virus ? gendel32.exe na raiz

Num mundo de vírus, spyware e bugs nada como estar informado

Moderadores: Administradores, Moderadores

virus ? gendel32.exe na raiz

Mensagempor LuisFilipe » Quinta Abr 09, 2009 12:00

Apareceu-me na raiz do disco um ficheiro gendel32.exe

Procurando no Google não encontrei nada de consistente, uns sites dizem que é um trojan outros dizem que não nada foi detectado no ficheiro.

Não sei como é que fui 'infectado' e é isso que me preocupa.

executei um tal pps geografia com 'flash' tem uma seta para acertar em cidades europeias e depois mede os km da diferença.

Antivirus Avast 7 (Passei a semana passada do Antivir)
Firewall Sygate 5

O que será ?
Algo que executei mas o quê?
LuisFilipe
Membro Diamante
Membro Diamante
 
Mensagens: 1270
Registado: Domingo Set 04, 2005 22:12

Mensagempor LuisFilipe » Quinta Abr 09, 2009 15:16

O programa 'gendel32.exe' que me apareceu na raiz também é mencionado em wininit.ini

O que encontrei foi o seguinte

http://techsupt.winbatch.com/ts/T000001045F1.html
Using WININIT.INI to Install Files after Reboot in Windows 95/IntControl(30,x,x,x,x) to Move Files after Reboot for NT
Keywords: WININIT.INI WININIT.EXE IntControl(30,...)
Question:
How do I delete a Winbatch files after a WB program finishes?
Answer:

You can't do it directly. Basically you have to write a WININIT.INI file in the windows directory that is designed to take care of this. (Note that the WININIT.INI file is NOT an INI file (be careful) and as such cannot be reliably written to via the iniwritepvt function)

If you look at the WININIT.INI and .BAK files in your Windows directory you can figure out how this works.

If it is WinBatch trying to overwrite the DLL is use, we can handle it, but if it is another setup program trying to do it, some other solution must be found.

If you create a file called WININIT.INI in the Windows directory, files listed will be renamed during bootup. An example of what a WININIT.INI file might look like is:
[rename]
C:\Fred\Fault.exe=C:\Fred\Fault.1
to delete a file use:
[rename]
NULL=C:\Fred\Fault.exe
Note: I believe the syntax is destination = source. Looks kind of backwards. Also, this file doesn't support long file names.


Portanto poderá ser restos de uma desinstalação ?
LuisFilipe
Membro Diamante
Membro Diamante
 
Mensagens: 1270
Registado: Domingo Set 04, 2005 22:12

Mensagempor PapaGigas » Sábado Abr 11, 2009 12:30

Descarrega e instala o Virus Total Uploader e envia esse ficheiro para análise... ;)

Imagem

PS - Se desconfias que é virus mas que o mesmo não está a ser devidamente detectado por nenhuma solução anti-virus, podes sempre enviar esse ficheiro para ser analizado pela Kaspersky Labs ( através do mail newvirus@kaspersky.com ) ou por outra software house... :roll:
If I offended you in anyway, please don't take it personally... it's not your fault you're an idiot!
PapaGigas
Gurus
Gurus
 
Mensagens: 4337
Registado: Sexta Out 22, 2004 2:54
Localização: Marrocos

Mensagempor LuisFilipe » Quinta Abr 16, 2009 0:54

RE: suspicious file in HD root (gendel32.exe) [KLAN-26619888]‏From: newvirus@kaspersky.com
Sent: Wednesday, April 15, 2009 12:16:53 PM
To: -----------@-------.---

Hello,

gendel32.exe_, Wininit.ini

No malicious code were found in these files.

> I have found this file in the root of my Windows XP SP2 hard drive C:\
> gendel32.exe
>
> a reference was found also in the wininit.ini file in C:\Windows folder
>
> wininit.ini
> nul=C:\gendel32.exe
>
> I have put a comment in the beggining of the only line of the file
>
> regards
> tanks
>
> ________________________________
> Invite your mail contacts to join your friends list with Windows Live Spaces. It's easy! Try it!<http://spaces.live.com/spacesapi.aspx?wx_action=create&wx_url=/friends.aspx&mkt=en-us>
>
Please quote all when answering.
-----------------
Regards, Davidow Dmitriy
Virus Analyst, Kaspersky Lab.
10/1, 1st Volokolamsky Proezd, Moscow, 123060, Russia
Tel./Fax: + 7 (495) 797 8700
http://www.kaspersky.com http://www.viruslist.com
LuisFilipe
Membro Diamante
Membro Diamante
 
Mensagens: 1270
Registado: Domingo Set 04, 2005 22:12


Voltar para Segurança Informática

Quem está ligado:

Utilizadores a ver este Fórum: Nenhum utilizador registado e 2 visitantes

cron