Page 3 of 4 FirstFirst 1234 LastLast
Results 21 to 30 of 33

Thread: Virtumonde.sci

  1. #21
    Junior Member Rob_39's Avatar
    Join Date
    Feb 2009
    Location
    Taxachusetts (MA)
    Posts
    22

    Default

    Yes: They are a couple of games I played a time or two. I do not use or need them now. I don't have a problem deleting them.

    Thanks again,

    Rob.....

  2. #22
    Security Expert: Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    29,374

    Default

    Thanks for information.

    We will scan them before possible deletion.

    I'd like you to check a file/some files for malware.

    G:\games\N Storm\Ricochet13\ricochet13-nstorm.exe
    G:\games\N Storm\SuperElfBowl\SuperEB.exe
    • Copy/Paste the first file on the list into the white Upload a file box.
    • Click Send/Submit, and the file will upload to VirusTotal/Jotti, where it will be scanned by several anti-virus programmes.
    • After a while, a window will open, with details of what the scans found.
    • Save the complete results in a Notepad/Word document on your desktop.
    • Repeat for all files on the list.
    • Post back results, please.
    Microsoft MVP Consumer Security 2008-2011

    Member of ASAP and UNITE since 2006

  3. #23
    Junior Member Rob_39's Avatar
    Join Date
    Feb 2009
    Location
    Taxachusetts (MA)
    Posts
    22

    Default

    Shaba:

    Loaded the first file to VirusTotal. It looked like VT may have hung, it must have crunched for 15-20 minutes before it halted. The message on the VT screen:"Current status: Not Found "

    Attempted to copy this screen and got the following:

    File ricochet13-nstorm.exe received on 02.26.2009 04:08:48 (CET)
    Current status: Loading ... queued waiting scanning finished NOT FOUND STOPPED
    Result:
    Loading server information...
    Your file is queued in position: ___.
    Estimated start time is between ___ and ___ .
    Do not close the window until scan is complete.
    The scanner that was processing your file is stopped at this moment, we are going to wait a few seconds to try to recover your result.
    If you are waiting for more than five minutes you have to resend your file.
    Your file is being scanned by VirusTotal in this moment,
    results will be shown as they're generated.
    Compact Compact
    Print results Print results
    Your file has expired or does not exists.
    Service is stopped in this moments, your file is waiting to be scanned (position: ) for an undefined time.

    You can wait for web response (automatic reload) or type your email in the form below and click "request" so the system sends you a notification when the scan is finished.
    Email:

    Antivirus Version Last Update Result
    Additional information


    I didn't see any way to type in the email request.
    Looks like I'll have to resend this file. (I did not have time to send the second file.) I won't have time to repeat this test until late Thursday night or probably Friday morning.

    Thanks again,

    Rob.....

  4. #24
    Security Expert: Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    29,374

    Default

    In that case you can try Jotti instead
    Microsoft MVP Consumer Security 2008-2011

    Member of ASAP and UNITE since 2006

  5. #25
    Junior Member Rob_39's Avatar
    Join Date
    Feb 2009
    Location
    Taxachusetts (MA)
    Posts
    22

    Default

    Hi Shaba:

    This PC seems to be running quite well, no unusual side effects observed.

    I'll probably delete these two files since I have no plans to run them in the future.

    Any suggestions you may care to offer will be appreciated.

    Jotti ran without problems but it did take a while (Jotti's web page indicated that it could take some time to finish. No surprise there. It seems it's a good resource so I've bookmarked it.)


    Thanks again,

    Rob.....


    Copy of Jotti's results for the two files in question follow:

    Jotti's malware scan 2.99-TRANSITION_TO_3.00-R1
    File to upload & scan: Virus

    Service
    Service load:
    0% 100%
    File: SuperEB.exe
    Status:
    INFECTED/MALWARE
    MD5: 157b404d55a706753ef24bd8cc3b74d7
    Packers detected:
    UPX
    Scanner results
    Scan taken on 27 Feb 2009 15:49:47 (GMT)
    A-Squared
    Found nothing
    AntiVir
    Found ADSPY/NavExcel.d.6, ADSPY/NavExcel.dll, ADSPY/NavExcel.d.5
    ArcaVir
    Found nothing
    Avast
    Found Win32:Trojan-gen {Other}, Win32:Navexcel
    AVG Antivirus
    Found Generic.TVD, Generic.OQD, Generic2.KER, Generic.UOO
    BitDefender
    Found nothing
    ClamAV
    Found Adware.Navexcel-2
    CPsecure
    Found Malware.W32.NavExel.E
    Dr.Web
    Found Adware.NavHelper
    F-Prot Antivirus
    Found nothing
    F-Secure Anti-Virus
    Found not-a-virus:AdWare.Win32.NavExcel.d (4, 1, 400), not-a-virus:AdWare.Win32.NavExcel (4, 1, 400)
    Ikarus
    Found not-a-virus:AdWare.Win32.NavExcel.d
    Kaspersky Anti-Virus
    Found not-a-virus:AdWare.Win32.NavExcel.d, not-a-virus:AdWare.Win32.NavExcel
    NOD32
    Found nothing
    Norman Virus Control
    Found nothing
    Panda Antivirus
    Found nothing
    Sophos Antivirus
    Found nothing
    VirusBuster
    Found Adware.NavExcel.AW, Adware.NavExcel.AZ
    VBA32
    Found nothing

    Powered by
    images/asquared.png images/antivir.png images/arcabit.png images/avast.png images/avg.gif images/bitdefender.png images/clamav-logo1.png images/cpsecure.gif images/drweb.gif images/f-prot.png images/f-secure_logo.gif images/ikarus.gif images/kaspersky.png images/nod32.gif images/norman.png images/panda.gif images/sophos.gif images/virusbuster.gif images/vba32.png
    Disclaimer
    This service is by no means 100% safe. If this scanner says 'OK', it does not necessarily mean the file is clean. There could be a whole new virus on the loose. NEVER rely on one single product only, not even this service, even though it utilizes several products. Therefore, We cannot and will not be held responsible for any damage caused by results presented by this non-profit online service.

    Scanning can take a while, since several scanners are being used, plus the fact some scanners use very high levels of (time consuming) heuristics. Scanners used are Linux versions, differences with Windows scanners may or may not occur. Some scanners will only report one virus when scanning archives with multiple pieces of malware.

    Virus definitions are updated every hour. There is a 10Mb limit per file. Please refrain from uploading tons of hex-edited or repacked variants of the same sample.

    Please do not ask for viruses uploaded here, unless you work for an anti-virus vendor. They are not for trade. This is a legitimate service, not a VX site. Viruses uploaded here will be distributed to antivirus vendors without exception. Read more about this in our privacy policy. If you do not want your files to be distributed, please do not send them at all.

    Sponsored by HotelScraper.com.
    Statistics
    Last file scanned at least one scanner reported something about: slika_1.exe (MD5: 81804d06b9321dcab9576840324e39c7, size: 10752 bytes), detected by:

    Scanner Malware name
    A-Squared Trojan-PWS.Win32.Agent!IK
    AntiVir TR/PSW.Agent.man
    ArcaVir X
    Avast Win32:Trojan-gen {Other}
    AVG Antivirus X
    BitDefender Trojan.Generic.1407554
    ClamAV X
    CPsecure X
    Dr.Web Trojan.PWS.Stealer.129
    F-Prot Antivirus X
    F-Secure Anti-Virus Trojan-PSW.Win32.Agent.lta
    Ikarus X
    Kaspersky Anti-Virus Trojan-PSW.Win32.Agent.lta
    NOD32 Win32/PSW.Agent.NKL
    Norman Virus Control X
    Panda Antivirus X
    Sophos Antivirus Mal/Emogen-U
    VirusBuster X
    VBA32 Trojan-PSW.Win32.Agent.lta


    You are free to (mis)interpret these automated, flawed statistics at your own discretion. For antivirus comparisons, visit AV comparatives
    We are not affiliated with any third parties that conduct tests using this service.



    Frequently asked questions - Privacy policy

    Debian

    Page generated by JTPL

    © 2004-


    Jotti's malware scan 2.99-TRANSITION_TO_3.00-R1
    File to upload & scan: Virus

    Service
    Service load:
    0% 100%
    File: ricochet13-nstorm.exe
    Status:
    INFECTED/MALWARE
    MD5: ed61a2c8490ade7164bd7c5e56778dec
    Packers detected:
    UPX
    Scanner results
    Scan taken on 27 Feb 2009 15:26:37 (GMT)
    A-Squared
    Found nothing
    AntiVir
    Found ADSPY/NavExcel.d.6, ADSPY/NavExcel.dll, ADSPY/NavExcel.d.5
    ArcaVir
    Found nothing
    Avast
    Found Win32:Trojan-gen {Other}, Win32:Navexcel
    AVG Antivirus
    Found Generic.TVD, Generic.OQD, Generic2.KER, Generic.UOO
    BitDefender
    Found nothing
    ClamAV
    Found Adware.Navexcel-2
    CPsecure
    Found Malware.W32.NavExel.E
    Dr.Web
    Found Adware.NavHelper
    F-Prot Antivirus
    Found nothing
    F-Secure Anti-Virus
    Found not-a-virus:AdWare.Win32.NavExcel.d (4, 1, 400), not-a-virus:AdWare.Win32.NavExcel (4, 1, 400)
    Ikarus
    Found not-a-virus:AdWare.Win32.NavExcel.d
    Kaspersky Anti-Virus
    Found not-a-virus:AdWare.Win32.NavExcel.d, not-a-virus:AdWare.Win32.NavExcel
    NOD32
    Found nothing
    Norman Virus Control
    Found nothing
    Panda Antivirus
    Found nothing
    Sophos Antivirus
    Found nothing
    VirusBuster
    Found Adware.NavExcel.AW, Adware.NavExcel.AZ
    VBA32
    Found nothing

    Powered by
    images/asquared.png images/antivir.png images/arcabit.png images/avast.png images/avg.gif images/bitdefender.png images/clamav-logo1.png images/cpsecure.gif images/drweb.gif images/f-prot.png images/f-secure_logo.gif images/ikarus.gif images/kaspersky.png images/nod32.gif images/norman.png images/panda.gif images/sophos.gif images/virusbuster.gif images/vba32.png
    Disclaimer
    This service is by no means 100% safe. If this scanner says 'OK', it does not necessarily mean the file is clean. There could be a whole new virus on the loose. NEVER rely on one single product only, not even this service, even though it utilizes several products. Therefore, We cannot and will not be held responsible for any damage caused by results presented by this non-profit online service.

    Scanning can take a while, since several scanners are being used, plus the fact some scanners use very high levels of (time consuming) heuristics. Scanners used are Linux versions, differences with Windows scanners may or may not occur. Some scanners will only report one virus when scanning archives with multiple pieces of malware.

    Virus definitions are updated every hour. There is a 10Mb limit per file. Please refrain from uploading tons of hex-edited or repacked variants of the same sample.

    Please do not ask for viruses uploaded here, unless you work for an anti-virus vendor. They are not for trade. This is a legitimate service, not a VX site. Viruses uploaded here will be distributed to antivirus vendors without exception. Read more about this in our privacy policy. If you do not want your files to be distributed, please do not send them at all.

    Sponsored by HotelScraper.com.
    Statistics
    Last file scanned at least one scanner reported something about: win32udp.exe (MD5: 99a874080fe88b831203a98efafd31cc, size: 28772 bytes), detected by:

    Scanner Malware name
    A-Squared X
    AntiVir HEUR/Malware
    ArcaVir X
    Avast X
    AVG Antivirus X
    BitDefender Trojan.Generic.1439180
    ClamAV X
    CPsecure X
    Dr.Web X
    F-Prot Antivirus X
    F-Secure Anti-Virus X
    Ikarus X
    Kaspersky Anti-Virus X
    NOD32 probably unknown NewHeur_PE
    Norman Virus Control X
    Panda Antivirus X
    Sophos Antivirus X
    VirusBuster X
    VBA32 X


    You are free to (mis)interpret these automated, flawed statistics at your own discretion. For antivirus comparisons, visit AV comparatives
    We are not affiliated with any third parties that conduct tests using this service.



    Frequently asked questions - Privacy policy

    Debian

    Page generated by JTPL

  6. #26
    Security Expert: Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    29,374

    Default

    Yes those are bad.

    Delete these:

    C:\Downloads\vivacam3000driver_3393.exe
    C:\Moz FF Bookmarks\PopularScreensaversSetup2.3.50.22.ZRfox000(2).exe
    C:\WINDOWS\system32\khfGyxUO.dll
    D:\Programs\Utilities\gPhotoshow
    G:\games\N Storm\Ricochet13
    G:\games\N Storm\SuperElfBowl
    I:\old New D\Games\games\Games\N-Storm\Ricochet13
    I:\old New D\Games\games\Games\N-Storm\SuperElfBow
    I:\Transfer\gPhotoshow

    Empty these folders:

    C:\Program Files\Norton SystemWorks\Norton AntiVirus\Quarantine
    C:\Qoobox\Quarantine\

    Empty Recycle Bin.

    Still problems?
    Microsoft MVP Consumer Security 2008-2011

    Member of ASAP and UNITE since 2006

  7. #27
    Junior Member Rob_39's Avatar
    Join Date
    Feb 2009
    Location
    Taxachusetts (MA)
    Posts
    22

    Default

    Hi Shaba:

    I deleted the files and folders that you indicated and cleared the Recycle Bin.

    I updated to the latest Spybot (V 1.6.2) and ran it. Spybot found three problems (1 trojan and two Windows Explorer security issues) which it corrected. I also ran Spybot Immunize. I'll load the latest AVG anti virus once we finish here. As near as I can tell this computer is now operating normally.

    Any additional recommendations or suggestions that you may care to offer would be appreciated.

    Thank you again for your patience and skillful assistance in removing the "demons"!

    Best wishes and success,

    Rob......

  8. #28
    Security Expert: Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    29,374

    Default

    Glad to hear

    Does spybot still find something upon rescan?
    Microsoft MVP Consumer Security 2008-2011

    Member of ASAP and UNITE since 2006

  9. #29
    Junior Member Rob_39's Avatar
    Join Date
    Feb 2009
    Location
    Taxachusetts (MA)
    Posts
    22

    Default

    Hi Shaba:

    The scan, that I ran after deleting the corrupt files yesterday, came up clean. This morning, I downloaded Spybot's latest definitions and performed a new scan. Results: No threats found:=) Oh Happy Day's!!

    So, it would appear that my trusty PC is back to its normal self. Monday I'll download AVG.

    Thank you so much for all your help!

    Rob....

    PS: Shut off your PC and take a few hours to enjoy some time out doors, I'm going to! Hopefully, the weather on your side of the pond will be nice:=)

  10. #30
    Security Expert: Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    29,374

    Default

    So is norton outdated or why are you going to install AVG?
    Microsoft MVP Consumer Security 2008-2011

    Member of ASAP and UNITE since 2006

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •