Virus or not Virus?

Virus or not Virus?

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Virus or not Virus? Eric 05-07-2008
  `--> Re: Virus or not Virus? PA Bear [MS MVP...05-08-2008
Posted by =?Utf-8?B?RXJpYw==?= on May 7, 2008, 6:18 am
If you were  Registered and logged in, you could reply and use other advanced thread options
When I scan my PC using F-Secure, I find no virus, but when I use the online
Norton anti-Virus, I find following infected files.

our computer is infected with at least one known virus or Trojan horse.

Search for the name of the threat(s) listed below on the Symantec Security
Response site for removal information

C:\WINDOWS\Downloaded Program Files\UERSR_0001_N91M2407NetInstaller.ex... is
infected with WinFixer
C:\WINDOWS\Downloaded Program Files\UERS_0001_N68M1801NetInstaller.exe is
infected with ErrorSafe
C:\WINDOWS\Downloaded Program Files\CONFLICT.1\UERSR_0001_N91M2407NetI... is
infected with WinFixer
C:\backup_carman\Radmin\r_server.exe is infected with Remacc.Radmin

Posted by Malke on May 7, 2008, 11:55 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Eric wrote:

> When I scan my PC using F-Secure, I find no virus, but when I use the
> online Norton anti-Virus, I find following infected files.
>
> our computer is infected with at least one known virus or Trojan horse.
>
> Search for the name of the threat(s) listed below on the Symantec Security
> Response site for removal information
>
> C:\WINDOWS\Downloaded Program Files\UERSR_0001_N91M2407NetInstaller.ex...
> is infected with WinFixer
> C:\WINDOWS\Downloaded Program Files\UERS_0001_N68M1801NetInstaller.exe is
> infected with ErrorSafe
> C:\WINDOWS\Downloaded Program Files\CONFLICT.1\UERSR_0001_N91M2407NetI...
> is infected with WinFixer
> C:\backup_carman\Radmin\r_server.exe is infected with Remacc.Radmin

I'm not a big fan of online scanning tools in general but this could be for
a couple of reasons:

1. Those files are connected with non-viral malware so it isn't surprising
that an antivirus program doesn't flag them. Perhaps F-Secure doesn't look
for non-viral malware.

2. It could be a false-positive.

I would certainly go through other malware scanning per the information
here:
http://www.elephantboycomputers.com/page2.html#Removing_Malware

Malke
--
MS-MVP
Elephant Boy Computers
www.elephantboycomputers.com
Don't Panic!

Posted by Milo on May 8, 2008, 12:18 am
If you were  Registered and logged in, you could reply and use other advanced thread options
It is not a virus to be exact it is a malware - a trojan that system has
been visiting site that prompts a preload of those rouge security
applications. Its just trying to go in your system.

Those that are in downloaded directory it means your system had made an
acquaintance with those file already someone or somehow they agreed to it
previously.

If you are using Internet Explorer 7 reset it on
on the internet option>Advance tab>reset it just to dump all possible
attached ( unauthorized apps ), you can just reinstall those that you use ex
for office or for your gaming. It's much safer than take chances.

> When I scan my PC using F-Secure, I find no virus, but when I use the
> online
> Norton anti-Virus, I find following infected files.
>
> our computer is infected with at least one known virus or Trojan horse.
>
> Search for the name of the threat(s) listed below on the Symantec Security
> Response site for removal information
>
> C:\WINDOWS\Downloaded Program Files\UERSR_0001_N91M2407NetInstaller.ex...
> is
> infected with WinFixer
> C:\WINDOWS\Downloaded Program Files\UERS_0001_N68M1801NetInstaller.exe is
> infected with ErrorSafe
> C:\WINDOWS\Downloaded Program Files\CONFLICT.1\UERSR_0001_N91M2407NetI...
> is
> infected with WinFixer
> C:\backup_carman\Radmin\r_server.exe is infected with Remacc.Radmin


Posted by PA Bear [MS MVP] on May 8, 2008, 11:36 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Milo, these are symptoms of a ZLOB infection, which is usually accompanied
by Vundo and SDBot, all of which are being protected by a rootkit. No
anti-virus or anti-spyware applications or online scans will detect and
remove all of it.
--
~PA Bear

Milo wrote:
> It is not a virus to be exact it is a malware - a trojan that system has
> been visiting site that prompts a preload of those rouge security
> applications. Its just trying to go in your system.
>
> Those that are in downloaded directory it means your system had made an
> acquaintance with those file already someone or somehow they agreed to it
> previously.
>
> If you are using Internet Explorer 7 reset it on
> on the internet option>Advance tab>reset it just to dump all possible
> attached ( unauthorized apps ), you can just reinstall those that you use
> ex
> for office or for your gaming. It's much safer than take chances.
>
>> When I scan my PC using F-Secure, I find no virus, but when I use the
>> online
>> Norton anti-Virus, I find following infected files.
>>
>> our computer is infected with at least one known virus or Trojan horse.
>>
>> Search for the name of the threat(s) listed below on the Symantec
>> Security
>> Response site for removal information
>>
>> C:\WINDOWS\Downloaded Program Files\UERSR_0001_N91M2407NetInstaller.ex...
>> is
>> infected with WinFixer
>> C:\WINDOWS\Downloaded Program Files\UERS_0001_N68M1801NetInstaller.exe is
>> infected with ErrorSafe
>> C:\WINDOWS\Downloaded Program Files\CONFLICT.1\UERSR_0001_N91M2407NetI...
>> is
>> infected with WinFixer
>> C:\backup_carman\Radmin\r_server.exe is infected with Remacc.Radmin


Similar ThreadsPosted
Re: virus January 26, 2006, 7:01 pm
A virus, or not? June 15, 2005, 9:02 pm
Virus February 22, 2006, 5:46 pm
i might have a virus... March 21, 2006, 10:40 pm
What virus is this? April 6, 2006, 10:47 am
Virus or not? May 9, 2006, 4:01 pm
says i have a virus, but cant get rid of it. September 10, 2006, 6:18 pm
virus... October 24, 2006, 6:35 am
help with virus May 22, 2007, 4:11 pm
help with virus May 22, 2007, 4:11 pm

The site map in XML format XML site map

Contact Us | Privacy Policy