rudrax Posted March 21, 2013 Share Posted March 21, 2013 Hey guys, just found something funny :lol:The virus with system file names are hidden and protected as system file. See below :Virus total result for one of them: https://www.virustotal.com/en/file/0f98dc57658a3e5176492fd1fa3e0f28ae4ad675374a95ac9b27eb2e9cd1afac/analysis/1363840768/I didn't upload the other one because I know that it will be the same as it also has the same size and behavior.So, DKT27, should I remove webroot?P.S. My 102 days of personal experience with WSA - "It may detect more false positive but never compromises" and of course, it is the lightest security suit in the planet till date. Link to comment Share on other sites More sharing options...
davhag Posted March 21, 2013 Share Posted March 21, 2013 Not DK, but I had to reformat my computer a few times because of webroot that I swore buy. Link to comment Share on other sites More sharing options...
rudrax Posted March 21, 2013 Author Share Posted March 21, 2013 Not DK, but I had to reformat my computer a few times because of webroot that I swore buy.It had a issue with win 8, now it's fixed. Link to comment Share on other sites More sharing options...
davhag Posted March 21, 2013 Share Posted March 21, 2013 Do you like WIN 8 or WIN 7 Better? Link to comment Share on other sites More sharing options...
rudrax Posted March 21, 2013 Author Share Posted March 21, 2013 Do you like WIN 8 or WIN 7 Better?Tweaked win 8 is better than win 7. Default win 8 scuks like hell. Link to comment Share on other sites More sharing options...
davhag Posted March 21, 2013 Share Posted March 21, 2013 Thanks for the advice, have been wondering what to do. Link to comment Share on other sites More sharing options...
rudrax Posted March 21, 2013 Author Share Posted March 21, 2013 Not a problem. From the side of security and speed, win 8 is better than win 7 but if you consider UI and usability, win 8 scuks, really, it does. Link to comment Share on other sites More sharing options...
Ponting Posted March 21, 2013 Share Posted March 21, 2013 First of all,how did you manage to get these virus?Use Sandboxie free or Paid version. Link to comment Share on other sites More sharing options...
xpmule Posted March 21, 2013 Share Posted March 21, 2013 did you try cleaning it up ?https://www.microsoft.com/security/portal/threat/encyclopedia/entry.aspx?Name=Worm%3AWin32%2FVB.HA&ThreatID=-2147354883 Link to comment Share on other sites More sharing options...
dcs18 Posted March 21, 2013 Share Posted March 21, 2013 First of all,how did you manage to get these virus?Use Sandboxie free or Paid version.You ain't seen nothing, yet - wait up . . . . . . . . . Link to comment Share on other sites More sharing options...
rudrax Posted March 21, 2013 Author Share Posted March 21, 2013 First of all,how did you manage to get these virus?Use Sandboxie free or Paid version.I think, some bad days in the past I was handling webroot menually. Link to comment Share on other sites More sharing options...
dcs18 Posted March 21, 2013 Share Posted March 21, 2013 Do you like WIN 8 or WIN 7 Better?Tweaked win 8 is better than win 7. Default win 8 scuks like hell.@ davhagThat's a pretty accurate fact, coming from rudrax (despite the fact that he does not use Windows 8.) :)Windows 7 is the best OS - out of the boxWindows 8 is the best OS - in the hands of an Craftsman (utterly unsuitable for the masses.)In fact, have personally seen Windows 8 forcing a lot of Users to bite the dust. :( Link to comment Share on other sites More sharing options...
dcs18 Posted March 21, 2013 Share Posted March 21, 2013 @ rudraxComing back to the topic - those 3 virii seem related to the new desktop dock that you're using. Link to comment Share on other sites More sharing options...
rudrax Posted March 21, 2013 Author Share Posted March 21, 2013 did you try cleaning it up ?https://www.microsoft.com/security/portal/threat/encyclopedia/entry.aspx?Name=Worm%3AWin32%2FVB.HA&ThreatID=-2147354883Webroot does the cleaning itself.@ rudraxComing back to the topic - those 3 virii seem related to the new desktop dock that you're using.Yeah, I knew that in the beginning that the crack of the dock contains infections. Webroot warned me but I forced it to compromise with that resulting the current situation. Link to comment Share on other sites More sharing options...
calguyhunk Posted March 21, 2013 Share Posted March 21, 2013 Yeah, I knew that in the beginning that the crack of the dock contains infections. Webroot warned me but I forced it to compromise with that resulting the current situation.I've no idea 'bout what we're dealing with here, but Malware.Gen? LOL! That's general malware heuristics that WSA is detecting. Doesn't mean a thing necessarily ;)I'm sure it'll also 'detect' most well known patches and activation programs as such ;) Link to comment Share on other sites More sharing options...
dcs18 Posted March 21, 2013 Share Posted March 21, 2013 @ calguyhunkOne is not supposed to have a system.exe file in the system32 directory. Link to comment Share on other sites More sharing options...
rudrax Posted March 21, 2013 Author Share Posted March 21, 2013 Yeah, I knew that in the beginning that the crack of the dock contains infections. Webroot warned me but I forced it to compromise with that resulting the current situation.I've no idea 'bout what we're dealing with here, but Malware.Gen? LOL! That's general malware heuristics that WSA is detecting. Doesn't mean a thing necessarily ;)I'm sure it'll also 'detect' most well known patches and activation programs as such ;)I've also posted the virustotal link. Check that out.@ calguyhunkOne is not supposed to have a system.exe file in the system32 directory.And, look at the icon. An .exe file is carrying a folder icon! But from where it has got the icon? I have modded system files replacing the icons including the folder ones. That means, it has got its own UI element for the folder icon. Link to comment Share on other sites More sharing options...
dcs18 Posted March 21, 2013 Share Posted March 21, 2013 You've configured for file extensions to stay hidden - that's asking for trouble. :think: Link to comment Share on other sites More sharing options...
rudrax Posted March 21, 2013 Author Share Posted March 21, 2013 Nope, no trouble with that. Even if I keep file extension shown, you can't see a file which is protected as a operating system file, unless you manually do that in the folder option. Link to comment Share on other sites More sharing options...
dcs18 Posted March 21, 2013 Share Posted March 21, 2013 Off-topic:Just noticed that your screenshot - your Detail Pane is upside down Link to comment Share on other sites More sharing options...
dcs18 Posted March 21, 2013 Share Posted March 21, 2013 Nope, no trouble with that. Even if I keep file extension shown, you can't see a file which is protected as a operating system file, unless you manually do that in the folder option.The biggest screw up is you end up click a virus - just because it looked like a folder. :thumbsdown:Edit:Your learning curve is taking a beating due to reluctance. :( Link to comment Share on other sites More sharing options...
SnakeMasteR Posted March 21, 2013 Share Posted March 21, 2013 Virus total result for one of them: https://www.virustotal.com/en/file/0f98dc57658a3e5176492fd1fa3e0f28ae4ad675374a95ac9b27eb2e9cd1afac/analysis/1363840768/P.S. My 102 days of personal experience with WSA - "It may detect more false positive but never compromises" and of course, it is the lightest security suit in the planet till date.Detecting an autorun worm as win32 malware.gen is just silly. Especially when i see that on avast! very often when the exe has been packed or compressed but never really contained an virus but your userinit did, obviously. :lol: Link to comment Share on other sites More sharing options...
rudrax Posted March 21, 2013 Author Share Posted March 21, 2013 Off-topic:Just noticed that your screenshot - your Detail Pane is upside downYeah, that's topshell. Other one is HUD Apocalypse. It has upside up :lol: Link to comment Share on other sites More sharing options...
rudrax Posted March 21, 2013 Author Share Posted March 21, 2013 Nope, no trouble with that. Even if I keep file extension shown, you can't see a file which is protected as a operating system file, unless you manually do that in the folder option.The biggest screw up is you end up click a virus - just because it looked like a folder. :thumbsdown:Edit:Your learning curve is taking a beating due to reluctance. :(That's not the only thing. It's just another aspect. Link to comment Share on other sites More sharing options...
rudrax Posted March 21, 2013 Author Share Posted March 21, 2013 Virus total result for one of them: https://www.virustotal.com/en/file/0f98dc57658a3e5176492fd1fa3e0f28ae4ad675374a95ac9b27eb2e9cd1afac/analysis/1363840768/P.S. My 102 days of personal experience with WSA - "It may detect more false positive but never compromises" and of course, it is the lightest security suit in the planet till date.Detecting an autorun worm as win32 malware.gen is just silly. Especially when i see that on avast! very often when the exe has been packed or compressed but never really contained an virus but your userinit did, obviously. :lol:I won't mind if my Antivirus detects an infection as a p0rnstar :lol: but I'll care to mind if it let that in the deep. Link to comment Share on other sites More sharing options...
Recommended Posts
Archived
This topic is now archived and is closed to further replies.