VOGONS


First post, by AdamP

User metadata
Rank Member
Rank
Member

Hi,

I've just been scanning my old Compaq Deskpro running Windows 98 (which is connected directly to my Windows 7 laptop) with AVG 2014:

"";"Virus found BAT/Formatx, Z:\WINDOWS\Desktop\Unused Desktop Icons\UltBootDisk98.zip";"Infected"
"";"Virus identified EICAR_Test, Z:\WINDOWS\Desktop\Unused Desktop Icons\eicar.com";"Infected"
"";"Virus found BAT/Formatx, Z:\WINDOWS\Desktop\Unused Desktop Icons\UltBootDisk98.zip:\UltBootDisk98.exe:\unpacked000A.bin:\MENU.BAT";"Infected"
"";"Corrupted executable file, Z:\BIGRED\WINRACE.EXE";"Infected"
"";"Could be a Trojan horse Downloader.Swizzor, Z:\Programme\Creative\CTSND\VIENNA\SFSHELLX.DLL";"Infected"
"";"Trojan horse Dropper.Agent.WJ, Z:\eGames\Blaster_Pack\Tunnel Blaster\tblasterfin.exe";"Infected"
"";"Trojan horse Dropper.Agent.WJ, Z:\eGames\Blaster_Pack\3D Astro Blaster\ASTRO.EXE";"Infected"
"";"Trojan horse Dropper.Agent.WJ, Z:\eGames\Blaster_Pack\Galactic Invasion\EGAMES.EXE";"Infected"
"";"Trojan horse Dropper.Agent.WJ, Z:\eGames\Blaster_Pack\Galactic Patrol\GALACTIC PATROL.EXE";"Infected"

Can these results be relied upon? I have some doubts. I can;t find much info about Dropper.Agent.WJ but as far as I can tell it didn't exist until 2005. Also, I thought Trojans didn't infect other programs, but are "hidden" programs designed to download malware in secret? For 4 (possibly 5, though I doubt it) Trojans, I don't appear to have many viruses.

I'm also curious to know why it thinks Bigred/Winrace.exe is corrupt. I tried running it on the Compaq and it worked fine.

The EICAR file was detected, so my AV appears to be in working order. I have the original disc for the last 4, so I scanned it:

"";"Trojan horse Dropper.Agent.WJ.dropper, E:\setups\drakdemo.exe";"Infected"
"";"Trojan horse Dropper.Agent.WJ.dropper, E:\setups\eggdemo.exe";"Infected"
"";"Trojan horse Dropper.Agent.WJ.dropper, E:\setups\fmdemo.exe";"Infected"
"";"Found Win32/DH{WABnNQ8g}, E:\stub1.exe";"Infected"
"";"Trojan horse Dropper.Agent.WJ.dropper, E:\setups\wcdemo.exe";"Infected"
"";"Trojan horse Dropper.Agent.WJ, E:\setups\rademo.EXE";"Infected"
"";"Found Win32/DH{WABnNQ8g}, E:\stub2.exe";"Infected"
"";"Found Win32/DH{WABnNQ8g}, E:\stub3.exe";"Infected"
"";"Found Win32/DH{WABnNQ8g}, E:\stub4.exe";"Infected"
"";"Found Win32/DH{WABnNQ8g}, E:\stub5.exe";"Infected"
"";"Trojan horse Dropper.Agent.WJ.dropper, E:\setups\Minidemo.exe";"Infected"
"";"Trojan horse Dropper.Agent.WJ, E:\setup.exe";"Infected"

I have no idea what the rest of it is, but I find it hard to believe that a Trojan from 5 years into the future(?) found its way onto eGames Family Friendly game disc. The only other thing about Dropper.Agent.WJ is that some file called glowingbugsdemo.exe is known to be infected. I notice that follows the same naming convention as most of the other infected files on the disc; is that an eGames game too I wonder? I know some marburg viruses got onto some July 1997 (or was it 1996?) editions of a PC gamer disc, but that's different. I used to have that disc, and yes, it was indeed infected with said virus. I remember XEarth, some paint program, and a couple of other programs on the disc were infected.

Could my AV be misidentifying files on my retro computer as threats? Is there any way I can find out if SFSHELLX.DLL is indeed a Downloader.Swizzor? (I don't appear to have its symptoms, so that's a good sign). I don't like the thought of software from that time period being routinely infected with malware and distributed on CD! I thought the PC Gamer incident was a one-off?

Thanks

Reply 1 of 5, by leileilol

User metadata
Rank l33t++
Rank
l33t++

eGames always tries to plug other games with their games so I wouldn't be surprised... Casual games are just rife with that stuff since the 2000 burst of them.

Big Red Racing is a false positive.

apsosig.png
long live PCem

Reply 2 of 5, by rgart

User metadata
Rank Oldbie
Rank
Oldbie

I don't think you can rely on the results.

Virus/trojan scanning programs have been ripping apart my files for a long time now.

=My Cyrix 5x86 systems : 120MHz vs 133MHz=. =My 486DX2-66MHz=

Reply 3 of 5, by mr_bigmouth_502

User metadata
Rank Oldbie
Rank
Oldbie

I used to play a lot of eGames crap back in the day, and the main thing found by the various antimalware programs I used was Timesink Ad Client or something like that. It sounded harmless enough, but I always deleted any instances of it and the games continued to work fine.

Also, Tunnel Blaster was a favorite of mine as a kid. 😁 I remember being rather amazed that the full version wasn't much different from the demo. 🤣

Reply 4 of 5, by AdamP

User metadata
Rank Member
Rank
Member

Ah yes, I forgot that eGames used to have that browser thingy and whatnot.

That's a relief! I thought maybe I'd caught something off the internet!

But what's special about Big Red Racing?