|
|
|
Win32/Genetik trojan
|
Original Message
|
Name: sgeva2001
Date: July 4, 2008 at 01:21:15 Pacific
Subject: Win32/Genetik trojanOS: XP PRO SP3CPU/Ram: Intel(R) Pentium(R) 4 CPU |
Comment: I get this alert from NOD32: " Time Module Object Name Threat Action User Information 04/07/08 06:23:36 Kernel file C:\Program Files\Replay AV 8\ReplayAV.exe probably a variant of Win32/Genetik trojan " 1. I have REPLAY program fo more then a year and now it became a threat? is it a real threat? 2. What the damage it can cause? thank you
Report Offensive Message For Removal
|
|
Response Number 2
|
Name: sgeva2001
Date: July 4, 2008 at 03:31:21 Pacific
|
Reply: (edit) A-Squared Found nothing AntiVir Found nothing ArcaVir Found nothing Avast Found nothing AVG Antivirus Found nothing BitDefender Found nothing ClamAV Found nothing CPsecure Found nothing Dr.Web Found nothing F-Prot Antivirus Found nothing F-Secure Anti-Virus Found nothing Fortinet Found nothing Ikarus Found Suspect code-parts (probable variant) Kaspersky Anti-Virus Found nothing NOD32 Found probably a variant of Win32/Genetik (probable variant) Norman Virus Control Found nothing Panda Antivirus Found nothing Sophos Antivirus Found nothing VirusBuster Found nothing VBA32 Found nothing and the conclusion: POSSIBLY INFECTED/MALWARE (Note: this file has been scanned before. Therefore, this file's scan results will not be stored in the database) (Note: this file was only flagged as malware by heuristic detection(s). This might be a false positive. Therefore, results of this scan will not be stored in the database)
Report Offensive Follow Up For Removal
|
|
Response Number 3
|
Name: btk1w1
Date: July 4, 2008 at 04:24:53 Pacific
|
Reply: (edit)It looks to be a false positive. Seeing the majority of scanners didn't recognise anything wrong with it, and the only other scan (Ikarus Found Suspect code-parts (probable variant) indicates it detected suspicious code. This more than likely has been detected through heuristic scanning which can produce false positives when the sensitivity is set too high. As far as I know NOD32 uses quite intensive heuristic scanning techniques.
Report Offensive Follow Up For Removal
|
|
Response Number 4
|
Name: sgeva2001
Date: July 4, 2008 at 04:37:35 Pacific
|
Reply: (edit) A-Squared Found nothing AntiVir Found nothing ArcaVir Found nothing Avast Found nothing AVG Antivirus Found nothing BitDefender Found nothing ClamAV Found nothing CPsecure Found nothing Dr.Web Found nothing F-Prot Antivirus Found nothing F-Secure Anti-Virus Found nothing Fortinet Found nothing Ikarus Found Suspect code-parts (probable variant) Kaspersky Anti-Virus Found nothing NOD32 Found probably a variant of Win32/Genetik (probable variant) Norman Virus Control Found nothing Panda Antivirus Found nothing Sophos Antivirus Found nothing VirusBuster Found nothing VBA32 Found nothing and the conclusion: POSSIBLY INFECTED/MALWARE (Note: this file has been scanned before. Therefore, this file's scan results will not be stored in the database) (Note: this file was only flagged as malware by heuristic detection(s). This might be a false positive. Therefore, results of this scan will not be stored in the database)
Report Offensive Follow Up For Removal
|
|
Response Number 7
|
Name: btk1w1
Date: July 4, 2008 at 06:08:49 Pacific
|
Reply: (edit)After a quick look online other posters with Win32/Genetik trojan detections had Vundo / virtumonde infections coupled with it. Most modern malware piggyback other viruses and / or trojans in with them. The Vundo malware is highly aggressive and if infected with it you definitely know. There are continuous pop-ups. Configuration settings have been changed or disabled. eg Task manager has been disabled, No access to the Run box in start menu, Control Panel removed, wallpaper and screen saver changed... are just a few of the symptoms. If you are looking for a second opinion on the health of your operating system you can run an online scan for peace of mind. A couple are listed at the link below. Step #3. http://www.computing.net/answers/se...
Report Offensive Follow Up For Removal
|
Use following form to reply to current message:
|
|

|