PDA

View Full Version : Trojan Hunter found 8 files [4 objects]...


Sylvander
10-23-2008, 10:01 AM
As in the screenshots below...
But are these really there for the purpose of doing harm to my PC?
Or are they just normal components of the UBCD4Win bootable CD?
If not, how did they get onto my PC?

I notice some of these are classed as "Riskware" & "Risktool".
Is this because it is possible for these to be used for malicious purposes?
In other words they pose no threat unless placed on my PC by someone with malicious intent.

If I run a UBCD4Win environment loaded from the CD [no firewall running]...
Can my PC be hacked into?
Do I need a router with its firewall to prevent this?
.

mjc
10-23-2008, 01:32 PM
TH is rather aggressive...those are not anything to worry about.

They are all legit tools that can be used for nefarious purposes.

Sylvander
10-23-2008, 03:31 PM
Whew, that puts my mind at rest. :)

Thank goodness some people [such as yourself] know these things. :cool:

This all began when I tried to install a copy of MagicISO.
Programs like ThreatFire and WinPatrol were reporting that the prog was adding itself to the Startup list [OK by me]...
But then it began to add BHO's, and I didn't like that much. :(

So I shut down and restored my last good image...
Then ran UBCD4Win and tried to scan for infection [failed miserably]...
And ran Eraser to erase all unused space on C: [just in case an infection can lurk in the unused space and still run].

Since the scan inside UBCD4Win was a failure, I scanned using Trojan Hunter once into Windows and it found those.

mjc
10-23-2008, 04:05 PM
TH is one of the programs that labels most network/forensic tools as possible threats.

From UBCD4Win's FAQ...This is becoming more of a common occurrence. AntiVirus companies are always trying to help protect us from new viruses but they do make mistakes sometimes. These "false positives" are reported to us every several weeks. Almost all vendors have released a virus definition that has listed different files in the project download as viruses or trojans. When people report this to us, we contact the vendor and send them the "offending" file. Usually within 24 hours a new virus definition file is released by them with "false positive" removed.