VOGONS


Am I in danger?

Topic actions

First post, by AdamP

User metadata
Rank Member
Rank
Member

Hi,

I've just been scanning my old Compaq Deskpro running Windows 98 (which is connected directly to my Windows 7 laptop) with AVG 2014:

"";"Virus found BAT/Formatx, Z:\WINDOWS\Desktop\Unused Desktop Icons\UltBootDisk98.zip";"Infected"
"";"Virus identified EICAR_Test, Z:\WINDOWS\Desktop\Unused Desktop Icons\eicar.com";"Infected"
"";"Virus found BAT/Formatx, Z:\WINDOWS\Desktop\Unused Desktop Icons\UltBootDisk98.zip:\UltBootDisk98.exe:\unpacked000A.bin:\MENU.BAT";"Infected"
"";"Corrupted executable file, Z:\BIGRED\WINRACE.EXE";"Infected"
"";"Could be a Trojan horse Downloader.Swizzor, Z:\Programme\Creative\CTSND\VIENNA\SFSHELLX.DLL";"Infected"
"";"Trojan horse Dropper.Agent.WJ, Z:\eGames\Blaster_Pack\Tunnel Blaster\tblasterfin.exe";"Infected"
"";"Trojan horse Dropper.Agent.WJ, Z:\eGames\Blaster_Pack\3D Astro Blaster\ASTRO.EXE";"Infected"
"";"Trojan horse Dropper.Agent.WJ, Z:\eGames\Blaster_Pack\Galactic Invasion\EGAMES.EXE";"Infected"
"";"Trojan horse Dropper.Agent.WJ, Z:\eGames\Blaster_Pack\Galactic Patrol\GALACTIC PATROL.EXE";"Infected"

Can these results be relied upon? I have some doubts. I can;t find much info about Dropper.Agent.WJ but as far as I can tell it didn't exist until 2005. Also, I thought Trojans didn't infect other programs, but are "hidden" programs designed to download malware in secret? For 4 (possibly 5, though I doubt it) Trojans, I don't appear to have many viruses.

I'm also curious to know why it thinks Bigred/Winrace.exe is corrupt. I tried running it on the Compaq and it worked fine.

The EICAR file was detected, so my AV appears to be in working order. I have the original disc for the last 4, so I scanned it:

"";"Trojan horse Dropper.Agent.WJ.dropper, E:\setups\drakdemo.exe";"Infected"
"";"Trojan horse Dropper.Agent.WJ.dropper, E:\setups\eggdemo.exe";"Infected"
"";"Trojan horse Dropper.Agent.WJ.dropper, E:\setups\fmdemo.exe";"Infected"
"";"Found Win32/DH{WABnNQ8g}, E:\stub1.exe";"Infected"
"";"Trojan horse Dropper.Agent.WJ.dropper, E:\setups\wcdemo.exe";"Infected"
"";"Trojan horse Dropper.Agent.WJ, E:\setups\rademo.EXE";"Infected"
"";"Found Win32/DH{WABnNQ8g}, E:\stub2.exe";"Infected"
"";"Found Win32/DH{WABnNQ8g}, E:\stub3.exe";"Infected"
"";"Found Win32/DH{WABnNQ8g}, E:\stub4.exe";"Infected"
"";"Found Win32/DH{WABnNQ8g}, E:\stub5.exe";"Infected"
"";"Trojan horse Dropper.Agent.WJ.dropper, E:\setups\Minidemo.exe";"Infected"
"";"Trojan horse Dropper.Agent.WJ, E:\setup.exe";"Infected"

I have no idea what the rest of it is, but I find it hard to believe that a Trojan from 5 years into the future(?) found its way onto eGames Family Friendly game disc. The only other thing about Dropper.Agent.WJ is that some file called glowingbugsdemo.exe is known to be infected. I notice that follows the same naming convention as most of the other infected files on the disc; is that an eGames game too I wonder? I know some marburg viruses got onto some July 1997 (or was it 1996?) editions of a PC gamer disc, but that's different. I used to have that disc, and yes, it was indeed infected with said virus. I remember XEarth, some paint program, and a couple of other programs on the disc were infected.

Could my AV be misidentifying files on my retro computer as threats? Is there any way I can find out if SFSHELLX.DLL is indeed a Downloader.Swizzor? (I don't appear to have its symptoms, so that's a good sign). I don't like the thought of software from that time period being routinely infected with malware and distributed on CD! I thought the PC Gamer incident was a one-off?

Thanks

Reply 1 of 5, by leileilol

User metadata
Rank l33t++
Rank
l33t++

eGames always tries to plug other games with their games so I wouldn't be surprised... Casual games are just rife with that stuff since the 2000 burst of them.

Big Red Racing is a false positive.

apsosig.png
long live PCem

Reply 3 of 5, by mr_bigmouth_502

User metadata
Rank Oldbie
Rank
Oldbie

I used to play a lot of eGames crap back in the day, and the main thing found by the various antimalware programs I used was Timesink Ad Client or something like that. It sounded harmless enough, but I always deleted any instances of it and the games continued to work fine.

Also, Tunnel Blaster was a favorite of mine as a kid. 😁 I remember being rather amazed that the full version wasn't much different from the demo. 🤣

Reply 4 of 5, by AdamP

User metadata
Rank Member
Rank
Member

Ah yes, I forgot that eGames used to have that browser thingy and whatnot.

That's a relief! I thought maybe I'd caught something off the internet!

But what's special about Big Red Racing?

Reply 5 of 5, by leileilol

User metadata
Rank l33t++
Rank
l33t++

it.... is one of the earliest Jon St. John + Lani Minella games that have both showcase their extremely versatile voices to a great degree?

apsosig.png
long live PCem