Giveaway of the Day Forums » Talks

Review Trojan/Virus Reports

(105 posts)

  1. You're right RunesageMagi, sometimes they do have a re-run on the giveaway, It's great if you missed a giveaway and really want it, but if you really want it you should go buy it.

    Posted 3 months ago #
  2. graylox
    Member

    Trojan horse in Wondershare Photo Story Platinum?

    please look here:

    http://www.giveawayoftheday.com/forums/topic/2476?replies=10

    Posted 3 months ago #
  3. I am quite upset that I got this trojan when downloading form your site. My virus scan told me that it loaded with Inca Ball. It seems to be very persistant. I am not a techy so this is not good for me. Now what do I do and do I continue to trust this web site?

    Posted 2 months ago #
  4. jhaber77
    Member

    I am concerned about Media Resizer PRO (GAOTD of January 2nd, 2008):

    In folder:
    C:\Program Files\Media Resizer PRO

    The file:
    shell file list.lst
    seems to be updated even if I do not use the software.
    the file "date-modified" is updated often by itself.

    Does it mean that the Media Resizer PRO software (or part of it) is loaded during boot without me activating it?

    I do not want software to load my system unless I intentionally load it.
    Any advice?

    My OS is Win XP.

    Posted 2 months ago #
  5. I have also noticed this softwares odd behaviour.

    I have my programs folder in a sequence of last modified > show in groups.

    I installed it when it was offered here, firstly then when the updated version v2.58 came along.

    It seems to stay as one of the last modified folders.

    I am currently trying to link it to see if when I say install a graphics application, sometimes they ask to be a default application for certain files.

    I am yet to conclude if this is affecting media re-sizer pro.

    Posted 2 months ago # | Login to Send PM
  6. jhaber77
    Member

    Thank you for your reply.
    Maybe GAOTD could access the software vendor and ask him?
    If this software loads itself to the system against the user preference, then I would rather uninstall it.
    Regards

    Posted 2 months ago #
  7. copmom
    Member

    I'm running AVG and it just picked up a trojan horse from Vidmorph.exe .. says" backdoor, hupigon3.arcw .. just thought I'd pass this on for what it's worth! I do believe I got this from GOTD awhile back.

    Posted 2 months ago #
  8. My first reaction (and years of experience) as soon as I see a virus report and AVG mentioned - I immediately think "false positive".

    can I ask you to disable your antivirus (and on-access checking) which will allow you to upload the file for checking. If the file is infected you only need worry if you actually execute/run the program - just selecting the file and loading it to a website should not matter.

    Please upload to

    http://virusscan.jotti.org/

    as the above can often be busy, an alternative

    http://www.virustotal.com/metodos.html

    you can either upload or email the file (check the instructions for email)

    If you could make a note of the results. Often you can tell from some of the "better AV products" and the general consensus across the products overall as to whether the file is a false positive or not.

    You should check with AVG for the procedure to provide them with the file so they can correctly classify the file.

    After all this - Don't forget to turn your AntiVirus scanning back on again.

    Posted 2 months ago # | Login to Send PM
  9. turkishvan007
    Member

    I use Norton online protection and antivirus tool, I have AnVir Task Manager and Mamutu. My Norton is updated daily and is current. I'm running Windows XP SP2.

    My system found the trojan Hacktool.Rootkit in Robotask idlehook.dll yesterday/today and in my easttec backup files under the Robotask product backup. I downloaded Robotask and haven't used it since I downloaded it on September 28, 2007 and east tec backup was used October 12, 2007. Norton Antivirus did not find this trojan until this mornings scan so the trojan ended up in this file somehow but I don't know how.

    I'm not saying this virus was downloaded in Robotask or EastTec Backup's original download from GAOTD because I routinely do full system Virus Scans (once a week) and quick scans whenever I restart my computer and they haven't been found until now. What I'm saying is to please do a full system scan on your computer to make sure you catch this trojan if your computer has somehow received it. The trojan has been removed from my computer as of this morning.

    Symatec provided this information on the Trojan.

    Hacktool.RootkitRisk Level 1: Very LowPrinter Friendly Page
    SUMMARY TECHNICAL DETAILS REMOVAL Discovered: September 27, 2001
    Updated: February 13, 2007 11:38:00 AM
    Type: Trojan Horse
    Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP

    Hacktool.Rootkit comprises a set of programs and scripts that work together to allow attackers to break into a system. If Hacktool.Rootkit is detected on a system, it is very likely that an attacker has gained complete control of that system. All files that are detected as Hacktool.Rootkit should be deleted. Infected systems may need to be restored from backups or patched to restore security.

    Rootkits first appeared on the UNIX operating system. Administrator/Superuser accounts on UNIX systems are called root. Rootkits are kits of programs that are designed to gain root access on a system. The term rootkit now refers to any set of tools that can be used to gain unauthorized access to a system.
    ProtectionInitial Rapid Release version September 27, 2001
    Latest Rapid Release version March 24, 2008 revision 004
    Initial Daily Certified version September 27, 2001 revision 007
    Latest Daily Certified version March 24, 2008 revision 005
    Initial Weekly Certified release date September 27, 2001
    Click here for a more detailed description of Rapid Release and Daily Certified virus definitions.

    Threat AssessmentWildWild Level: Medium
    Number of Infections: More than 1000
    Number of Sites: More than 10
    Geographical Distribution: Low
    Threat Containment: Easy
    Removal: Moderate
    DamageDamage Level: Medium
    DistributionDistribution Level: Low

    Writeup By: Jimmy Shah

    Hope this helps someone else out.

    Posted 1 month ago #
  10. Thebeo
    Member

    After installing iBizCard, Avira Antivir detects trojan "TR/Crypt.XPACK.Gen".
    Please look in to this.

    Posted 2 weeks ago #
  11. iBizCard_Studio
    Member

    our product "ibizcard" have not any virus, it's 100% Clean
    download3k.com Antivirus Report: http://www.download3k.com/Antivirus-Report-iBizCard.html
    softpedia.com Antivirus Report: http://www.softpedia.com/progClean/iBizCard-Clean-98324.html
    to Thebeo:I will contact Avira to Correct this wrong virus report.

    Posted 2 weeks ago #
  12. Thebeo
    Member

    to iBizCard_Studio, for your information.
    The program Bizcard.exe creates a Temp directory "E_4". In this directory it creates al kind of files. One of them is identified as the Trojan. Maybe this narrows the search to the problem.

    Posted 2 weeks ago #
  13. iBizCard_Studio
    Member

    Thebeo:Thank you for your report. we will contact Avira and deal with this problem as soon as possible.Please set assured,our produc is 100% Clean

    download3k.com Antivirus Report: http://www.download3k.com/Antivirus-Report-iBizCard.html
    softpedia.com Antivirus Report: http://www.softpedia.com/progClean/iBizCard-Clean-98324.html

    Posted 2 weeks ago #
  14. OiMack
    Member

    Same problem here. After installing iBizCard Bitdefender found two infected files in the E_4 directory. Both infected with Trojan.Peed.Gen.
    The files are
    - EXMLParser.fne
    - shell.fne

    Posted 2 weeks ago #
  15. zubterfuge
    Member

    The Myspace Editor had a "trojen.adclick" and I was using NAV. The virus isn't found until after the product is installed. How disappointing.

    Posted 3 days ago #

RSS feed for this topic

Reply

You must log in to post.