Forum Home
Press F1
 
Thread ID: 97937 2009-03-05 03:13:00 Trojan? sarel (2490) Press F1
Post ID Timestamp Content User
753550 2009-03-05 03:13:00 Trojan or False Positive? I had family stay over, using the PC and when they went, found Backdoor.backdoor.64024.A, sitting in Wextract.exe, on my PC (Picked up by Spyware Terminator). Nod32 showed nothing, so I d/l'ed Avira and TrojanRemover - both negative. Restore is not enabled. Spyware Terminator can't remove it. Trojan Remover just came back negative. Same with Avira

Should I worry?

sarel
sarel (2490)
753551 2009-03-05 04:14:00 can you report false/positives in Spyware Terminator? GameJunkie (72)
753552 2009-03-05 04:14:00 Probably a false positive, as a google search shows nothing.

And wextract.exe is a legit system files anyways,(altho it could be infected)
Blam (54)
753553 2009-03-05 05:03:00 I think so - I'll report it and see. Will do another exhaustive scan tomorrow, just to be sure

sarel
sarel (2490)
753554 2009-03-05 05:22:00 Upload it here (http://www.virustotal.com/)

See what it says
Speedy Gonzales (78)
753555 2009-03-05 05:37:00 Found the following:

Antivirus Version Last Update Result

Authentium 5.1.0.4 2009.03.04 W32/Backdoor2.NYH
F-Prot 4.4.4.56 2009.03.04 W32/Backdoor2.NYH
K7AntiVirus 7.10.657 2009.03.04 Trojan.Win32.Malware.1

All the other negative
sarel (2490)
753556 2009-03-05 19:24:00 This morning I did a few more scans with on-line scanners - negative. Everything else reports it as negative on my PC. If I remove/delete the file, it reappears after about 10 secs (Windows doing it)?

Any advice - ignore? Or should I see whether I can get any remover for Trojan.Win32.Malware.1 (as reported by one of the multiscans)?

sarel
sarel (2490)
753557 2009-03-05 19:51:00 Disable system restore, reboot then delete it. Then see if it comes back

Then select all options under utilities in trojan remover
Speedy Gonzales (78)
753558 2009-03-05 20:26:00 Speedy, Restore has not been enabled for the last 6 months. Will do the rest.

sarel
sarel (2490)
753559 2009-03-05 20:39:00 Came back after 10 secs.

TR negative again - with all options

sarel
sarel (2490)
1 2