Odd Virus. Trojan horse SHeur3.BQVB

Discussion in 'Malware Help (A Specialist Will Reply)' started by Arcanum, Mar 6, 2011.

  1. Arcanum

    Arcanum Private E-2

    Today I got told by my Resident Shield that a Trojan was in one of my game files and then it shoved it down the Virus Vault. So I reinstalled the thing, went right through the trouble of re-updating it, and voila, it's back. I put it as odd because ESET's online scanner is telling me its clean and so is Malware Malbytes. I also found a second one of the same type when the Resident Shield suddenly popped up telling me it was in my System Restore earlier today. (It's not the first one, though it is the first one this year.)

    Right now both are in the Virus Vault. Any idea what both these viruses are? And how is it every time I reupdate my updater, it comes back?
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It could very well be a false positive. You can check the file at Jotti's:

    Click on the following link and use the below steps to scan a file: Virustotal
    Click the Browse... button.
    Navigate to the file FileToBeScanned

    • Where FileToBeScanned is the actual file to be scanned. Like C:\WINDOWS\System32\vdmt16.sys
     
  3. Arcanum

    Arcanum Private E-2

    Okay, I tried uploading the splash.exe to VirusTotal (The AVG alert popped up again but I just closed the window for now.), but VirusTotal doesn't give me an answer. It's like it just refreshed the page.

    But the dmy file, whatever that means. Comes out like this.

    File name: splash.dmy
    Submission date: 2011-03-06 23:41:53 (UTC)
    Current status: queued (#2) queued (#2) analysing finished
    Result: 0/ 43 (0.0%)

    I'm really hoping REALLY hard that it's just a false positive, but the fact that the ResidentShield spotted another one of the same type in the System Restore files yesterday also bugs me.
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The restore point has an exact copy of the file. Probably taken before the Resident Shield zapped it. Are you sure you are giving a full path to the file for Jotti to scan?
     
  5. Arcanum

    Arcanum Private E-2

    Yep, unless the AVG acts first and cuts it off preventing the file from being sent.

    Okay new odd bit, before I reinstalled the thing to pre-updater stage, it can be uploaded on to VirusTotal.

    File name: Splash.exe
    Submission date: 2011-03-07 00:35:58 (UTC)
    Current status: queued (#6) queued analysing finished
    Result: 0/ 42 (0.0%)

    After updating to the current version of the updater, then it can't be uploaded. Should I set AVG to ignore it first then send it in?
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes, you can just have AVG ignore those files. As Jotti reported, none of the scanners reported it as malware, so you just have to do the above and then you should be able to run the program without issue.
     
  7. Arcanum

    Arcanum Private E-2

    So before I do that, what is Trojan SHeur3.BQVB anyway? Better know than to not and unintentionally damage the computer in the process.

    By the way, is AVG trustworthy?

    In case this it is a virus really in disguise that has messed up my files, what precautions should I take?
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Not a clue. No result from a search either. So it is just what AVG happens to name it. Again, I don't believe it is anything to worry about. You need to tell AVG to ignore that program.
    It is about as trustworthy as any AV software can be, which is to say, it can throw up false positives just like the rest of them.
    None of the scanners report it as a virus. However, you should work your way through this:

    How to Protect yourself from malware!
     
  9. Arcanum

    Arcanum Private E-2

    Okay odd point. My problem self-rectified. AVG doesn't see it as a virus anymore when I reinstalled it and reupdated yesterday. I hadn't even set it to ignore yet.

    So I guess this means case closed?
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Guess so. ;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds