Page 1 of 2 12 LastLast
Results 1 to 10 of 14

Thread: FP - Win32.Zhelatin.k ?

  1. #1
    Security Expert-Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    3,934

    Default FP - Win32.Zhelatin.k ?

    Hiya

    I think that this is a false positive (case here):

    Win32.Zhelatin.k
    Settings
    HKEY_USERS\S-1-5-21-3293823761-4021508746-2703944788-1003\Software\Microsoft\Windows\ShellNoRoam\MUICache\x\greeting card.exe
    Seems that the ArcSoft also has a program which uses a file named "greeting card.exe". It is the same filename as Zhelatin.k uses

    MalWare Removal University - You too could train to help others
    UNITE & ASAP member since 2006

  2. #2
    Senior Member Yodama's Avatar
    Join Date
    Oct 2005
    Location
    Buchenheim
    Posts
    1,110

    Default

    hi,

    thanks for reporting, it is a false positive and will be corrected with the next update scheduled for next week.
    born in the shadow to die in the shadow, that is the fate of the shinobi

    Spybot S&D Downloads

    Please help us improve Spybot and download our distributed testing client.

  3. #3
    Security Expert-Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    3,934

    Default

    OK thank you
    MalWare Removal University - You too could train to help others
    UNITE & ASAP member since 2006

  4. #4
    Member
    Join Date
    Feb 2006
    Posts
    94

    Default Same ol' same ol'...

    Hi there. I gather Tashi's reopened this forum for me because I'm getting alerts about that trojan again. I sent the following to her:

    I had a discussion going that's now closed - http://forums.spybot.info/showthread...070458&t=15458 - and the team decided I was getting a "false positive." I'd like some reassurance please. I was told that this would be corrected in a week, but I'm still getting notifications from Spybot that I have a trojan called Win32.Zhelatin.k, with the same registry key cited. Can you confirm that this is still nothing to worry about, and that the team hasn't yet had a chance to take Win32.Zhelatin.k off its hit list?

  5. #5
    Senior Member Yodama's Avatar
    Join Date
    Oct 2005
    Location
    Buchenheim
    Posts
    1,110

    Default

    thank you for reporting,
    this will be corrected with the update this week, it looks like we skipped the trojans.sbi last week

    But you need not be concerned about detections showing MuiCache, those are actually usagetracks and will be treated as such in the near future.
    born in the shadow to die in the shadow, that is the fate of the shinobi

    Spybot S&D Downloads

    Please help us improve Spybot and download our distributed testing client.

  6. #6
    Member
    Join Date
    Feb 2006
    Posts
    94

    Default Usage tracks

    Thanks, Yodama. I'm reassured.

  7. #7
    Member
    Join Date
    Feb 2006
    Posts
    94

    Default Mystery message

    Hi Jake. Can I still post here? I want to ask about the various software packages you advised me to install (ATF Cleaner, SpywareBlaster, MVPS Hosts). I did so, and other than auto updates for firefox, windows and java nothing else has changed on my system. But this is what I've got on two separate occasions this past week:
    Windows – Virtual Memory Minimum Too Low
    Your system is low on virtual memory. Windows is increasing the size of your virtual memory paging file. During this process, memory rquests for some applications may be denied. For more information, see Help.

    I've had my computer for 6 years and never seen this alert before. I checked the help & support feature, and was advised to set my virtual memory paging file to "system managed size," so I did that. But I'm wondering why I would get that message. I tend to run about four applications at once, sometimes more, but I only had Outlook, Firefox and Word open at the time (other than the various anti-virus/-malware packages operating in the background).

    So I'm asking if any of those packages (ATF, SpywareBlaster & MVPS) could have upset my system. The last unusual thing I did was use ATF to clean out all the "selected files" yesterday. What do you think?

    (Should I be posting somewhere else?)

  8. #8
    Security Expert-Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    3,934

    Default

    Hello Benzmum

    Sorry for the delay...


    Ok the MVPS Hosts might slow your computer down especially if you didn't follow the advice in the "Editors note"-section:

    http://www.mvps.org/winhelp2002/hosts.htm

    Editors Note: in most cases a large HOSTS file (over 135 kb) tends to slow down the machine. This only occurs in W2000/XP/Vista. Windows 98 and ME are not affected.

    To resolve this issue (manually) open the "Services Editor"

    * Start | Run (type) "services.msc" (no quotes)
    * Scroll down to "DNS Client", Right-click and select: Properties
    * Click the drop-down arrow for "Startup type"
    * Select: Manual, or Disabled (recommended) click Apply/Ok and restart.
    ATF Cleaner and SpywareBlaster shouldn't slow down the computer.

    Let me know if it helped
    MalWare Removal University - You too could train to help others
    UNITE & ASAP member since 2006

  9. #9
    Member
    Join Date
    Feb 2006
    Posts
    94

    Default DNS Client

    OK, I've set the Startup type to disabled - thanks. But I'm wondering what that's got to do with Virtual Memory being too low. I understand that my machine would be slowed down if I didn't change the DNS Client setting, but I thought the alert I was getting meant I was running out of useable memory. Can you explain this for me, please?

  10. #10
    Security Expert-Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    3,934

    Default

    Hello

    When the service is enabled and running with a big hosts file it will eat tons of memory. This caused the "Virtual Memory being too low" message.

    MalWare Removal University - You too could train to help others
    UNITE & ASAP member since 2006

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •