Author Topic: urgent help on possible virus  (Read 8166 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
urgent help on possible virus
« on: December 17, 2014, 01:55:44 PM »
So someone puts a link to a game on my steam profile, since i have avast sandbox i thought who cares why not, so i opened the exe with avast sandbox instant virus warning then my avast was oddly turned off, and i got a notification that it wanted to turned off even though it already was?

Anyway here is the virus analysis, avast did not detect anything my pc works fine now avast works fine after a reboot and no virus is detected with either malwarebytes or avast should i worry? or should i reformat i would apreeciate a response as soon as possible

i use avast internet security


Antivirus   Result   Update
ALYac   Gen:Variant.Zusy.117925   20141217
Ad-Aware   Gen:Variant.Zusy.117925   20141217
BitDefender   Gen:Variant.Zusy.117925   20141217
DrWeb   Trojan.PWS.UFR.3856   20141217
ESET-NOD32   a variant of MSIL/TrojanDownloader.Small.PX   20141217
Emsisoft   Gen:Variant.Zusy.117925 (B)   20141217
GData   Gen:Variant.Zusy.117925   20141217
Ikarus   Trojan-Downloader.MSIL.Small   20141217
MicroWorld-eScan   Gen:Variant.Zusy.117925   20141217
NANO-Antivirus   Trojan.Win32.Small.djrxno   20141217

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31079
  • Watching (over?) you
    • Malware removal, Biljart and other things.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37533
  • Not a avast user
Re: urgent help on possible virus
« Reply #2 on: December 17, 2014, 02:00:36 PM »
Quote
Antivirus   Result   Update
ALYac   Gen:Variant.Zusy.117925   20141217
Ad-Aware   Gen:Variant.Zusy.117925   20141217
BitDefender   Gen:Variant.Zusy.117925   20141217
DrWeb   Trojan.PWS.UFR.3856   20141217
ESET-NOD32   a variant of MSIL/TrojanDownloader.Small.PX   20141217
Emsisoft   Gen:Variant.Zusy.117925 (B)   20141217
GData   Gen:Variant.Zusy.117925   20141217
Ikarus   Trojan-Downloader.MSIL.Small   20141217
MicroWorld-eScan   Gen:Variant.Zusy.117925   20141217
NANO-Antivirus   Trojan.Win32.Small.djrxno   20141217
always post link to scan result, as there are lots of info we cant see when you just copy and paste


REDACTED

  • Guest
Re: urgent help on possible virus
« Reply #3 on: December 17, 2014, 02:11:06 PM »
Quote
Antivirus   Result   Update
ALYac   Gen:Variant.Zusy.117925   20141217
Ad-Aware   Gen:Variant.Zusy.117925   20141217
BitDefender   Gen:Variant.Zusy.117925   20141217
DrWeb   Trojan.PWS.UFR.3856   20141217
ESET-NOD32   a variant of MSIL/TrojanDownloader.Small.PX   20141217
Emsisoft   Gen:Variant.Zusy.117925 (B)   20141217
GData   Gen:Variant.Zusy.117925   20141217
Ikarus   Trojan-Downloader.MSIL.Small   20141217
MicroWorld-eScan   Gen:Variant.Zusy.117925   20141217
NANO-Antivirus   Trojan.Win32.Small.djrxno   20141217
always post link to scan result, as there are lots of info we cant see when you just copy and paste

i sent you a pm with the link thankyou

ok here it is

https://www.virustotal.com/en/file/1cf68de50488ff53d75967c1ba5da05fa119320f0de6114f9bc220978464f862/analysis/1418822036/

according to properties of the file it used to be called pvp.ganker.exe

i also did a malwarebytes rootkit scan checking the rootkit box but still nothing found

« Last Edit: December 17, 2014, 02:18:50 PM by zzcool »

REDACTED

  • Guest
Re: urgent help on possible virus
« Reply #4 on: December 17, 2014, 02:48:22 PM »
asw log

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: urgent help on possible virus
« Reply #5 on: December 17, 2014, 03:02:26 PM »
We need FRST the most..
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

REDACTED

  • Guest
Re: urgent help on possible virus
« Reply #6 on: December 17, 2014, 03:14:10 PM »
here

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: urgent help on possible virus
« Reply #7 on: December 17, 2014, 03:51:58 PM »
Holy crap... You have a lot of torrents!!

Also, can you uninstall PunkBuster? It's classified as Spyware.
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37533
  • Not a avast user
Re: urgent help on possible virus
« Reply #8 on: December 17, 2014, 03:55:34 PM »
one frst log is missing ...... additional.txt    attach that also


Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: urgent help on possible virus
« Reply #9 on: December 17, 2014, 03:58:15 PM »
And Shortcut.txt, as I see you have that too.
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

REDACTED

  • Guest
Re: urgent help on possible virus
« Reply #10 on: December 17, 2014, 07:21:09 PM »
Damm sorry I fell asleep ok I will add those

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: urgent help on possible virus
« Reply #11 on: December 17, 2014, 07:47:05 PM »
Nothing readily apparent so far, are you having any problems

REDACTED

  • Guest
Re: urgent help on possible virus
« Reply #12 on: December 17, 2014, 07:51:11 PM »
well i still have the final files to attach

REDACTED

  • Guest
Re: urgent help on possible virus
« Reply #13 on: December 17, 2014, 07:51:48 PM »
and shortcut (i was not able to attach all of them at once

and no the pc works perfect nothing no but i worry that i might have a keylogger now or someone spying on it so yeah avast works fine too

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: urgent help on possible virus
« Reply #14 on: December 17, 2014, 08:57:32 PM »
They also look good