Overclock.net - Overclocking.net
     
 
Home Gallery Reviews Blogs Register Today's Posts Mark Forums Read Members List


Go Back   Overclock.net - Overclocking.net > Software, Programming and Coding > Networking & Security

Reply
 
LinkBack Thread Tools
Old 06-22-08   #1 (permalink)
GH0
Security Sleuth
 
GH0's Avatar
 
amd nvidia

Join Date: Jan 2008
Location: 0.0.0.0 (multicast)
Posts: 1,561

Rep: 143 GH0 is acknowledged by manyGH0 is acknowledged by many
Unique Rep: 111
Folding Team Rank: 421
Trader Rating: 0
Default Supposed system virus?

Well, after seeing a malware thing pop up on Avast, I decided to check my Chest.

I then noticed that three system files were in there: wsock32.dll, winsock.dll, kernel32.dll.

Now, I did check them with virus scans. Nothing seems to have appeared, here are the logs for those.
Quote:
Kernel32.dll Log:

Scanning of selected files
------------------------------------------------------------------------------------------
Program will try to scan 1 selected file(s) in the Chest

Move files to temporary folder: C:\DOCUME~1\Andrew\LOCALS~1\Temp\_avast4_\unp24161 8324.tmp
FileID: 0000000001 Original file name: C:\WINDOWS\system32\kernel32.dll New folder: C:\DOCUME~1\Andrew\LOCALS~1\Temp\_avast4_\unp24161 8324.tmp\1.dll

Scan files in the temporary folder: C:\DOCUME~1\Andrew\LOCALS~1\Temp\_avast4_\unp24161 8324.tmp
C:\DOCUME~1\Andrew\LOCALS~1\Temp\_avast4_\unp24161 8324.tmp\1.dll -- no virus --
------------------------------------------------------------------------------------------
Action was completed successfully!
Quote:
winsock.dll Log:

Scanning of selected files
------------------------------------------------------------------------------------------
Program will try to scan 1 selected file(s) in the Chest

Move files to temporary folder: C:\DOCUME~1\Andrew\LOCALS~1\Temp\_avast4_\unp15578 9285.tmp
FileID: 0000000002 Original file name: C:\WINDOWS\system32\winsock.dll New folder: C:\DOCUME~1\Andrew\LOCALS~1\Temp\_avast4_\unp15578 9285.tmp\2.dll

Scan files in the temporary folder: C:\DOCUME~1\Andrew\LOCALS~1\Temp\_avast4_\unp15578 9285.tmp
C:\DOCUME~1\Andrew\LOCALS~1\Temp\_avast4_\unp15578 9285.tmp\2.dll -- no virus --
------------------------------------------------------------------------------------------
Action was completed successfully!
Finally:

Quote:
Wsock32.dll Log:

Scanning of selected files
------------------------------------------------------------------------------------------
Program will try to scan 1 selected file(s) in the Chest

Move files to temporary folder: C:\DOCUME~1\Andrew\LOCALS~1\Temp\_avast4_\unp23962 9379.tmp
FileID: 0000000003 Original file name: C:\WINDOWS\system32\wsock32.dll New folder: C:\DOCUME~1\Andrew\LOCALS~1\Temp\_avast4_\unp23962 9379.tmp\3.dll

Scan files in the temporary folder: C:\DOCUME~1\Andrew\LOCALS~1\Temp\_avast4_\unp23962 9379.tmp
C:\DOCUME~1\Andrew\LOCALS~1\Temp\_avast4_\unp23962 9379.tmp\3.dll -- no virus --
------------------------------------------------------------------------------------------
Action was completed successfully!
Now, I tried restoring them, but that is impossible because they are always going to be in use by the system.

I just find this highly weird. Could it be possible that it is a False Positive and they will always be in there? Or is it possible that it actually is a virus?

Any help?
__________________
System: Dataslum
CPU
5000+ Black Edition
Motherboard
ASUS Formula Crosshair II
Memory
4 (2x2) Muskin Memory
Graphics Card
EVGA 9800GTX+ 512 MB (SLI)
Hard Drive
Windows XP/Vista Business RAID 0, Total 2.1 TB
Sound Card
SupremeFX / Some form of cheap Creative
Power Supply
Corsair 1KW
Case
Lian-Li
CPU cooling
Xigmatek
GPU cooling
Stock
OS
Windows XP 32-bit Pro (SP2) and Vista Ultimate
Monitor
Samsung SyncMaster 906 BW, Sony 19"
GH0 is offline I fold for Overclock.net GH0's Gallery   Reply With Quote
Old 06-23-08   #2 (permalink)
Intel Overclocker
 
Grafixs's Avatar
 
intel ati

Join Date: Nov 2007
Location: Annapolis, MD
Posts: 438

Rep: 25 Grafixs is acknowledged by some
Unique Rep: 20
Trader Rating: 1
Default

Probably a virus attached itself to the host files so that the virus can help spread during boot times. i.e. the kernal32.dll

I am not much of a virus guy, but I can see how a virus, which can attach itself to a host file, and spread would easily attach to a system boot up file and spread easier without avast being in the way.
__________________
My Anti-Drug
Audi A4 2.0T
220BHP 240 Torque
Less than 3 Sarah Lynn Stocker

System: Credit Card Debt FTW!
CPU
E3110|Wolfdale|3.8ghz|1.31v|
Motherboard
DFI|X48-T2R|
Memory
G.SKILL|4GB|1066|5-5-5-15|
Graphics Card
Sapphire|4870|Stock|
Hard Drive
Seagate|500GB|16MB|7200.11|
Sound Card
Onboard
Power Supply
Raidmax 700w
Case
Rocketfish
CPU cooling
TRUE *lapped* Scythe Slipstrem 110CFM
GPU cooling
Scythe Slipstream 110CFM
OS
Vista 64|SP1|
Monitor
24" Dell WFP2407
Grafixs is offline   Reply With Quote
Old 06-23-08   #3 (permalink)
Programmer
 
Mr_Torch's Avatar
 
intel ati

Join Date: Feb 2005
Location: B-F-E
Posts: 1,111

Rep: 114 Mr_Torch is acknowledged by manyMr_Torch is acknowledged by many
Unique Rep: 103
FAQs Submitted: 5
Trader Rating: 0
Default

Those system files are supposed to be in there, notice that they are NOT in the Infected file area. Just leave them be, they are NOT viruses. If you do some reading on Avast they will explain it all completely.
__________________
The Fire Of Life Burns Deep Within Me

The Internet? We are not interested in it. - Bill Gates 1993


System: Torch's Rig
CPU
E6750 w/G0 @ 3.2GHz
Motherboard
ASUS P5KC
Memory
OCZ PC6400 2 GIG
Graphics Card
Sapphire HD 2900 PRO 512MB 512bit
Hard Drive
Seagate Barracuda 7200.10 250GB x2
Sound Card
Stock 7.1
Power Supply
610w PC Power & Cool Silencer
Case
Tsunami Dream
CPU cooling
Thermaltake Silent Tower
GPU cooling
ATI Rear Exhaust
OS
Vista Ultimate SP1 32 bit
Monitor
Proview 22" Widescreen LCD
Mr_Torch is offline Mr_Torch's Gallery   Reply With Quote
Reply



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools



All times are GMT -4. The time now is 10:17 AM.


Overclock.net is a Carbon Neutral Site Creative Commons License Internet Security By ControlScan

Terms of Service / Forum Rules | Privacy Policy | Advertising | Become an Official Vendor
Copyright © 2008 Shogun Interactive Development. Most rights reserved.
Page generated in 0.13040 seconds with 9 queries