect anything out of the ordinary, nothing named system32.exe tried to connect to the outside.
I'm going to assume it was a false positive but, not 100% sure because my laptop was acting weird for a while. I did a scan with nod32, and kaspersky and nothing came back positive. Also a scan with spybot, and checked my reg.
Was this more then likely a false positive? If it did infect my system I think nod32 would have tripped off right away, no? any ideas? My pc did start acting a bit funny until I rebooted. I'm not finding anything now though. Where should I be looking for 100% sure verification?
http://img337.imageshack.us/img337/7497/12763230dn6.jpg