Are these spyware?

shortmantuff

New member
Power User
Local time
4:14 PM
Messages
171
Hey guys, I just ran a scan on SUPERAntiSpyware and it found 2 trojans. I don't think either of them are legit trojans but wanted your opinions.

C:\TOSHIBAUPDATE\UPDATEX86.EXE

&

C:\WINDOWS\CLOSESEC.EXE

Also, is there a place on the internet to check for legit spyware files? Like a list that lists them?
 

My Computer

Computer Manufacturer/Model Number
Toshiba Satellite A215-S4757
OS
Windows 7 Home Premium x86
Motherboard
AMD Turion™ 64 X2 Dual-Core Mobile Technology TL56 1.8 GHz
Memory
4096MB (2 x 2048) DDR2 667mhz Corsair
Graphics Card(s)
ATI Radeon® X1200 128MB-319MB dynamically allocated shared g
Sound Card
Realtek
Monitor(s) Displays
15.4” diagonal widescreen TruBrite®TFT LCD display at 1280x8
Screen Resolution
1280x800
Hard Drives
Internal HD: 250GB (4200RPM); Serial ATA HDD
External HD: Western Digital 320GB My Passport Elite WDMLZ3200TN USB 2.0 Portable Hard Drive (Bronze)
Case
Targus
Mouse
Logitech G7
Internet Speed
6meg

My Computer

Computer Manufacturer/Model Number
Custom
OS
Windows 7 Professional x64
CPU
Intel i7 2600K OC'd @ 4620 MHz
Motherboard
Asus P8Z68-V Pro
Memory
16GB GSkill Sniper 2133 Mhz (4x4GB)
Graphics Card(s)
EVGA GeForce GTX 480 SuperClocked+
Sound Card
Realtek High Definition Audio
Monitor(s) Displays
2x Acer S273HLbmii 27"
Screen Resolution
2 x 1920x1080
Hard Drives
64GB Crucial M4 SSD

Storage: Hitachi 1TB 5400RPM, Samsung 1.5TB 5400RPM
PSU
Corsair HW Series 750w (modular)
Case
Cooler Master HAF 932 Advanced Blue Edition
Cooling
CM Hyper 212+ CPU cooler, 3x 230mm + 1x 140mm case fans
Keyboard
Logitech MK320 (wireless)
Mouse
Logitech MK320 (wireless)
Internet Speed
30 Mb/s : 2 Mb/s
It said 4/41 programs found it to be spyware (at least I think that is what it means). So, does this mean it's legit?
 

My Computer

Computer Manufacturer/Model Number
Toshiba Satellite A215-S4757
OS
Windows 7 Home Premium x86
Motherboard
AMD Turion™ 64 X2 Dual-Core Mobile Technology TL56 1.8 GHz
Memory
4096MB (2 x 2048) DDR2 667mhz Corsair
Graphics Card(s)
ATI Radeon® X1200 128MB-319MB dynamically allocated shared g
Sound Card
Realtek
Monitor(s) Displays
15.4” diagonal widescreen TruBrite®TFT LCD display at 1280x8
Screen Resolution
1280x800
Hard Drives
Internal HD: 250GB (4200RPM); Serial ATA HDD
External HD: Western Digital 320GB My Passport Elite WDMLZ3200TN USB 2.0 Portable Hard Drive (Bronze)
Case
Targus
Mouse
Logitech G7
Internet Speed
6meg
I'd say it's probably legit. I didn't see much on Google about it being malware either.
 

My Computer

Computer Manufacturer/Model Number
Custom
OS
Windows 7 Professional x64
CPU
Intel i7 2600K OC'd @ 4620 MHz
Motherboard
Asus P8Z68-V Pro
Memory
16GB GSkill Sniper 2133 Mhz (4x4GB)
Graphics Card(s)
EVGA GeForce GTX 480 SuperClocked+
Sound Card
Realtek High Definition Audio
Monitor(s) Displays
2x Acer S273HLbmii 27"
Screen Resolution
2 x 1920x1080
Hard Drives
64GB Crucial M4 SSD

Storage: Hitachi 1TB 5400RPM, Samsung 1.5TB 5400RPM
PSU
Corsair HW Series 750w (modular)
Case
Cooler Master HAF 932 Advanced Blue Edition
Cooling
CM Hyper 212+ CPU cooler, 3x 230mm + 1x 140mm case fans
Keyboard
Logitech MK320 (wireless)
Mouse
Logitech MK320 (wireless)
Internet Speed
30 Mb/s : 2 Mb/s
Both of them are Toshiba based programs. It was just weird because I've ran SUPERAntiSpyware earlier in the week and it didn't detect these. That's why I worried a little.
 

My Computer

Computer Manufacturer/Model Number
Toshiba Satellite A215-S4757
OS
Windows 7 Home Premium x86
Motherboard
AMD Turion™ 64 X2 Dual-Core Mobile Technology TL56 1.8 GHz
Memory
4096MB (2 x 2048) DDR2 667mhz Corsair
Graphics Card(s)
ATI Radeon® X1200 128MB-319MB dynamically allocated shared g
Sound Card
Realtek
Monitor(s) Displays
15.4” diagonal widescreen TruBrite®TFT LCD display at 1280x8
Screen Resolution
1280x800
Hard Drives
Internal HD: 250GB (4200RPM); Serial ATA HDD
External HD: Western Digital 320GB My Passport Elite WDMLZ3200TN USB 2.0 Portable Hard Drive (Bronze)
Case
Targus
Mouse
Logitech G7
Internet Speed
6meg
You know those anti-virus programs. One day they don't detect anything, the next day they do.
 

My Computer

Computer Manufacturer/Model Number
Custom
OS
Windows 7 Professional x64
CPU
Intel i7 2600K OC'd @ 4620 MHz
Motherboard
Asus P8Z68-V Pro
Memory
16GB GSkill Sniper 2133 Mhz (4x4GB)
Graphics Card(s)
EVGA GeForce GTX 480 SuperClocked+
Sound Card
Realtek High Definition Audio
Monitor(s) Displays
2x Acer S273HLbmii 27"
Screen Resolution
2 x 1920x1080
Hard Drives
64GB Crucial M4 SSD

Storage: Hitachi 1TB 5400RPM, Samsung 1.5TB 5400RPM
PSU
Corsair HW Series 750w (modular)
Case
Cooler Master HAF 932 Advanced Blue Edition
Cooling
CM Hyper 212+ CPU cooler, 3x 230mm + 1x 140mm case fans
Keyboard
Logitech MK320 (wireless)
Mouse
Logitech MK320 (wireless)
Internet Speed
30 Mb/s : 2 Mb/s
can you post links from virustotal scans... please :)
 

My Computer

OS
Windows 7 Ultimate x86 SP1

My Computer

Computer Manufacturer/Model Number
Toshiba Satellite A215-S4757
OS
Windows 7 Home Premium x86
Motherboard
AMD Turion™ 64 X2 Dual-Core Mobile Technology TL56 1.8 GHz
Memory
4096MB (2 x 2048) DDR2 667mhz Corsair
Graphics Card(s)
ATI Radeon® X1200 128MB-319MB dynamically allocated shared g
Sound Card
Realtek
Monitor(s) Displays
15.4” diagonal widescreen TruBrite®TFT LCD display at 1280x8
Screen Resolution
1280x800
Hard Drives
Internal HD: 250GB (4200RPM); Serial ATA HDD
External HD: Western Digital 320GB My Passport Elite WDMLZ3200TN USB 2.0 Portable Hard Drive (Bronze)
Case
Targus
Mouse
Logitech G7
Internet Speed
6meg
ok, as I can see you gave results for:

C:\WINDOWS\CLOSESEC.EXE

vendors which detec it right now according to virus total:

a-squared - Trojan-Dropper.Win32.Mudrop.flp!A2 (note that "A2" at the end it means that only a2 engine of the a-sqaured detected it. (a-sqaured uses it's own a2 and Ikarus AV engines)) A-sqaure is known for some False Positives.
CAT-QuickHeal - Trojan.Agent.ATV (not sure about QuickHeal)
McAfee+ Artemis - Artemis!9DF7B80C4E0B(note: McAfee dosen't detect it. It is detected by McAfee Atremis only!) Artemis is cloud based technology, known for some False Positives...
TheHacker - Trojan/Downloader.gen (can't comment on this one)

Further analyses of "C:\WINDOWS\CLOSESEC.EXE" led me to finding to this:
https://forum.f-prot.com/index.php?topic=1694.0

as you can see it's official F-prot (AV company) forum.
And as you can see a few months ago, this file was detected by F-prot as malware aswell.
But look at the last post by F-Prot virus researcher/developer that it is probably False Positive and soon will be deleted from database.
Now from virustotal link you posted, we can see it has indeed been taken out of database.

So, I would say it is probably False Positive.
;)

P.S. Just noticed the Original Poster on the Forum link I gave uses laptop from Toshiba like you.
 

My Computer

OS
Windows 7 Ultimate x86 SP1
Yeah, I found that link too. I found it after I posted this though.
 

My Computer

Computer Manufacturer/Model Number
Toshiba Satellite A215-S4757
OS
Windows 7 Home Premium x86
Motherboard
AMD Turion™ 64 X2 Dual-Core Mobile Technology TL56 1.8 GHz
Memory
4096MB (2 x 2048) DDR2 667mhz Corsair
Graphics Card(s)
ATI Radeon® X1200 128MB-319MB dynamically allocated shared g
Sound Card
Realtek
Monitor(s) Displays
15.4” diagonal widescreen TruBrite®TFT LCD display at 1280x8
Screen Resolution
1280x800
Hard Drives
Internal HD: 250GB (4200RPM); Serial ATA HDD
External HD: Western Digital 320GB My Passport Elite WDMLZ3200TN USB 2.0 Portable Hard Drive (Bronze)
Case
Targus
Mouse
Logitech G7
Internet Speed
6meg

My Computer

OS
Windows 7 Ultimate x86 SP1

My Computer

OS
windows 7 ultimate 64 bit,Windows 7 ultimate 32 bit,Windows XP sp3 home
Weird...when I browse for TOSHIBAX86.EXE on Virus Total (online) I couldn't find the file. But I downloaded the tool to upload it via Send To and I found it when I browsed that way. Hmm....Oh well.

Thanks for all the help guys!
 

My Computer

Computer Manufacturer/Model Number
Toshiba Satellite A215-S4757
OS
Windows 7 Home Premium x86
Motherboard
AMD Turion™ 64 X2 Dual-Core Mobile Technology TL56 1.8 GHz
Memory
4096MB (2 x 2048) DDR2 667mhz Corsair
Graphics Card(s)
ATI Radeon® X1200 128MB-319MB dynamically allocated shared g
Sound Card
Realtek
Monitor(s) Displays
15.4” diagonal widescreen TruBrite®TFT LCD display at 1280x8
Screen Resolution
1280x800
Hard Drives
Internal HD: 250GB (4200RPM); Serial ATA HDD
External HD: Western Digital 320GB My Passport Elite WDMLZ3200TN USB 2.0 Portable Hard Drive (Bronze)
Case
Targus
Mouse
Logitech G7
Internet Speed
6meg
Back
Top