Author Topic: COuld this be wrong?  (Read 6797 times)

0 Members and 1 Guest are viewing this topic.

Offline .: Mac :.

  • Avast Überevangelist
  • Ultra Poster
  • *****
  • Posts: 5093
COuld this be wrong?
« on: November 30, 2004, 01:00:40 PM »
ClamWin AV detected this when I scanned my computer:

C:\WINDOWS\lpr123.exe: Worm.Gaobot.167 FOUND
-- summary --
Known viruses: 27913
Scanned directories: 5137
Scanned files: 73891
Infected files: 1
Data scanned: 16420.51 MB
I/O buffer size: 131072 bytes
Time: 14813.922 sec (246 m 53 s)


I scanned my computer with Command Antivirus and Avast and neither found anything.  Does anyone know anything about this lpr123.exe file?

I run windows update weekly so how could this be Gaobot?
"People who are really serious about software should make their own hardware." - Alan Kay

lee16

  • Guest
Re:COuld this be wrong?
« Reply #1 on: November 30, 2004, 01:09:34 PM »
Hi MAC,

Please use Jotti scanner and let us know the results, if only one anti-virus detects it, then its properly a false positive.

--lee

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31079
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re:COuld this be wrong?
« Reply #2 on: November 30, 2004, 01:25:27 PM »
Looks like the Remote Password Stealer originating from FindPassword.com.

- Connects to the remote server
- Logs keystrokes
- Runs in stealth mode
- Steals personal information

Creates the following files:
FILE:%WINDOWS%\Lpr123.exe
FILE:%WINDOWS%\Spdhook.dll
FILE:%WINDOWS%\Spd123.ini

and adds the following registry keys:
RUN:lpr
RUN:lpr123.exe

whocares

  • Guest
Re:COuld this be wrong?
« Reply #3 on: November 30, 2004, 03:08:13 PM »
This ClamAV-detection is only 2 days old:
Info
so maybe it's not too good a signature..

But please submit file to alwil, as it definitely seems suspicious




 ;)
« Last Edit: November 30, 2004, 03:08:37 PM by whocares »

Offline .: Mac :.

  • Avast Überevangelist
  • Ultra Poster
  • *****
  • Posts: 5093
Re:COuld this be wrong?
« Reply #4 on: December 01, 2004, 12:27:16 AM »
ok I will try to locate the file
"People who are really serious about software should make their own hardware." - Alan Kay

Offline .: Mac :.

  • Avast Überevangelist
  • Ultra Poster
  • *****
  • Posts: 5093
Re:COuld this be wrong?
« Reply #5 on: December 01, 2004, 01:12:24 AM »
THis is wierd, Clamwin is set to report only which it did. So why Can't I find the file? I went to the folder options and checked the show hidden files and folders option.  still could not find anything. I used the search function telling it to search in hidden files in folders and still did not find it. I even tried searching in safe mode.

I tried the following AV scanners
Avast
Antivir
House Call
Command AV
F-Secure AV (which includes the KAV engine)
"People who are really serious about software should make their own hardware." - Alan Kay

inthewildteam

  • Guest
Re:COuld this be wrong?
« Reply #6 on: December 01, 2004, 01:33:13 AM »
@ .:Mac:.

Try a registry search for the 2 values Eddy mentioned

Offline .: Mac :.

  • Avast Überevangelist
  • Ultra Poster
  • *****
  • Posts: 5093
Re:COuld this be wrong?
« Reply #7 on: December 01, 2004, 02:05:40 AM »
no there are no registry entries like that. I will contact the maker of ClamAV (alch)  and ask him why his scanner is detecting this.
"People who are really serious about software should make their own hardware." - Alan Kay

whocares

  • Guest
Re:COuld this be wrong?
« Reply #8 on: December 01, 2004, 07:43:13 PM »
Hi MAc,

try ESCAN in SafeMode: See " VirusRemoval" below for link

 ;)

Offline .: Mac :.

  • Avast Überevangelist
  • Ultra Poster
  • *****
  • Posts: 5093
Re:COuld this be wrong?
« Reply #9 on: December 02, 2004, 03:46:01 AM »
Guys Alfter talking with alch about the problem he gave me a small patch  and the version now reads 0.37.3.0.1 and the FP is gone.
"People who are really serious about software should make their own hardware." - Alan Kay