Forum Home
PC World Chat
 
Thread ID: 84717 2007-11-15 23:52:00 Compaq Preloaded Trojans wainuitech (129) PC World Chat
Post ID Timestamp Content User
611860 2007-11-15 23:52:00 Here's a good one - just finished setting up a Brand new Compaq for a customer.

Brand new in the box, unpacked it, set it up, fired it up, added in user details (as you do) Installed Nod32 Antivirus, Installed the Free version of Spyware Doctor and almost INSTANTLY as it started doing its "First setup Scan" BING!! INFECTION - it said it was the Backdoor.Rbot.Aeu Trojan.

This PC had never been on the internet, the dial up account had not been created yet, or the phone line plugged in the PC.

When I got back to the workshop I doubled checked my own Install CD's just in case - all Clean.

Isn't it nice of Compaq to Ship new PC's Already Infected :D
wainuitech (129)
611861 2007-11-16 00:01:00 Its not a Seagate hdd (www.vnunet.com) by any chance is it??

Some had password stealing trojans on them.

BUT, it looks like the Maxtor Basics Personal Storage 3200 were affected.

Which I dont think this would have?
Speedy Gonzales (78)
611862 2007-11-16 00:24:00 No Idea Mate what Drive it is, but I may have to take the side off the case later to upgrade the RAM, only has 512Mb - Vista I'll Look then.

Heres What Spyware Doctor (www.pctools.com) describes the "bug"

You should have seen the look on the customers face though when the Infection Alert poped up on this brand new PC - priceless
wainuitech (129)
611863 2007-11-16 00:32:00 Hmm according to the link I posted Kaspersky detects it as this as well (vil.nai.com)

And here (www.symantec.com)

It deletes MP3's.

It'll also run on removable drives.

lol most sites say its low risk.

I bet the person who had the MP3's would think otherwise.
Speedy Gonzales (78)
611864 2007-11-16 01:28:00 But was it actually?

Not a false positive?

I've had that before.

And yesterday my helpful little anti-spyware kept deleting foxitreader.exe of my PC. The same Foxitreader thats been there for ages.

Until I updated the antispyware definitions and it finally left the poor little thing alone....
pctek (84)
611865 2007-11-16 02:04:00 But was it actually?

Not a false positive?

Until I updated the antispyware definitions and it finally left the poor little thing alone....

Hmmmm not to sure, never struck it before either. But what ever it was spyware doc dumped it.


Until I updated the antispyware definitions and it finally left the poor little thing alone.... Foxit reader is good - got the Pro version, Sounds a bit like some software I got for recovering Passwords - Nod32 thinks they are viruses, but they aren't.
wainuitech (129)
1