1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Inactive W32/Malware!Gemini

Discussion in 'Malware and Virus Removal Archive' started by Lugwalker, 2010/12/05.

  1. 2010/12/05
    Lugwalker Lifetime Subscription

    Lugwalker Forever Autumn Thread Starter

    Joined:
    2002/01/26
    Messages:
    602
    Likes Received:
    7
    [Inactive] W32/Malware!Gemini

    Using F-Secure's online scanner on my computer, four instances of W32/Malware!Gemini were found in two programs and one in System. The programs were reputable free programs, such as eRightsoft's Super (Simplified Universal Player Encoder & Renderer) and EasyGPS, each downloaded from the owners website.

    I had recently uninstalled these programs because I discovered (with F-Secure Online) this malware in them, and then later reinstalled them again. However, I see that F-Secure online scanner has found the same malware again. I then scanned the computer with Malwarebytes (277,326 files - 3hrs 45mins) and received a totally clean result. A boot-scan with my Avast! anti-virus also revealed nothing.

    Who do I believe? Any suggestions would be appreciated. :)

    Thank you.
     
  2. 2010/12/05
    PeteC

    PeteC SuperGeek Staff

    Joined:
    2002/05/10
    Messages:
    28,896
    Likes Received:
    389
    Please read this as indicated at the head of the forum and post the logs requested in this thread.
     

  3. to hide this advert.

  4. 2010/12/05
    Lugwalker Lifetime Subscription

    Lugwalker Forever Autumn Thread Starter

    Joined:
    2002/01/26
    Messages:
    602
    Likes Received:
    7
    Thanks. It appears that I have some work to do before I get back to this thread. :)
     
  5. 2010/12/05
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
  6. 2010/12/05
    Lugwalker Lifetime Subscription

    Lugwalker Forever Autumn Thread Starter

    Joined:
    2002/01/26
    Messages:
    602
    Likes Received:
    7
    Thank you.

    I've had to reboot twice already while using gmer. It froze my desktop when trying to save the log. Third time lucky! :)
     
  7. 2010/12/05
    Lugwalker Lifetime Subscription

    Lugwalker Forever Autumn Thread Starter

    Joined:
    2002/01/26
    Messages:
    602
    Likes Received:
    7
    After going through the second stage (gmer) of the suggested procedures (for the third time) before seeking help, and having my desktop freeze for the third time when I clicked on gmer, requiring me to press the power button to exit on three occasions, I decided to remove gmer. I also had to do a system restore because everything had become snail-like after my attempts thus far.

    I decided to try Broni's suggestion. I submitted two of the files in question and here's the result:

    Super (eRightsoft) - 2 (4.7%)out of 43 antivirus engines (Cat-Quickheal & eSafe) simply reported 'Suspicious File'.

    Easy GPS - 3 out of 42 (7.1%) antivirus engines (Emsisoft, Ikarus, Clamav) reported 'PUA.packed', 'Aspack' & 'W32.suspect'.

    With so few engines reporting suspicious behaviour, might I have reason to suspect that I'm dealing with false positives here?
     
  8. 2010/12/05
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    I'm pretty sure, it's false positive.
     
  9. 2010/12/05
    Lugwalker Lifetime Subscription

    Lugwalker Forever Autumn Thread Starter

    Joined:
    2002/01/26
    Messages:
    602
    Likes Received:
    7
    Many thanks. :)
     
  10. 2010/12/05
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    You're very welcome :)
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.