Welcome to SecurityForumz.com!
FAQFAQ      ProfileProfile    Private MessagesPrivate Messages   Log inLog in

Trojan.Win32.KillFiles.nu

 
   Security Forums (Home) -> General Discussions RSS
Next:  Here we go again, more virus and spyware  
Author Message
Desert Rider

External


Since: Oct 10, 2007
Posts: 1



(Msg. 1) Posted: Wed Oct 10, 2007 12:37 pm
Post subject: Trojan.Win32.KillFiles.nu
Archived from groups: alt>comp>anti-virus (more info?)

I downloaded a patch from HP (Hewlitt Packard) for a fix for HP
Director on a HP 1310 PSC printer. I scanned the downloaded exe with
Active Virus Shield (resident), AntiVirus Lab online scanner and
Kaspersky online scanner. They all came up clean.

When I went to install the patch Active Virus Shield popped an alert
that Trojan.Win32.KillFiles.nu had been detected in the HPGPD.exe file
in the directory C:\DOCUME~1\XXXXXXX\LOCALS~1\Temp\207354\. This has
to be the a file extracted from the original patch file. I deleted the
file and obviously that aborted the install of the patch.

Is this a false positive being generated by Active Virus Shield?
Should I skip the deletion of the above file and then submit the
HPGPD.exe file to online scanners for analysis?

I confirmed that the HP site I downloaded from was a legitimate HP
site.

TIA for any comments.

 >> Stay informed about: Trojan.Win32.KillFiles.nu 
Back to top
Login to vote
kurt wismer

External


Since: Jul 04, 2003
Posts: 1562



(Msg. 2) Posted: Sat Oct 13, 2007 5:18 pm
Post subject: Re: Trojan.Win32.KillFiles.nu [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

Desert Rider wrote:
> I downloaded a patch from HP (Hewlitt Packard) for a fix for HP
> Director on a HP 1310 PSC printer. I scanned the downloaded exe with
> Active Virus Shield (resident), AntiVirus Lab online scanner and
> Kaspersky online scanner. They all came up clean.
>
> When I went to install the patch Active Virus Shield popped an alert
> that Trojan.Win32.KillFiles.nu had been detected in the HPGPD.exe file
> in the directory C:\DOCUME~1\XXXXXXX\LOCALS~1\Temp\207354\. This has
> to be the a file extracted from the original patch file. I deleted the
> file and obviously that aborted the install of the patch.
>
> Is this a false positive being generated by Active Virus Shield?
> Should I skip the deletion of the above file and then submit the
> HPGPD.exe file to online scanners for analysis?
>
> I confirmed that the HP site I downloaded from was a legitimate HP
> site.
>
> TIA for any comments.

it's impossible for us to say with certainty that it's a false positive,
but if it's definitely from hp's site then the chances of it being a
false positive are pretty good...

the best way to resolve the uncertainty would be to submit the file to
your anti-malware vendor for analysis - if it is a false alarm then they
can not only tell you but possibly even fix the problem... if it's not a
false alarm then probably they saved you from some problems down the line...

--
"it's not the right time to be sober
now the idiots have taken over
spreading like a social cancer,
is there an answer?"

 >> Stay informed about: Trojan.Win32.KillFiles.nu 
Back to top
Login to vote
Display posts from previous:   
Related Topics:
win32:trojan-gen - I am running Avast on my computer. It keeps showing that it is finding 2 viruses. win32:trojan-gen and win32:abusable system utility. I have searched and cannot find out what these 2 are or how to get rid of them. Anyone out there know? Thanks!

Win32:Trojan-gen. {Other} - how do I get rid of it? - Somehow... I've managed to get viruses on my PC. The error message I get is: Win32:Trojan-gen. {Other} (This is amongst several others.) The one above appears in C:\System Volume Information\_restore{90F... etc. I also get loads of other viruses found...

Win32.Trojan Gen - Avast found Win32.Trojan Gen on a friend's PC along with the following. C:/Windows/SYSTEM/mxflrfn.exe/[UPX] unable to scan UPX archive is corrupted C:/Windows/Temp/morphrec.exe/[UPX] unable to scan UPX archive is corrupted C:/Windows/All..

Trojan.Win32.Agent - Hi Folks..... I discovered this trojan using a-Squared.....EZ Trust, Spybot and AdAware (among a few I ran) did not alert on it. A-Squared called it "Trojan.Win32.Autoit.b" I fired the infected files off to Virus Total and got the followin...

WIN32.Briss.G Trojan help. - I think my computer is infected by the WIN32.BRISS.G trojan. Can anybody get me information or a link that explains how to get rid of the WIN32.BRISS.G Trojan. I can find information on all the other variants except the G variant. The G Variant is the...
   Security Forums (Home) -> General Discussions All times are: Pacific Time (US & Canada) (change)
Page 1 of 1

 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum



[ Contact us | Terms of Service/Privacy Policy ]