Jump to content


Brontok virus in modules\Tweaks\__Functionality\MSConfig_2K_files\msconfig.exe??


4 replies to this topic

#1 vof

    Newbie

  • Members
  • Pip
  • 2 posts
  • Location:Dorset, UK

Posted 01 July 2008 - 12:44 AM

My AVG 8.0 is reporting I-Worm/Brontok.KO in this file. This is in a freshly created AutoPatcher folder for XP SP3. If this file is supposedly msconfig.exe from Win2K, it certainly has a different size to my Win2K SP4 executable. What do other users' AV progs report?

vof

#2 Cristiano

    Super Helpful Guy

  • Veterans
  • PipPipPipPipPipPip
  • 3,851 posts
  • Gender:Male
  • Location:Brazil (Santa Maria - RS)

Posted 01 July 2008 - 03:59 AM

you can check it at http://www.virustotal.com . this service check each file with several engines

#3 James

    Advanced Member

  • Veterans
  • PipPipPipPipPipPip
  • 1,212 posts
  • Gender:Male
  • Location:UK

Posted 01 July 2008 - 06:09 AM

 vof, on Jul 1 2008, 12:44 AM, said:

My AVG 8.0 is reporting I-Worm/Brontok.KO in this file. ...

This looks like a false reading by AVG. F-Secure with the latest updates (2008-07-01_02) finds NO virus

To be sure, check the MD5 hash of msconfig.exe (with md5deep, md5sum, HashCalc or others)
It should be 3c60aefa68efa2c4d13ab6b68fe82b81


 vof, on Jul 1 2008, 12:44 AM, said:

If this file is supposedly msconfig.exe from Win2K, ...

No, this is msconfig for Win2k, not from Win2k.

--
James

#4 vof

    Newbie

  • Members
  • Pip
  • 2 posts
  • Location:Dorset, UK

Posted 01 July 2008 - 01:59 PM

 James, on Jul 1 2008, 06:09 AM, said:

This looks like a false reading by AVG. F-Secure with the latest updates (2008-07-01_02) finds NO virus

To be sure, check the MD5 hash of msconfig.exe (with md5deep, md5sum, HashCalc or others)
It should be 3c60aefa68efa2c4d13ab6b68fe82b81




No, this is msconfig for Win2k, not from Win2k.

--
James

Thanks for that. MD5 hash is OK. VirusTotal reports it clean, and interestingly, AVG 8.0 with most recent update from earlier today (270.4.3/1528) now thinks it is clean.

vof

#5 James

    Advanced Member

  • Veterans
  • PipPipPipPipPipPip
  • 1,212 posts
  • Gender:Male
  • Location:UK

Posted 01 July 2008 - 02:18 PM

Thanks for the feedback. Every test I carried out this morning confirmed that this was a false alarm.
--
James





1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users