PDA

View Full Version : Kaspersky AVS and Bitdefender 8


Tham
March 20th, 2007, 01:00 PM
I appear to have two trojans in my System32 folder.

The free version of Kaspersky, Active Virus Shield, detected
one of them at "Xorpix.m". Bitdefender 8, their free version,
missed it.

Bitdefender 8 detected the other one as "Worm.Glowa.AR".
Kaspersk missed this though.

Antivir, Comodo, Clam, Spyware Terminator, Super Antispyware,
Asquared and Ewido missed both totally.

I'm not sure if they were false alarms though.

Escalader
March 20th, 2007, 01:32 PM
Don't know if they are FP's or not:

Best to assume they are real parasites.

You could post a HJT log but these don't get done here anymore I was told.

Over at Techguy in their security forum they do provide HJT service.

The other idea, would be get BitDefender 10 on trial and see what it finds!

danieleb
March 20th, 2007, 02:56 PM
Or try some online scanners.

plantextract
March 20th, 2007, 03:05 PM
see what www.virustotal.com has to say.

Escalader
March 20th, 2007, 08:34 PM
Both good ideas! Thanks for the link!

VahlefeldD
March 21st, 2007, 06:45 AM
Hi,
I would suggest using additional anti-malware software like Spybot or Ad-Aware to verify these trojans and use this software to clean them.
Regards...

aigle
March 21st, 2007, 07:13 AM
Hi VahlefeldD, sorry to say, the age of spybot and adaware is gone.

SuperAntispyware free &
AVG antispyware free

It wil be best to upload them to virus total and jotti.

Escalader
March 21st, 2007, 08:47 AM
Hi aigle:

Those two are sure oldies. I still use them once every 3 months or so as "infrequent"on demand scanners.

Am I am wasting my time doing even that? I think they still have updates so they aren't completely static!

In theory anyway, the thesis that they are over the hill is saying they will never find a single parasite that more current tools routinely prevent or detect. (I think that is what it means)

Moderator, this my the hill stuff may be off thread so if you need to move this post elsewhere please do...

Tham
March 21st, 2007, 01:20 PM
Thanks for the help, everyone.

I sent my files to Virus Total and many of the scanners
indicate they are indeed trojans or worms. The scan
results are attached.

I also sent them to Virus Buster. They were kind enough
to check them out for me. They confirmed the "Xorpix.m"
as "Trojan.PR.Xorpix.BR". However, they said they couldn't
analyze the "Worm.Glowa.Ar" file as it was damaged.

~Online virus scan results removed. Send any samples to the respective antivirus vendors....Bubba~

aigle
March 21st, 2007, 08:54 PM
-{ Quote: "Hi aigle:

Those two are sure oldies. I still use them once every 3 months or so as "infrequent"on demand scanners.

Am I am wasting my time doing even that? I think they still have updates so they aren't completely static!
" }-
I will not use them when I have much better choices as I stated above.
U can diusagree of course.

Tham
March 22nd, 2007, 06:00 AM
Er ...... we are not allowed to post virus scan results here ?

Firecat
March 22nd, 2007, 08:19 AM
-{ Quote: "Er ...... we are not allowed to post virus scan results here ?" }-
Yes, it is a forum policy, the reasons of which are already discussed and over with...

Escalader
March 22nd, 2007, 08:36 AM
-{ Quote: "I will not use them when I have much better choices as I stated above.
U can diusagree of course." }-

Not at all, I don't disagree. What I am wondering is my own use of them as infequent on demand tools. Just want to avoid wasting time.

I already use active SS and BD10.