Im sorry in advance!

Oldman help!! again :cry: I have not idea this time what I did… but again I have encountered a Trojan. I had a feeling something was not right as the computer all of a sudden started running slow as molasses. I never got any trojans warnings but Im just now running a Avast scan and the list of trojans is coming… Im so sorry and i would understand if you don’t want to help me again…I went for years and didn’t have torjans now i seem to have become the trojan queen!

C:\Documents and Settings\HP_Owner\Shared\Eighties classic (grandmas).wma

\Documents and Settings\HP_Owner\Shared\Rare Recording.wma

So far this is what has come up… ugh!

let me know what you think i need to do this time and ill let you know when the scan is done…
Sorry
SassySusie :-[

In fact it found another and now it seems the virus scan is froze up!
this is the one it found before it froze and it is saying Current Scanner Status …infected.
C:\Documents and Settings\HP_Owner\Shared\Wicked Remix.wma
Thanks
susie

You can find a list of forums offering help with malware removal here:

http://www.bleepingcomputer.com/combofix/how-to-use-combofix#forums

ok… i did move it to my avast chest but if you knew my history with trojans you might understand why I might panic!
Thank you
Susie

those seem to be VERY odd places to have a trojan in. could be a false positive. I’m guessing you didn’t send the files to virustotal ?? If you didnt delete them yet, you might want to try uploading them to virustotal to see if they are false positives.

Whilst it would be unusual to find a virus, etc. in a Windows Media Audio (.wma) file, the file name alone doesn’t confirm that it is a media file and since it is in a shared folder, it could be suspect.

In either case possible FP or suspect location it needs further investigation.

You could also check the offending/suspect file at: VirusTotal - Multi engine on-line virus scanner and report the findings here. I feel virustotal is the better option as it uses the windows version of avast (more packers supported) and there are currently over 30 different scanners.
Or Jotti - Multi engine on-line virus scanner if any other scanners here detect them it is less likely to be a false positive. Whichever scanner you use, you can’t do this with the file in the chest, you will need to move it out.

Thank you for responding! I will do what you suggested just one thing… how do i move a virus out of my chest and where do i more it to that it would not harm my computer?
Thank you again
Susie

You open the chest and find the file in the Infected Files section, right click on the file and select export (not restore) and move it to a temporary location (see below), the standard shield may alarm.

Create a folder called Suspect in the C:\ drive, e.g. C:\Suspect.
Now exclude that folder in the Standard Shield, Customize, Advanced, Add, type (or copy and paste) C:\Suspect* That will stop the standard shield scanning any file you put in that folder.

You should now be able to export any file in the chest to this folder and upload it to VirusTotal without avast alerting.

I do not mean to be so difficult Im trying my best really… I have looked everywhere i know in the Avast I have exclude the folder “Suspect” from the Standard shield. Do I need to upgrade my Avast in oder to use that feature? If so I will.
Thanks
Susie

No, you don’t have to upgrade to exclude files or folder, it is a regular function of avast.

Exclusions lists:
Standard Shield, Customize, Advanced, Add and
Program Settings, Exclusions

If you say you have excluded the suspect folder (you need to create in windows explorer, you did that right and exported the file there ?) what is it that you are looking everywhere in avast for ?

Sorry I was not clear with my response… I was looking all over in Avast for where the Exclusion list is… I was not able to find that… but… as we speak i just found it… ok ill try to go on from here… ill be back if i encounter any more problems… please be patient with me…
Thank you
Sasy

I will send the results from Virus total as eash one finishes… there are 4 total.

Eighties_classic__grandmas_.wma
Result: 10/32 (31.25%)
Antivirus Version Last Update Result
AhnLab-V3 2008.1.31.10 2008.01.30 -
AntiVir 7.6.0.59 2008.01.30 TR/Dldr.WMA.Wimad.K
Authentium 4.93.8 2008.01.31 -
Avast 4.7.1098.0 2008.01.30 Win32:WimAD-I
AVG 7.5.0.516 2008.01.30 -
BitDefender 7.2 2008.01.31 Trojan.Downloader.Wma.Wimad.K
CAT-QuickHeal 9.00 2008.01.30 -
ClamAV 0.91.2 2008.01.30 -
DrWeb 4.44.0.09170 2008.01.30 -
eSafe 7.0.15.0 2008.01.28 -
eTrust-Vet 31.3.5499 2008.01.30 -
Ewido 4.0 2008.01.30 -
FileAdvisor 1 2008.01.31 -
Fortinet 3.14.0.0 2008.01.30 Wimad.K!tr.dldr
F-Prot 4.4.2.54 2008.01.30 -
F-Secure 6.70.13260.0 2008.01.31 Trojan-Downloader.WMA.Wimad.k
Ikarus T3.1.1.20 2008.01.31 Trojan-Downloader.WMA.Wimad.k
Kaspersky 7.0.0.125 2008.01.31 Trojan-Downloader.WMA.Wimad.k
McAfee 5219 2008.01.30 -
Microsoft 1.3109 2008.01.28 -
NOD32v2 2837 2008.01.30 -
Norman 5.80.02 2008.01.30 -
Panda 9.0.0.4 2008.01.30 -
Prevx1 V2 2008.01.31 -
Rising 20.29.22.00 2008.01.30 -
Sophos 4.25.0 2008.01.31 Troj/Wimad-D
Sunbelt 2.2.907.0 2008.01.31 -
Symantec 10 2008.01.31 Trojan.Wimad
TheHacker 6.2.9.203 2008.01.30 -
VBA32 3.12.2.6 2008.01.31 -
VirusBuster 4.3.26:9 2008.01.30 -
Webwasher-Gateway 6.6.2 2008.01.30 Trojan.Dldr.WMA.Wimad.K
Additional information
File size: 4335426 bytes
MD5: f8deade293428758c2affa4f802274db
SHA1: c82aac0a6b0282d12d3c5f67e427b35f9ef3ecd6
PEiD: -

File Rare_Recording.wma
Result: 6/32 (18.75%)
Antivirus Version Last Update Result
AhnLab-V3 2008.1.31.10 2008.01.30 -
AntiVir 7.6.0.59 2008.01.30 -
Authentium 4.93.8 2008.01.31 -
Avast 4.7.1098.0 2008.01.30 Win32:WimAD-I
AVG 7.5.0.516 2008.01.30 Downloader.Wimad.D
BitDefender 7.2 2008.01.31 -
CAT-QuickHeal 9.00 2008.01.30 -
ClamAV 0.91.2 2008.01.30 -
DrWeb 4.44.0.09170 2008.01.30 -
eSafe 7.0.15.0 2008.01.28 -
eTrust-Vet 31.3.5499 2008.01.30 -
Ewido 4.0 2008.01.30 Downloader.Wimad.l
FileAdvisor 1 2008.01.31 -
Fortinet 3.14.0.0 2008.01.30 -
F-Prot 4.4.2.54 2008.01.30 -
F-Secure 6.70.13260.0 2008.01.31 Trojan-Downloader.WMA.Wimad.l
Ikarus T3.1.1.20 2008.01.31 Trojan-Downloader.WMA.Wimad.l
Kaspersky 7.0.0.125 2008.01.31 Trojan-Downloader.WMA.Wimad.l
McAfee 5219 2008.01.30 -
Microsoft 1.3109 2008.01.28 -
NOD32v2 2837 2008.01.30 -
Norman 5.80.02 2008.01.30 -
Panda 9.0.0.4 2008.01.30 -
Prevx1 V2 2008.01.31 -
Rising 20.29.22.00 2008.01.30 -
Sophos 4.25.0 2008.01.31 -
Sunbelt 2.2.907.0 2008.01.31 -
Symantec 10 2008.01.31 -
TheHacker 6.2.9.203 2008.01.30 -
VBA32 3.12.2.6 2008.01.31 -
VirusBuster 4.3.26:9 2008.01.30 -
Webwasher-Gateway 6.6.2 2008.01.30 -
Additional information
File size: 2559308 bytes
MD5: 805f448e115d5dbd71a99b98f8ba7f4a
SHA1: 9ca95d23f4f22d68bbeee20f6f32886a422fcd7e
PEiD: -

ATTENTION: VirusTotal is a free service offered by Hispasec Sistemas. There are

File T-4494360-LimeWireWin4.16.1.exe
Result: 1/32 (3.13%)
Antivirus Version Last Update Result
AhnLab-V3 2008.1.31.10 2008.01.30 -
AntiVir 7.6.0.59 2008.01.30 -
Authentium 4.93.8 2008.01.31 -
Avast 4.7.1098.0 2008.01.30 -
AVG 7.5.0.516 2008.01.30 -
BitDefender 7.2 2008.01.31 -
CAT-QuickHeal 9.00 2008.01.30 -
ClamAV 0.91.2 2008.01.30 -
DrWeb 4.44.0.09170 2008.01.30 -
eSafe 7.0.15.0 2008.01.28 -
eTrust-Vet 31.3.5499 2008.01.30 -
Ewido 4.0 2008.01.30 -
FileAdvisor 1 2008.01.31 -
Fortinet 3.14.0.0 2008.01.30 -
F-Prot 4.4.2.54 2008.01.30 -
F-Secure 6.70.13260.0 2008.01.31 -
Ikarus T3.1.1.20 2008.01.31 -
Kaspersky 7.0.0.125 2008.01.31 -
McAfee 5219 2008.01.30 -
Microsoft 1.3109 2008.01.28 -
NOD32v2 2837 2008.01.30 -
Norman 5.80.02 2008.01.30 -
Panda 9.0.0.4 2008.01.30 -
Prevx1 V2 2008.01.31 Heuristic: Suspicious Hijacker
Rising 20.29.22.00 2008.01.30 -
Sophos 4.25.0 2008.01.31 -
Sunbelt 2.2.907.0 2008.01.31 -
Symantec 10 2008.01.31 -
TheHacker 6.2.9.203 2008.01.30 -
VBA32 3.12.2.6 2008.01.31 -
VirusBuster 4.3.26:9 2008.01.30 -
Webwasher-Gateway 6.6.2 2008.01.30 -
Additional information
File size: 4494360 bytes
MD5: c09ac51303d94820a637012c4ecca603
SHA1: 8cb4a2d49621e04f5003133f7b3d2d0e0afe7cb9
PEiD: -
Prevx info: http://info.prevx.com/aboutprogramtext.asp?PX5=0D0D749A18DFF216945644D43B0C4700629AD555

File Wicked_Remix.wma
Result: 5/32 (15.63%)
Antivirus Version Last Update Result
AhnLab-V3 2008.1.31.10 2008.01.30 -
AntiVir 7.6.0.59 2008.01.30 -
Authentium 4.93.8 2008.01.31 -
Avast 4.7.1098.0 2008.01.30 Win32:WimAD-I
AVG 7.5.0.516 2008.01.30 -
BitDefender 7.2 2008.01.31 -
CAT-QuickHeal 9.00 2008.01.30 -
ClamAV 0.91.2 2008.01.30 -
DrWeb 4.44.0.09170 2008.01.30 -
eSafe 7.0.15.0 2008.01.28 -
eTrust-Vet 31.3.5499 2008.01.30 -
Ewido 4.0 2008.01.30 -
FileAdvisor 1 2008.01.31 -
Fortinet 3.14.0.0 2008.01.30 Wimad.K!tr.dldr
F-Prot 4.4.2.54 2008.01.30 -
F-Secure 6.70.13260.0 2008.01.31 Trojan-Downloader.WMA.Wimad.k
Ikarus T3.1.1.20 2008.01.31 -
Kaspersky 7.0.0.125 2008.01.31 Trojan-Downloader.WMA.Wimad.k
McAfee 5219 2008.01.30 -
Microsoft 1.3109 2008.01.28 -
NOD32v2 2837 2008.01.30 -
Norman 5.80.02 2008.01.30 -
Panda 9.0.0.4 2008.01.30 -
Prevx1 V2 2008.01.31 -
Rising 20.29.22.00 2008.01.30 -
Sophos 4.25.0 2008.01.31 Troj/Wimad-D
Sunbelt 2.2.907.0 2008.01.31 -
Symantec 10 2008.01.31 -
TheHacker 6.2.9.203 2008.01.30 -
VBA32 3.12.2.6 2008.01.31 -
VirusBuster 4.3.26:9 2008.01.30 -
Webwasher-Gateway 6.6.2 2008.01.30 -
Additional information
File size: 1932810 bytes
MD5: 43c59d70362c9c8c9f1b1f60c659bdc7
SHA1: 1c30dbd2ab9e8a03b42db927413ba183872a7b17
PEiD: -

Ok I hope this is what you wanted… I did the best I could hope it is right.
Thank you
Sasy

lol…from what you posted…now its kinda hard to tell. Most likely they ARENT false positives, but i’m still surprised to see so many AV programs not detecting anything while others are.

oh…ur limewire one (the limewire.exe) shouldnt be dangerous unless you downloaded it over a year ago. Lol, hope your not downloading naughty videos or illegal music/movies. waves finger…i forget which version they took the adware out of it, but it was a couple years ago i believe.

Well the .wma detections look fine. The T-4494360-LimeWireWin4.16.1.exe one may be an FP if downloaded from a good source, as the 1 detection (strange no avast detection, scan the copy in the chest and see if avast still detects it) was a heuristic one.

Though there are some that don’t rate limewire as a good p2p application anyway.