HardwareHeaven.com
Looking for the skin chooser?
 
 
  • Home

  • Reviews

  • Articles

  • News

  • Tools

  • GamingHeaven

  • Forums

  • Network

 

Go Back   HardwareHeaven.com > Forums > Graphics Cards > AMD Radeon Drivers > Windows XP Radeon Display Drivers


Windows XP Radeon Display Drivers The official Omegadrive support forum. Also discuss ATI's Catalyst Control Center and windows drivers here.

Reply
 
Thread Tools
Old Sep 9, 2005, 04:38 PM   #1
DriverHeaven Newbie
 
Join Date: Apr 2005
Posts: 5
Rep Power: 0
Pelk is on a distinguished road

Trojan in omega 5.7??

How come that when i ran my antivirus today it found a Trojan Horse Downloader.agent.xs in the installation file for omegadriver 5.7?(2653). Can the virus has come there after i downloaded the file because ive been having it quite long now and i have scanned for virus before but then it didnt find anything.strange. However i deleted the file, but do you know if this virus may still be on the computer? I used Avg but maybe there is some better free antivirus.

Ps:my english may not be the best
Pelk is offline   Reply With Quote


Old Sep 9, 2005, 04:43 PM   #2
DriverHeaven Senior Member
 
Join Date: Jun 2003
Location: USA
Posts: 2,761
Rep Power: 0
Warpy is on a distinguished road

Donator
Perhaps your pc is infected with a virus and has infected any exe files that you run... I'd say if this file was in fact infected with a nasty virus, you would be one of thousands with this problem. Perhaps run a virus scan on your PC and an adaware scan too.

Adaware

Spybot S+D
__________________

The nine most terrifying words in the English language are, "I'm from the government and I'm here to help."

Last edited by Warpy; Sep 9, 2005 at 05:00 PM.
Warpy is offline   Reply With Quote
Old Sep 9, 2005, 04:46 PM Threadstarter Thread Starter   #3
DriverHeaven Newbie
 
Join Date: Apr 2005
Posts: 5
Rep Power: 0
Pelk is on a distinguished road

I found the virus when i ran a virus scan, then i deleted it. Im runing it again to see if it find anything more. I didnt find anything with adaware, so if i dont find it with avg the second time can i consider it to be gone then? or is it something more i can do?
Pelk is offline   Reply With Quote
Old Sep 9, 2005, 04:53 PM   #4
DriverHeaven Senior Member
 
Join Date: Jun 2003
Location: USA
Posts: 2,761
Rep Power: 0
Warpy is on a distinguished road

Donator
Quote:
Originally Posted by Pelk
I found the virus when i ran a virus scan, then i deleted it. Im runing it again to see if it find anything more. I didnt find anything with adaware, so if i dont find it with avg the second time can i consider it to be gone then? or is it something more i can do?
There are free online scans that I'd recommend like this one: Trend Micro Scan , and this one: Norton Scan

Run the adaware and S+D, reboot your PC when the scan is compete and then run the online scan with that link I gave you, then you should be clear.
__________________

The nine most terrifying words in the English language are, "I'm from the government and I'm here to help."

Last edited by Warpy; Sep 9, 2005 at 05:00 PM.
Warpy is offline   Reply With Quote
Old Sep 9, 2005, 07:47 PM   #5
HardwareHeaven Extreme Member
 
The_Neon_Cowboy's Avatar
 
Join Date: Dec 2002
Location: U.S.A.
Posts: 16,009
Rep Power: 90
The_Neon_Cowboy is a jewel in the roughThe_Neon_Cowboy is a jewel in the roughThe_Neon_Cowboy is a jewel in the rough
System Specs

Just a side notes:

1) make sure you download things from offical mirrors or god knows
what people can pack inside.

2)Also that it can be a false positive wich hapen frequently with the more
abscure antiviruses

3) be careful the sites you visit, some use expolits in IE to load crap on your pc silently.
__________________
The_Neon_Cowboy is offline   Reply With Quote
Old Sep 10, 2005, 05:14 AM   #6
DriverHeaven Lover
 
Join Date: Jan 2005
Location: New York
Posts: 225
Rep Power: 0
sc3000 is on a distinguished road

This is the ultimate online scanner, http://www.pandasoftware.com/products/activescan.htm
sc3000 is offline   Reply With Quote
Old Sep 10, 2005, 06:29 AM   #7
DriverHeaven Extreme Member
 
Join Date: May 2005
Posts: 6,794
Rep Power: 0
H3X4D3C1M4L will become famous soon enoughH3X4D3C1M4L will become famous soon enough

Quote:
Originally Posted by The_Neon_Cowboy
2)Also that it can be a false positive wich hapen frequently with the more
abscure antiviruses
A false positive in this case would be more widespread because it would contain a binary sequence that's universal to all packages and if it resembled a virus, obscure or not, I'm sure more people would notice.
H3X4D3C1M4L is offline   Reply With Quote
Old Sep 10, 2005, 06:48 PM Threadstarter Thread Starter   #8
DriverHeaven Newbie
 
Join Date: Apr 2005
Posts: 5
Rep Power: 0
Pelk is on a distinguished road

I used the online scanner that sc3000 recommended and it found 2 things that none of the others found. It was in the category "hacking tools" and it was found in a hidden map ( C:/windows/system/driver). The file was named ntsrv.exe. i couldnt remove it or anything with the program and even if i scan that exact file with AVG it finds no virus. I dont really know if its good to just delete the file. I cant really remember where the other file was but i will check it out.


EDIT:The other one was found in C:\windows\system32\dllcache\win32 and was called psshutdown.exe. The description for the file was: shutdown,logoff and power manage local and remote systems. The company was www.sysinternal.com .

Anyone knows what i should do with these files? is it safe to delete them?

Last edited by Pelk; Sep 10, 2005 at 07:18 PM.
Pelk is offline   Reply With Quote
Old Sep 12, 2005, 05:50 PM   #9
Drivers? What Drivers???
 
Omegadrive's Avatar
 
Join Date: May 2002
Location: Puerto Rico
Posts: 1,526
Rep Power: 73
Omegadrive has much to be proud ofOmegadrive has much to be proud ofOmegadrive has much to be proud ofOmegadrive has much to be proud ofOmegadrive has much to be proud ofOmegadrive has much to be proud ofOmegadrive has much to be proud ofOmegadrive has much to be proud of

Guys, I got a few emails telling me about this, I checked my files with my AV (Kapersky) and found nothing, also, we did a scan on the server, nothing, the server is protected 24/7 from virus using NOD32, and it haven't reported anything either.
It is safe to say this is yet ANOTHER false-positive from AVG (which I don't know why people keep using since it detects too many false-positives). Try updating your virus definitions or use another AV. You can rest well tonight.
__________________

DRIVERHEAVEN ADMINISTRATOR

<<E-MAIL>> <<PC SPECS>>

GOD BLESS YOU ALL!
Omegadrive is offline   Reply With Quote
Old Sep 12, 2005, 06:50 PM   #10
HardwareHeaven Extreme Member
 
swimtech's Avatar
 
Join Date: May 2002
Location: North Carolina
Posts: 4,040
Rep Power: 122
swimtech has a reputation beyond refuteswimtech has a reputation beyond refuteswimtech has a reputation beyond refuteswimtech has a reputation beyond refuteswimtech has a reputation beyond refuteswimtech has a reputation beyond refuteswimtech has a reputation beyond refuteswimtech has a reputation beyond refuteswimtech has a reputation beyond refuteswimtech has a reputation beyond refuteswimtech has a reputation beyond refute
System Specs

I use the German AntiVir program - works great and doesn't seem to use as many clock cycles as AVG.

Tonite eh? Thanks Omegadrive!
__________________
It's not so much getting your way that matters or not - what matters is how you go about getting it.
swimtech is offline   Reply With Quote
Reply

Bookmarks

Thread Tools