Computing.Net > Forums > Security and Virus > Win32/Genetik trojan

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

Win32/Genetik trojan

Reply to Message Icon

Name: sgeva2001
Date: July 4, 2008 at 01:21:15 Pacific
OS: XP PRO SP3
CPU/Ram: Intel(R) Pentium(R) 4 CPU
Comment:

I get this alert from NOD32:
"
Time Module Object Name Threat Action User Information
04/07/08 06:23:36 Kernel file C:\Program Files\Replay AV 8\ReplayAV.exe probably a variant of Win32/Genetik trojan
"
1. I have REPLAY program fo more then a year and now it became a threat? is it a real threat?
2. What the damage it can cause?

thank you



Sponsored Link
Ads by Google

Response Number 1
Name: btk1w1
Date: July 4, 2008 at 02:54:45 Pacific
Reply:

I would use jotti to get a comprehensive scan from multple AV engines.

This might help you to rule out a false positive or assess the threat level it poses.

Click here to go to Jotti Online Malware Scanner

It is designed to scan single files.

Upload the ReplayAV.exe


0

Response Number 2
Name: sgeva2001
Date: July 4, 2008 at 03:31:21 Pacific
Reply:

A-Squared
Found nothing
AntiVir
Found nothing
ArcaVir
Found nothing
Avast
Found nothing
AVG Antivirus
Found nothing
BitDefender
Found nothing
ClamAV
Found nothing
CPsecure
Found nothing
Dr.Web
Found nothing
F-Prot Antivirus
Found nothing
F-Secure Anti-Virus
Found nothing
Fortinet
Found nothing
Ikarus
Found Suspect code-parts (probable variant)
Kaspersky Anti-Virus
Found nothing
NOD32
Found probably a variant of Win32/Genetik (probable variant)
Norman Virus Control
Found nothing
Panda Antivirus
Found nothing
Sophos Antivirus
Found nothing
VirusBuster
Found nothing
VBA32
Found nothing

and the conclusion:
POSSIBLY INFECTED/MALWARE (Note: this file has been scanned before. Therefore, this file's scan results will not be stored in the database) (Note: this file was only flagged as malware by heuristic detection(s). This might be a false positive. Therefore, results of this scan will not be stored in the database)


0

Response Number 3
Name: btk1w1
Date: July 4, 2008 at 04:24:53 Pacific
Reply:

It looks to be a false positive.

Seeing the majority of scanners didn't recognise anything wrong with it, and the only other scan (Ikarus
Found Suspect code-parts (probable variant) indicates it detected suspicious code.

This more than likely has been detected through heuristic scanning which can produce false positives when the sensitivity is set too high.

As far as I know NOD32 uses quite intensive heuristic scanning techniques.


0

Response Number 4
Name: sgeva2001
Date: July 4, 2008 at 04:37:35 Pacific
Reply:

A-Squared
Found nothing
AntiVir
Found nothing
ArcaVir
Found nothing
Avast
Found nothing
AVG Antivirus
Found nothing
BitDefender
Found nothing
ClamAV
Found nothing
CPsecure
Found nothing
Dr.Web
Found nothing
F-Prot Antivirus
Found nothing
F-Secure Anti-Virus
Found nothing
Fortinet
Found nothing
Ikarus
Found Suspect code-parts (probable variant)
Kaspersky Anti-Virus
Found nothing
NOD32
Found probably a variant of Win32/Genetik (probable variant)
Norman Virus Control
Found nothing
Panda Antivirus
Found nothing
Sophos Antivirus
Found nothing
VirusBuster
Found nothing
VBA32
Found nothing

and the conclusion:
POSSIBLY INFECTED/MALWARE (Note: this file has been scanned before. Therefore, this file's scan results will not be stored in the database) (Note: this file was only flagged as malware by heuristic detection(s). This might be a false positive. Therefore, results of this scan will not be stored in the database)


0

Response Number 5
Name: btk1w1
Date: July 4, 2008 at 04:41:10 Pacific
Reply:

Heya sgeva2001,

You've double posted, read response #3.


0

Related Posts

See More



Response Number 6
Name: sgeva2001
Date: July 4, 2008 at 04:42:50 Pacific
Reply:

than you for your help.
I will treat it as false positive.
What is the typical behaviorof/damage of Win32/Genetik trojan?


0

Response Number 7
Name: btk1w1
Date: July 4, 2008 at 06:08:49 Pacific
Reply:

After a quick look online other posters with Win32/Genetik trojan detections had Vundo / virtumonde infections coupled with it. Most modern malware piggyback other viruses and / or trojans in with them.

The Vundo malware is highly aggressive and if infected with it you definitely know. There are continuous pop-ups. Configuration settings have been changed or disabled. eg Task manager has been disabled, No access to the Run box in start menu, Control Panel removed, wallpaper and screen saver changed... are just a few of the symptoms.

If you are looking for a second opinion on the health of your operating system you can run an online scan for peace of mind.

A couple are listed at the link below. Step #3.

http://www.computing.net/answers/se...


0

Response Number 8
Name: sgeva2001
Date: July 4, 2008 at 06:21:15 Pacific
Reply:

yooo!!
thank you again.
You give me a great help & explanation.


0

Sponsored Link
Ads by Google
Reply to Message Icon






Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home


Sponsored links

Ads by Google


Results for: Win32/Genetik trojan

win32/genetik trojan www.computing.net/answers/security/win32genetik-trojan/20324.html

Win32/Genetik Trojan..Need Help www.computing.net/answers/security/win32genetik-trojanneed-help/21895.html

Infection with Win32/Genetik trojan www.computing.net/answers/security/infection-with-win32genetik-trojan/20508.html