From: David H. Lipman on 17 Mar 2010 18:02 From: "Oreally" <sashago(a)comcast.net> | Thanks..... | I've loaded 6 of the files.....(there were 10 total) | Let me know, | Oreally Got'em -- Dave http://www.claymania.com/removal-trojan-adware.html Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp
From: David H. Lipman on 17 Mar 2010 18:18 From: "David H. Lipman" <DLipman~nospam~@Verizon.Net> | From: "Oreally" <sashago(a)comcast.net> || Thanks..... || I've loaded 6 of the files.....(there were 10 total) || Let me know, || Oreally | Got'em Three of the files are the same having the MD5 checksum of f98415e3c2d1b96a5f132769f067627c -- Dave http://www.claymania.com/removal-trojan-adware.html Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp
From: Oreally on 17 Mar 2010 18:26 Right......8 total are: Trojan-Spy.Win32.Agent.beaf "David H. Lipman" <DLipman~nospam~@Verizon.Net> wrote in message news:eXpHO$hxKHA.6140(a)TK2MSFTNGP05.phx.gbl... > From: "David H. Lipman" <DLipman~nospam~@Verizon.Net> > > | From: "Oreally" <sashago(a)comcast.net> > > || Thanks..... > > || I've loaded 6 of the files.....(there were 10 total) > > || Let me know, > > || Oreally > > > | Got'em > > Three of the files are the same having the MD5 checksum of > f98415e3c2d1b96a5f132769f067627c > > > > > -- > Dave > http://www.claymania.com/removal-trojan-adware.html > Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp > >
From: David H. Lipman on 17 Mar 2010 18:52 From: "Oreally" <sashago(a)comcast.net> | Right......8 total are: Trojan-Spy.Win32.Agent.beaf No, that's the detection. I'm saying that while the EXE names are different the files are the same thus the WOULD get the same detection. A string in the Visual Basic file is... F:\work\hp\systemwiz\SWR_Wizard\RunLinkReset\RunLinkReset.vbp' Which jives with "HP Recovery Wizard". -- Dave http://www.claymania.com/removal-trojan-adware.html Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp
From: Oreally on 17 Mar 2010 19:23
Ok....so what do I do? Are they false positives? "David H. Lipman" <DLipman~nospam~@Verizon.Net> wrote in message news:eWI$VSixKHA.2012(a)TK2MSFTNGP04.phx.gbl... > From: "Oreally" <sashago(a)comcast.net> > > | Right......8 total are: Trojan-Spy.Win32.Agent.beaf > > > > No, that's the detection. I'm saying that while the EXE names are > different the files are > the same thus the WOULD get the same detection. > > A string in the Visual Basic file is... > > F:\work\hp\systemwiz\SWR_Wizard\RunLinkReset\RunLinkReset.vbp' > > Which jives with "HP Recovery Wizard". > > > > > -- > Dave > http://www.claymania.com/removal-trojan-adware.html > Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp > > |