Author Topic: Help me remove this virus  (Read 2308 times)

0 Members and 1 Guest are viewing this topic.

angie20

  • Guest
Help me remove this virus
« on: May 23, 2008, 12:43:56 PM »
It's in a file from the program MEDA MP3 Splitter I downloaded more than 3 months ago. I always scan my downloads but Avast didn't find it then obviously:(

The file is:

 C:\Program Files\MEDA MP3 Splitter.joiner.exe

And here's what Virus Total scanner showed:

AhnLab-V3 2008.5.22.1 2008.05.23 -
AntiVir 7.8.0.19 2008.05.23 -
 Authentium 5.1.0.4 2008.05.22 -
Avast 4.8.1195.0 2008.05.22 -
AVG 7.5.0.516 2008.05.23 -
BitDefender 7.2 2008.05.23 -
CAT-QuickHeal 9.50 2008.05.22 -
ClamAV 0.92.1 2008.05.23 -
DrWeb 4.44.0.09170 2008.05.23 -
eSafe 7.0.15.0 2008.05.22 -
eTrust-Vet 31.4.5815 2008.05.23 -
Ewido 4.0 2008.05.22 -
F-Prot 4.4.4.56 2008.05.23 -
 
F-Secure 6.70.13260.0 2008.05.23 Backdoor.Win32.Agobot.pax
 
Fortinet 3.14.0.0 2008.05.23 -

GData 2.0.7306.1023 2008.05.23 Backdoor.Win32.Agobot.pax

Ikarus T3.1.1.26.0 2008.05.23 Virus.Win32.VB.FJU

Kaspersky 7.0.0.125 2008.05.23 Backdoor.Win32.Agobot.pax

McAfee 5301 2008.05.22 -
Microsoft 1.3520 2008.05.23 -
NOD32v2 3125 2008.05.23 -
Norman 5.80.02 2008.05.22 -
Panda 9.0.0.4 2008.05.22 -

Prevx1 V2 2008.05.23 Malicious Software

 Rising 20.45.40.00 2008.05.23 -
 
Sophos 4.29.0 2008.05.23 Sus/ComPack-C

Sunbelt 3.0.1123.1 2008.05.17 -
Symantec 10 2008.05.23 -
TheHacker 6.2.92.318 2008.05.23 -
VBA32 3.12.6.6 2008.05.22 -
VirusBuster 4.3.26:9 2008.05.22 -
 
Webwasher-Gateway 6.6.2 2008.05.23 Virus.Win32.FileInfector.gen (suspicious)


What should I do now?

Please help!!!

« Last Edit: May 23, 2008, 12:45:34 PM by angie20 »

Offline FreewheelinFrank

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 4872
  • I'm a GNU
    • Don't Surf in the Nude!
Re: Help me remove this virus
« Reply #1 on: May 23, 2008, 03:00:46 PM »
The program is available from several trusted download sites, so it looks like a false positive. I suggest you send the file to Kaspersky in a password protected zip file and mention that it's a possible false positive identification.

newvirus[at]kaspersky.com
     Bambleweeny 57 sub-meson brain     Don't Surf in the Nude Blog