Two Trojans - Anyone see these???

Discussion in 'malware problems & news' started by dja2k, May 5, 2008.

Thread Status:
Not open for further replies.
  1. dja2k

    dja2k Registered Member

    Joined:
    Feb 15, 2005
    Posts:
    2,121
    Location:
    South Texas, USA
    I did a scan on a computer and saw these two trojans. Anyone seen them before, don't know if these are false positives from AVG antispyware.

    dja2k
     

    Attached Files:

  2. lordpake

    lordpake Registered Member

    Joined:
    Aug 7, 2004
    Posts:
    563
    Location:
    Helsinki ~ European Union
    Well, considering I have iTunes installed and do not have that "additunes" thingy you got there, yes I'd be concerned :) Also, there's the location, \system32\, that's kinda wrong place for normal applications to install anything.

    Just my .02€

    PS. There's always Virustotal (and Jotti) where to submit suspicious stuff for second opinion(s).
     
  3. lodore

    lodore Registered Member

    Joined:
    Jun 22, 2006
    Posts:
    9,065
    according to a quick google search they dont seem to be FP's
    do you have the online armour with KAV? if so update the av module and run a scan of the system32 folder. if not then follow the advice from the above poster about using virustotal.
     
  4. dja2k

    dja2k Registered Member

    Joined:
    Feb 15, 2005
    Posts:
    2,121
    Location:
    South Texas, USA
    Nothing else (Asquared, KAV, etc) picked those two up but only AVG antispyware did. My OA AV+ KAV definations are up to date and those two .exe's aren't even on my OA list, they haven't tried to run.

    dja2k
     
  5. lordpake

    lordpake Registered Member

    Joined:
    Aug 7, 2004
    Posts:
    563
    Location:
    Helsinki ~ European Union
    The next question is, are those legit files? For example, that additunes.exe seems to be associated with something called 3gp converter?
     
  6. dja2k

    dja2k Registered Member

    Joined:
    Feb 15, 2005
    Posts:
    2,121
    Location:
    South Texas, USA
    Now we are getting somewhere. I have some video converters, don't know if that belongs to one of them. And another related process to additunes is ATOMChanger.exe according to a google search and look how similar that is to the other apexchanger.exe.

    dja2k
     
  7. dja2k

    dja2k Registered Member

    Joined:
    Feb 15, 2005
    Posts:
    2,121
    Location:
    South Texas, USA
    Weird that I have another exe in the system32 called apexcoverter and that one isn't flagged as a trojan. Look at the attachments, nothing else picks additunes nor apexchanger as torjans.

    dja2k
     

    Attached Files:

  8. dja2k

    dja2k Registered Member

    Joined:
    Feb 15, 2005
    Posts:
    2,121
    Location:
    South Texas, USA
    Virus Total results are in the attachments. From what I see, only AVG Antispyware (ewido) shows those as trojans on both results, so they are probably false positives.

    ~VirusTotal screenshots removed per Policy. - Ron~

    dja2k
     
    Last edited by a moderator: May 5, 2008
  9. ErikAlbert

    ErikAlbert Registered Member

    Joined:
    Jun 16, 2005
    Posts:
    9,455
  10. dja2k

    dja2k Registered Member

    Joined:
    Feb 15, 2005
    Posts:
    2,121
    Location:
    South Texas, USA
  11. ErikAlbert

    ErikAlbert Registered Member

    Joined:
    Jun 16, 2005
    Posts:
    9,455
    Yes, it's a combination of 2 things.
    1. First an incomplete uninstall with leftovers.
    2. Then 2 false positives (= leftovers) reported by a scanner.
    Much ado about nothing and a waste of time, which is usually the case when scanners report false positives.
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.