FAQ FAQ  Forum Search   Register Register  Login Login

False positive?

Post Date: 2010-07-25

 Post Reply Post Reply
Author
  Topic Search Topic Search  Topic Options Topic Options
Dsnewb210 View Drop Down
Senior Member
Senior Member

Email address used to purchase matched with forums account email.

Joined: 01 Oct 2008
Online Status: Offline
Posts: 972
  Quote Dsnewb210 Quote  Post ReplyReply bullet Topic: False positive?
    Posted: 25 Jul 2010 at 11:59pm
I just purchased 2 year sub with ESET and it detected a virus that its not able to delete/clean. File is called msgciutr.dll, when I try to manually delete it I get the you need permission message. Should I boot up via safemode and try to delete it?
950SI
965/4.0 Frostbite LC
6GB Dominator 1600mhz
Rampage II Extreme
Intel 160 320 Raid 0
GTX 285 SLI
Dell 2408wfp/2407wfp
Logitech G19, Razer Mamba
Wireless Astro A40's
Bose Companion 5 Speakers
Back to Top
Maylar View Drop Down
Newbie
Newbie

Email address used to purchase matched with forums account email.

Joined: 13 Feb 2010
Online Status: Offline
Posts: 15
  Quote Maylar Quote  Post ReplyReply bullet Posted: 26 Jul 2010 at 1:49pm
That's a keylogger.

Name: msgciutr
Filename: msgciutr.dll
Registry key:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run | tghlig

Command: RUNDLL32.EXE C:\WINDOWS\system32\msgciutr.dll,w
Startup Type: HKLM->Run
HiJackThis Category: O4
HiJackThis Line:

O4 – HKLM\..\Run: [tghlig] RUNDLL32.EXE C:\WINDOWS\system32\msgciutr.dll,w

DDS Line:

mRun: [tghlig] RUNDLL32.EXE C:\WINDOWS\system32\msgciutr.dll,w

Combofix/RSIT Line:

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
“tghlig”=RUNDLL32.EXE C:\WINDOWS\system32\msgciutr.dll,w

Description: trojan that also known as Trojan-PSW.Wowcraft [PCTools], Infostealer.Wowcraft [Symantec], Trojan-GameThief.Win32.WOW.abah [Kaspersky Lab], Mal/Behav-170 [Sophos], PWS:Win32/Frethog.MK [Microsoft], PWS.Win32 [Ikarus], Win-Trojan/Onlinegamehack.36865.EI [AhnLab]
Notes: installed with l84alx.exe


GMER along with Malwarebytes along with some other tools may get rid of it, but as it's a keylogger the "SAFEST" thing you can do is reformat. Keyloggers are nothign to mess around with, as they steal your personal information and give it to thieves.



Edited by Maylar - 26 Jul 2010 at 1:51pm
Close the world, txEn eht nepO
Back to Top
 Post Reply Post Reply

Forum Jump Forum Permissions View Drop Down



This page was generated in 0.03125 seconds.