Welcome to SecurityForumz.com!
FAQFAQ      ProfileProfile    Private MessagesPrivate Messages   Log inLog in

Does my dad have a virus/worm/trojan?

 
   Security Forums (Home) -> General Discussions RSS
Next:  Program that will remove Trojan.Bookmarker.B ?  
Author Message
OzFree

External


Since: Apr 11, 2004
Posts: 2



(Msg. 1) Posted: Sun Apr 11, 2004 5:56 pm
Post subject: Does my dad have a virus/worm/trojan?
Archived from groups: alt>comp>virus (more info?)

Hi all,

My dad just emailed saying that his ZoneAlarm keeps picking up a file
called "deinst_qfe002.exe" trying to access the internet.

I did a quick google search on the name and couldn't find anything
much to let me know what this file is/does.

Is it a virus/worm/trojan?

Thanks,

Catherine

 >> Stay informed about: Does my dad have a virus/worm/trojan? 
Back to top
Login to vote
Jack the Bear

External


Since: Mar 16, 2004
Posts: 54



(Msg. 2) Posted: Mon Apr 12, 2004 12:15 am
Post subject: Re: Does my dad have a virus/worm/trojan? [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

"OzFree" <OzFree DeleteThis @despammed.com> wrote in message
news:ab25526c.0404111656.2cd7dcdd@posting.google.com...
> Hi all,
>
> My dad just emailed saying that his ZoneAlarm keeps picking up a file
> called "deinst_qfe002.exe" trying to access the internet.
>
> I did a quick google search on the name and couldn't find anything
> much to let me know what this file is/does.
>
> Is it a virus/worm/trojan?
>
> Thanks,
>
> Catherine

If I had a copy, I could give you my opinion.
Feel free to mail anything my way.
Put "ACV" in the subject somewhere to avoid my spam filters.

Jack the Bear.
jack DeleteThis @total.net

 >> Stay informed about: Does my dad have a virus/worm/trojan? 
Back to top
Login to vote
OzFree

External


Since: Apr 11, 2004
Posts: 2



(Msg. 3) Posted: Tue Apr 13, 2004 2:07 am
Post subject: Re: Does my dad have a virus/worm/trojan? [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

"Jack the Bear" <jack RemoveThis @total.net> wrote in message news:<c5d5n3$bqe$1@news.eusc.inter.net>...
> "OzFree" <OzFree RemoveThis @despammed.com> wrote in message
> news:ab25526c.0404111656.2cd7dcdd@posting.google.com...
[Deleted]
> If I had a copy, I could give you my opinion.
> Feel free to mail anything my way.
> Put "ACV" in the subject somewhere to avoid my spam filters.
>
> Jack the Bear.

Hi Jack,

Thanks for your offer. I've just emailed my dad asking him to send me
a copy of that file, and also of "winproc32.exe" which he says is also
troubling him.

Will take you up on your very kind offer just as soon as he emails me
back.

THANKYOU!

Catherine
 >> Stay informed about: Does my dad have a virus/worm/trojan? 
Back to top
Login to vote
Big Will

External


Since: Mar 30, 2004
Posts: 214



(Msg. 4) Posted: Tue Apr 13, 2004 3:04 am
Post subject: Re: Does my dad have a virus/worm/trojan? [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

OzFree wrote:

> "Jack the Bear" <jack.DeleteThis@total.net> wrote in message news:<c5d5n3$bqe$1@news.eusc.inter.net>...
>
>>"OzFree" <OzFree.DeleteThis@despammed.com> wrote in message
>>news:ab25526c.0404111656.2cd7dcdd@posting.google.com...
>
> [Deleted]
>
>>If I had a copy, I could give you my opinion.
>>Feel free to mail anything my way.
>>Put "ACV" in the subject somewhere to avoid my spam filters.
>>
>>Jack the Bear.
>
>
> Hi Jack,
>
> Thanks for your offer. I've just emailed my dad asking him to send me
> a copy of that file, and also of "winproc32.exe" which he says is also
> troubling him.
>
> Will take you up on your very kind offer just as soon as he emails me
> back.
>
> THANKYOU!
>
> Catherine
Try instead to send it to an AV vendor. I don't know which one you're
using, but you coud submit to Sophos at support @ sophos.com if you
can't think of any others.

--
William

If it don't work, hit it.
If it still don't work, kick it.
If it works after that, than it doesn't matter if that helped, what's
important is it works.
 >> Stay informed about: Does my dad have a virus/worm/trojan? 
Back to top
Login to vote
Jack the Bear

External


Since: Mar 16, 2004
Posts: 54



(Msg. 5) Posted: Tue Apr 13, 2004 4:46 pm
Post subject: Re: Does my dad have a virus/worm/trojan? [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

"OzFree" <OzFree.RemoveThis@despammed.com> wrote in message
news:ab25526c.0404130107.3247b789@posting.google.com...

> Hi Jack,

[Don't say that too loudly on an airplane]

> Thanks for your offer. I've just emailed my dad asking him to send me
> a copy of that file, and also of "winproc32.exe" which he says is also
> troubling him.
>
> Will take you up on your very kind offer just as soon as he emails me
> back.
>
> THANKYOU!
>
> Catherine

I was wondering what had happened to you/it/him/etc,

Looking forward to it.

- Jack.
 >> Stay informed about: Does my dad have a virus/worm/trojan? 
Back to top
Login to vote
Jack the Bear

External


Since: Mar 16, 2004
Posts: 54



(Msg. 6) Posted: Tue Apr 13, 2004 4:55 pm
Post subject: Re: Does my dad have a virus/worm/trojan? [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

"Big Will"
<SPAMwSPAMiSPAMlSPAMlSPAMbSPAM4SPAMeSPAMvSPAAAAAMeSPAMMITTYrSPAAAAM@nIeDONTt
LIKEzSPAMero.net> wrote in message news:407bbbbf$1@darkstar...
> OzFree wrote:
>
> > "Jack the Bear" <jack.TakeThisOut@total.net> wrote in message
news:<c5d5n3$bqe$1@news.eusc.inter.net>...
> >
> >>"OzFree" <OzFree.TakeThisOut@despammed.com> wrote in message
> >>news:ab25526c.0404111656.2cd7dcdd@posting.google.com...
> >
> > [Deleted]
> >
> >>If I had a copy, I could give you my opinion.
> >>Feel free to mail anything my way.
> >>Put "ACV" in the subject somewhere to avoid my spam filters.
> >>
> >>Jack the Bear.
> >
> >
> > Hi Jack,
> >
> > Thanks for your offer. I've just emailed my dad asking him to send me
> > a copy of that file, and also of "winproc32.exe" which he says is also
> > troubling him.
> >
> > Will take you up on your very kind offer just as soon as he emails me
> > back.
> >
> > THANKYOU!
> >
> > Catherine
> Try instead to send it to an AV vendor. I don't know which one you're
> using, but you coud submit to Sophos at support @ sophos.com if you
> can't think of any others.
>
> --
> William
>

I often do that with these, when I can't spot giveaways in the file. I find
it to be quicker, and more useful to look at them myself first, as I'll
often see regkeys and other filenames in the text segment(s) that provide
useful clues as to problems to fix. AV vendors often will eventually tell
you that the file IS malware, and that next week's Defs will detect it, but
often it could take months, if ever, for their encyclopedias to include the
new malware.

- Jack.
 >> Stay informed about: Does my dad have a virus/worm/trojan? 
Back to top
Login to vote
Ant

External


Since: Jan 31, 2004
Posts: 241



(Msg. 7) Posted: Wed Apr 14, 2004 2:43 am
Post subject: Re: Does my dad have a virus/worm/trojan? [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

"Jack the Bear" wrote...
> "Big Will" wrote...

>> Try instead to send it to an AV vendor. I don't know which one you're
>> using, but you coud submit to Sophos at support @ sophos.com if you
>> can't think of any others.

> I often do that with these, when I can't spot giveaways in the file. I find
> it to be quicker, and more useful to look at them myself first, as I'll
> often see regkeys and other filenames in the text segment(s) that provide
> useful clues as to problems to fix. AV vendors often will eventually tell
> you that the file IS malware, and that next week's Defs will detect it, but
> often it could take months, if ever, for their encyclopedias to include the
> new malware.

I have not had that experience with Sophos. They always send me an
IDE file in response to the samples I supply. I send samples in the
evening, and receive a reply the next day. If there are problems, I
can correspond with the technician who's dealing with my report.
 >> Stay informed about: Does my dad have a virus/worm/trojan? 
Back to top
Login to vote
Jack the Bear

External


Since: Mar 16, 2004
Posts: 54



(Msg. 8) Posted: Wed Apr 14, 2004 2:43 am
Post subject: Re: Does my dad have a virus/worm/trojan? [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

"Ant" <not.TakeThisOut@home.today> wrote in message
news:c5i52q$v8d$1@newsg4.svr.pol.co.uk...
> "Jack the Bear" wrote...
> > "Big Will" wrote...
>
> >> Try instead to send it to an AV vendor. I don't know which one you're
> >> using, but you coud submit to Sophos at support @ sophos.com if you
> >> can't think of any others.
>
> > I often do that with these, when I can't spot giveaways in the file. I
find
> > it to be quicker, and more useful to look at them myself first, as I'll
> > often see regkeys and other filenames in the text segment(s) that
provide
> > useful clues as to problems to fix. AV vendors often will eventually
tell
> > you that the file IS malware, and that next week's Defs will detect it,
but
> > often it could take months, if ever, for their encyclopedias to include
the
> > new malware.
>
> I have not had that experience with Sophos. They always send me an
> IDE file in response to the samples I supply. I send samples in the
> evening, and receive a reply the next day. If there are problems, I
> can correspond with the technician who's dealing with my report.
>

Sounds good. Are you a [paying] customer, or does that work "off the street"
too?

My AV will usually respond in a few hours with either/both "Looks
Suspicious" or a list of other vendors Aliases, if known. Very often this
does not translate directly to a cure, nor to the registry key shenanigans
which can often be read directly from the file.

- Jack.
 >> Stay informed about: Does my dad have a virus/worm/trojan? 
Back to top
Login to vote
Ant

External


Since: Jan 31, 2004
Posts: 241



(Msg. 9) Posted: Wed Apr 14, 2004 11:48 am
Post subject: Re: Does my dad have a virus/worm/trojan? [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

"Jack the Bear" wrote...
> "Ant" wrote...

>> I have not had that experience with Sophos. They always send me an
>> IDE file in response to the samples I supply. I send samples in the
>> evening, and receive a reply the next day. If there are problems, I
>> can correspond with the technician who's dealing with my report.
>
> Sounds good. Are you a [paying] customer, or does that work "off the
> street" too?

Indirectly I'm a customer, but they don't know that. Sophos target
their products at corporate use. The licence allows employees to use
the AV on home PCs - which I do. In other words, as long as I keep my
current job, I get to use it for free.

They don't have a free version of it, but an evaluation version is
available.

> My AV will usually respond in a few hours with either/both "Looks
> Suspicious" or a list of other vendors Aliases, if known. Very often
> this does not translate directly to a cure, nor to the registry key
> shenanigans which can often be read directly from the file.

So far Sophos has always always identified my samples, which usually
turn out to be new variants of existing trojans. They give me details
of what the malware does, and what registry keys are involved.
 >> Stay informed about: Does my dad have a virus/worm/trojan? 
Back to top
Login to vote
Display posts from previous:   
Related Topics:
Protection from a Virus, Worm, Backdoor or Trojan Horse - If your computer is a on a Windows Platform you need to disable the Services that Windows leaves opens, for starters. Most home users aren't using a Virtual Private Network, Mail Server, FTP Server, TCP Server and so on. You also need to install a..

Request for examples of mixed virus-worm-trojan malware - Hi everyone, I am currently preparing a paper about malware. I would appreciate very much examples of mixed malware entities, i.e. showing at the same time features of viruses, worms, trojans, adware, spyware, etc... I am already gathering this..

trojan or worm or something - Does anyone know of any trojan or worm or something that's supposed to start today. Since 9:26:01, I have received some 36 attacks of subseven trojan horse, all different IP's. William

Trojan Virus? - Hi, a friend of mine has booked a ticket for a concert and a few minutes later it was booked again. When he complained to the ticket-company and said that he only ordered one ticket and asked why they charged him two, they said that it was booked twice....

Virus/Trojan question - Virus/Trojan question I am working on a friend's PC (Windows 2k Pro. w/sp 1) and I believe he has a virus or trojan. Can anyone help me identify the culprit? Here are the symptoms: 1. I can not see ANY files or folders in C:\Winnt or below..
   Security Forums (Home) -> General Discussions All times are: Pacific Time (US & Canada) (change)
Page 1 of 1

 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum



[ Contact us | Terms of Service/Privacy Policy ]