Question ( 1 ) : I was downloading a game, after that i restarted my computer and i saw msupdte.exe after that i google it, and found it was a virus, i tried scanning on Avast, and a online scanner, but it can’t detect anything.
Question ( 2 ) : From a keygen website i guess.
Question ( 3 ) : Downloaded
Question ( 4 ) : C:\WINDOWS\system32\msupdte.exe
Question ( 5 ) : Nothing came out.
Question ( 6 ) :Scanned, nothing happens.
Question ( 7 ) : I used that website to scan, but can’t detect anything either.
You could also check the offending/suspect file at: VirusTotal - Multi engine on-line virus scanner and report the findings here. You can’t do this with the file securely in the chest, you need to extract it to a temporary (not original) location first, see below.
Create a folder called Suspect in the C:\ drive, e.g. C:\Suspect. Now exclude that folder in the Standard Shield, Customize, Advanced, Add, type (or copy and paste) C:\Suspect* That will stop the standard shield scanning any file you put in that folder. You should now be able to export any file in the chest to this folder and upload it to VirusTotal without avast alerting.
If multiple scanners detect it but not avast, send the sample to avast.
Send the sample to virus@avast.com zipped and password protected with the password in email body, a link to this topic, the URL for the virustotal results page might help and undetected malware in the subject.
Or you can also add the file to the User Files (File, Add) section of the avast chest (if it isn’t already there) where it can do no harm and send it from there (select the file, right click, email to Alwil Software). No need to zip and PW protect when the sample is sent from chest. A copy of the file/s will remain in the original location, so any further action you take can remove that.
I am using superantispyware to find any trojans or virus now.
I will try your method, should i delete off msupdte.exe ?
or i should try your solution creating a folder ’ suspect ’ move the file inside, then go standard shield and block it?
This upload you made to VT is different to the msupdte.exe in your first post ???
This link is for Macromedia_Flash_player.exe, so I’m guessing that VT said this had already been scanned (received on 11.05.2008) this is an eternity in virus terms. So you should always have the upload scanned again, as that set of results is over 6 months old and basically worthless.
Edit: I assumed Date was UK date format which is day month year, if month, day, year then no it isn’t old.
So I would say you need to upload this again and have it scanned copy the URL from the address bar when the scan is complete. Make a not of the size of the file on your HDD it should match the size of the reported size in the results.
That one is also a previous scan, you must have it scan the file ‘you’ upload again and not simply copy the old scan information, this one being 4 months old.
VirusTotal will recognise if it has scanned this before but you must click the ‘Reanalyse file now’ button (see image) so that it scan the that ‘you’ and not someone else uploaded.
After 4 months many AVs could now detect it or perhaps not, but we need the most recent information and that means reanalysing the file.
Edit: I assumed Date was UK date format which is day month year, if month, day, year then no it isn’t old.
Ok, I,m a little confused ( slightly drunk ) Is the result 4 months old ? 11/07/2008 Is that not today.Also the files, for msupdte and Flash_player.exe ,are they not the same ?They have the same MD5, and file size.Please remind me never to post, when I have been drinking ;D ;D ;D
Your not drunk or seeing double, but I night have been ;D
I assumed Date was UK date format which is day month year, if month, day, year then no it isn’t old.
Yes md5s can be the same but have different file name, which to me is suspicious as to me I don’t see a legit reason to do that and more suspicious when both differently dated scans show no infection.
So this is a strange one and is still suspicious to me and the multiple google hits that think this malware seem to confirm that suspicion.
Yes,very odd,also there is a HJT entry Unknown
O4 - HKCU..\Run: [Microsoft Update Machine] meaukd.exe, that is unusual.I was very surprised by the VT result.Off to bed now