Author Topic: winxp sp2 and Win32:Trogen-gen again  (Read 7306 times)

0 Members and 1 Guest are viewing this topic.

aquaOS

  • Guest
winxp sp2 and Win32:Trogen-gen again
« on: March 21, 2004, 06:13:24 AM »
ok peoples (u just gotta love that word), here's an intersting twist to the really wierd Win32:Trojan-gen. {VC} reports. I have windows xp sp2 beta, and now avast! home says basically every windows update file is infected with Win32:Trojan-gen. {VC}

Dialog info box:

Virus name: Win32:Trojan-gen. {VC}
File Name: C:\Program Files\Common files\updmgr\simgr.exe
VPS Version: 0403-15, 03/19/2004


WinXP Version: Version 5.1.2600 (2600 indicates SP2 build)

now all i gotta do i to keep hitting OK until someone comes up with a solution, DOH  :'(

aquaOS

  • Guest
Re:winxp sp2 and Win32:Trogen-gen again
« Reply #1 on: March 21, 2004, 07:40:29 AM »
OK, DIS REGARD THIS POST!!!


to mods & admins: pls delete me!!! sry   :-[

Offline Vlk

  • Avast CEO
  • Serious Graphoman
  • *
  • Posts: 11658
  • Please don't send me IM's. Email only. Thx.
    • ALWIL Software
Re:winxp sp2 and Win32:Trogen-gen again
« Reply #2 on: March 21, 2004, 08:52:45 AM »
Why should we disregard the post? The XP2 file is still being detected as a virus, isn't it?

So I guess we should definitely do something about it.

Thanks for your report,
Vlk
If at first you don't succeed, then skydiving's not for you.

whocares

  • Guest
Re:winxp sp2 and Win32:Trogen-gen again
« Reply #3 on: March 21, 2004, 06:26:58 PM »
Hi,

i think the legit MS-Updater is called wupdmgr.exe (at least on Win2000; is this different on XP/SP2 ?)

aquaOS

  • Guest
Re:winxp sp2 and Win32:Trogen-gen again
« Reply #4 on: March 21, 2004, 10:48:01 PM »
yes, but i checked the source of the EXE (opened with Notepad) and i'll post the human-readable data in the next reply. And yes, whocares is right, the legit updater has a different name. Well, if i see more virus reports on LEGIT winXP SP2 files, i'll post them... :)

aquaOS

  • Guest
Re:winxp sp2 and Win32:Trogen-gen again
« Reply #5 on: March 21, 2004, 10:56:05 PM »
oklidokili neighbourinos, here's the readable part of the EXE (as attachment)

interfaces with ASPX file and downloads something...

i'll see what u think ;)