HeurEngine.Packed.Themida.RGa

Discussion in 'Malware Help (A Specialist Will Reply)' started by DarkeKun, Aug 3, 2009.

  1. DarkeKun

    DarkeKun Private E-2

    :confused Anyone who knows what HeurEngine.Packed.Themida.RGa is? What it does, can't get anything from google what it's supposed to do. :confused
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Antivirus and antispyware companies are notorious for inventing names for things without giving any details on what symptoms or problems infections they name supposedly cause. In most cases, we really don't care about the name. We care more about where the infection is supposedly being found. Like what file, in what folder, and what registry keys.....etc. PC Tools Spyware Doctor has mentioned this infection in the past and several times it was a false detection of files being used by Cyberlink's PowerDVD and also for AVSMEDIA files. I guessing that you Spyware Doctor at this point and may be having false detections.

    Why are you asking? Do you have a problem with this? Then you should run the procedure that was given to you in the email you received when you signed up.
     
  3. DarkeKun

    DarkeKun Private E-2

    Well, its only detected as suspicious, more like, if there is anyone that know what the purpose with it is, my AV might just detect some random crap, as many free AV does. Just curious, that's all.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    But was it a detection of Cyberlink's PowerDVD or AVSMEDIA as I stated? And was it from PC Tools Spyware Doctor?
     
  5. DarkeKun

    DarkeKun Private E-2

    If I understand correct, it can have multiple purposes?
    I found it under system32 folder.

    And it's was my antivirus that detected it
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not answer my question as to whether it was detecting files for thos programs. Do you have those programs installed?


    Not helpful. We need to know what exactly was found.

    Which antivirus program? Attach a log.


    If you continue to have issues with this, then the best thing for you to do is run our cleaning procedure given below.


    Please follow the instructions in the READ & RUN ME FIRST link given below and attach the requested logs when you finish these instructions.

    READ & RUN ME FIRST. Malware Removal Guide
    • If something does not run, write down the info to explain to us later but keep on going.
    • Do not assume that because one step does not work that they all will not.

    • After completing the READ & RUN ME and attaching your logs, make sure that you tell us what problems still remain ( if any still do )!
    Helpful Notes:

    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode, you can run the steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools and the manual updates for SUPERAntiSpyware, Malwarebytes and Spybot ( links are given in the READ & RUN ME) onto another PC and then burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
    3. If you cannot seem to login to an infected user account, try using a different user account (if you have one) in either normal or safe boot mode and running only SUPERAntiSpyware and Malwarebytes while logged into this other user account. Then reboot and see if you can log into the problem user account. If you can then run SUPERAntiSpyware, Malwarebytes, ComboFix and MGtools on the infected account as requested in the instructions.
    4. To avoid additional delay in getting a response, it is strongly advised that after completing the READ & RUN ME you also read this sticky:
    Any additional post is a bump which will add more delay. Once you attach the logs, your thread will be in the work queue and as stated our system works the oldest threads FIRST.
     
  7. DarkeKun

    DarkeKun Private E-2

    Sorry for being a noob, and, i didnt know that my question demanded that amount of data, because, it was just a curious question, nothing big in it at all.. and my log is deleted, since it delete it self every once a week, when its only suspicious, i don't take backup. Sorry
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Basically without seeing a log that shows exactly what files or registry keys and in what locations they are being detected, we have no idea whether a detection is valid. An infection name is basically useless without the supporting information. Many scanners frequently have false detections, and as noted earlier, they give useless/meanining names to infections with out decribing the supposed problems caused by the infection.
     
  9. DarkeKun

    DarkeKun Private E-2

    Okay, it was my suspicion that it was a fake alert, anyway, thanks, and thanks for taking time to tell me :) I'm not good at reading, i tend to daze away, so i don't get the meaning of the message.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I never said it was a fake alert. I said we will not know for sure unless you tell us exactly what we being detected and where and I also said you should run our cleaning procedure.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds