From: David H. Lipman on
From: "Oreally" <sashago(a)comcast.net>

| Thanks.....

| I've loaded 6 of the files.....(there were 10 total)

| Let me know,

| Oreally


Got'em


--
Dave
http://www.claymania.com/removal-trojan-adware.html
Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp


From: David H. Lipman on
From: "David H. Lipman" <DLipman~nospam~@Verizon.Net>

| From: "Oreally" <sashago(a)comcast.net>

|| Thanks.....

|| I've loaded 6 of the files.....(there were 10 total)

|| Let me know,

|| Oreally


| Got'em

Three of the files are the same having the MD5 checksum of
f98415e3c2d1b96a5f132769f067627c




--
Dave
http://www.claymania.com/removal-trojan-adware.html
Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp


From: Oreally on
Right......8 total are: Trojan-Spy.Win32.Agent.beaf




"David H. Lipman" <DLipman~nospam~@Verizon.Net> wrote in message
news:eXpHO$hxKHA.6140(a)TK2MSFTNGP05.phx.gbl...
> From: "David H. Lipman" <DLipman~nospam~@Verizon.Net>
>
> | From: "Oreally" <sashago(a)comcast.net>
>
> || Thanks.....
>
> || I've loaded 6 of the files.....(there were 10 total)
>
> || Let me know,
>
> || Oreally
>
>
> | Got'em
>
> Three of the files are the same having the MD5 checksum of
> f98415e3c2d1b96a5f132769f067627c
>
>
>
>
> --
> Dave
> http://www.claymania.com/removal-trojan-adware.html
> Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp
>
>
From: David H. Lipman on
From: "Oreally" <sashago(a)comcast.net>

| Right......8 total are: Trojan-Spy.Win32.Agent.beaf



No, that's the detection. I'm saying that while the EXE names are different the files are
the same thus the WOULD get the same detection.

A string in the Visual Basic file is...

F:\work\hp\systemwiz\SWR_Wizard\RunLinkReset\RunLinkReset.vbp'

Which jives with "HP Recovery Wizard".




--
Dave
http://www.claymania.com/removal-trojan-adware.html
Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp


From: Oreally on
Ok....so what do I do? Are they false positives?





"David H. Lipman" <DLipman~nospam~@Verizon.Net> wrote in message
news:eWI$VSixKHA.2012(a)TK2MSFTNGP04.phx.gbl...
> From: "Oreally" <sashago(a)comcast.net>
>
> | Right......8 total are: Trojan-Spy.Win32.Agent.beaf
>
>
>
> No, that's the detection. I'm saying that while the EXE names are
> different the files are
> the same thus the WOULD get the same detection.
>
> A string in the Visual Basic file is...
>
> F:\work\hp\systemwiz\SWR_Wizard\RunLinkReset\RunLinkReset.vbp'
>
> Which jives with "HP Recovery Wizard".
>
>
>
>
> --
> Dave
> http://www.claymania.com/removal-trojan-adware.html
> Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp
>
>