Uruguay 6/7/8

hi all,
was wondering if anyone can help me, i was on www.lge.com,
and when i went to pick my country, as soon as i picked it my avast anti virus kicked in and said i was infected with Uruguay 6/7/8 virus.
can anyone help, and let me know what sort of virus it is.
avast gave me the option to delete it and i did, is that all i do.
i will do a full scan very shortly.

thank for any advise.

It is a resident virus that infects .com en .exe files.

For instructions on how to thoroughly clean a system click on the link in my system and choose malware removal instructions from the menu.

Ok I downloaded the app ‘WorldWind’ from NASA.gov. —

It had this virus apparently in it… I wonder if its just a false positive… or what…

Would the virus scanner lie? And why would NASA give me a virus… Or quite possibly the source I downloaded from was unsafe… ???

If you downloaded from www.nasa.org it’s most probably a false positive…

nasa.org looks like a non-government website – I got from

http://worldwind.arc.nasa.gov/

Can someone else confirm this source?? Perhaps?

OrgName: National Aeronautics and Space Administration
OrgID: NASA
Address: AD33/Office of the Chief Information Officer
City: MSFC
StateProv: AL
PostalCode: 35812
Country: US

NetRange: 128.102.0.0 - 128.102.255.255
CIDR: 128.102.0.0/16
NetName: AMES-NET
NetHandle: NET-128-102-0-0-1
Parent: NET-128-0-0-0-0
NetType: Direct Allocation
NameServer: NS.ARC.NASA.GOV
NameServer: NASANS4.NASA.GOV
Comment:
RegDate: 1986-01-24
Updated: 2003-07-01

TechHandle: ZN7-ARIN
TechName: National Aeronautics and Space Administration
TechPhone: +1-256-544-5623
TechEmail: dns.support@nasa.gov

OrgAbuseHandle: NASAA-ARIN
OrgAbuseName: NASA Abuse
OrgAbusePhone: +1-800-762-7472
OrgAbuseEmail: abuse@nasa.gov

OrgNOCHandle: NISN-ARIN
OrgNOCName: NASA Information Services Network
OrgNOCPhone: +1-256-961-4000
OrgNOCEmail: noc@nisn.nasa.gov

OrgTechHandle: WEBBN-ARIN
OrgTechName: Webb, Nancy
OrgTechPhone: +1-256-544-3245
OrgTechEmail: dns.support@nasa.gov

Yes,page is from NASA. I’ll check the file,but i belive it’s false positive.
Was it detected directly (installer) or after you installed it?

It was ‘after’ I installed. –

and actually after running it after a period of time. -

ie. I was viewing some satellite images…

To be more exact, I downloaded using the SourceForge mirror.

http :// prdownloads.sourceforge.net/nasa-exp/World_Wind_1.3.1_Full.exe?use_mirror=easynews

Could you edit your link please.

Although this is more likely to be a false positive, but it is best not to post active URLs which may link to harmful content, you can exclude or edit parts so that they aren’t active/clickable.

e.g. put spaces before and after the ’ :// ’
http :// prdownloads.sourceforge.net/nasa-exp/World_Wind_1.3.1_Full.exe?use_mirror=easynews

That way the curious or accidental clicking shouldn’t cause harm.

done. ty.

All clear by McAfee VSE 8.0i. It’s a false positive for sure. Program is legitim too.