Help Me Find If This Is Malware Please

Need help or want to hear about latest Tech stuff? It's probably in here!

Moderator: Claw

Post Reply
Nellyboy
GSV Spammer
Posts: 1872
Joined: Sat Aug 26, 2006 12:12 pm
Contact:

Post by Nellyboy »

nteusigtssd.exe


Google and Bing never heard of it.

Keeps popping up for permission to connect to net in zonealarm

Help!!!!
Image
Thane
Advanced Member
Posts: 482
Joined: Thu Aug 24, 2006 8:38 pm
Contact:

Post by Thane »

Tried running an app that tells you what files/dll's its hooked into or what might be calling it up?

Done info on the exe?
Trig
GSV Spammer
Posts: 4608
Joined: Thu Aug 24, 2006 6:18 pm
Contact:

Post by Trig »

Probably something that generates its own random filename when it lands on your PC hence it not appearing to Google..
Thane
Advanced Member
Posts: 482
Joined: Thu Aug 24, 2006 8:38 pm
Contact:

Post by Thane »

Tbh kill it off and if something then doesn't work you know you needed it :)
Nellyboy
GSV Spammer
Posts: 1872
Joined: Sat Aug 26, 2006 12:12 pm
Contact:

Post by Nellyboy »

Got a reply from Avira after submitting the file for id.

A listing of files alongside their results can be found below:
File ID Filename Size (Byte) Result
25701533 nteusigtssd.exe 262.25 KB MALWARE


Please find a detailed report concerning each individual sample below:
Filename Result nteusigtssd.exe MALWARE

The file 'nteusigtssd.exe' has been determined to be 'MALWARE'. Our analysts named the threat TR/FraudPack.avij. The term "TR/" denotes a trojan horse that is able to spy out data, to violate your privacy or carry out unwanted modifications to the system.Detection is added to our virus definition file (VDF) starting with version 7.10.07.67.
Image
Claw
GSV Spammer
Posts: 2944
Joined: Fri Aug 25, 2006 12:41 am
Contact:

Post by Claw »

There's nothing spoken of regarding that specific file name, but the ending of that file name was interesting and may be related to this:

<a href="http://myantispyware.com/forum/hagwnet- ... t3389.html" target="_blank">http://myantispyware.com/forum/hagwnet- ... 89.html</a>

Then again it may not be.

Have you tried running <a href="http://www.malwarebytes.org/" target="_blank">Malwarebytes?</a>
Just be a nutter... life becomes much more exciting, and people won't expect anything more of you...
Nellyboy
GSV Spammer
Posts: 1872
Joined: Sat Aug 26, 2006 12:12 pm
Contact:

Post by Nellyboy »

Updated my av and it killed that file and 4 similar ones. Sorted I hope.
Image
Thane
Advanced Member
Posts: 482
Joined: Thu Aug 24, 2006 8:38 pm
Contact:

Post by Thane »

Stay away from those gay porn links in future, they be bad for you.
Nellyboy
GSV Spammer
Posts: 1872
Joined: Sat Aug 26, 2006 12:12 pm
Contact:

Post by Nellyboy »

I am assuming it is rapidshare related. I get my content only from there now. No appz just vids.
Image
Richie
GSV Regular
Posts: 887
Joined: Thu Aug 24, 2006 5:18 pm
Contact:

Post by Richie »

Thane wrote: Stay away from those gay porn links in future, they be bad for you.
Listen to the voice of experience there Nelly :boff: :boff:
Life - Its the **** that happens while you're waiting for moments that never come...
Post Reply