CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

A possible trojan? (15/32)

 
Post new topic   Reply to topic       All -> FavForums -> Unknown Files [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
80rg

Cadet
Cadet


Joined: May 24, 2008
Posts: 1
Location: USA

PostPosted: Sat May 24, 2008 9:45 am    Post subject: A possible trojan? (15/32)
Reply with quote

This keygen may be bound with a trojan, although it's hard to tell since it has been packed with npack. Many avs pick that up as being suspicious in itself.

MD5...: b75a9508436c9fb1fd64aedde018d948

Virustotal detections:

AntiVir 7.8.0.19 2008.05.23 TR/Crypt.XPACK.Gen
Authentium 5.1.0.4 2008.05.23 W32/NewUnknownMalware-P99!Maximus
ClamAV 0.92.1 2008.05.24 PUA.Packed.NPack-1
eSafe 7.0.15.0 2008.05.22 Suspicious File
Ewido 4.0 2008.05.23 Downloader.Banload.egn
F-Prot 4.4.4.56 2008.05.23 W32/NewUnknownMalware-P99!Maximus
Ikarus T3.1.1.26.0 2008.05.24 Virus.Win32.Virut.n
McAfee 5302 2008.05.23 New Malware.eb
Norman 5.80.02 2008.05.23 W32/Smalltroj.DZVQ
Panda 9.0.0.4 2008.05.23 Suspicious file
Sophos 4.29.0 2008.05.24 Mal/EncPk-AO
Sunbelt 3.0.1123.1 2008.05.17 Trojan.Crypt.XPACK.Gen
VBA32 3.12.6.6 2008.05.24 suspected of Trojan-PSW.Game.59 (paranoid heuristics)
VirusBuster 4.3.26:9 2008.05.23 Packed/nPack
Webwasher-Gateway 6.6.2 2008.05.24 Trojan.Crypt.XPACK.Gen

Jotti detections:

AntiVir Found TR/Crypt.XPACK.Gen
ClamAV Found PUA.Packed.NPack-1
Ikarus Found Virus.Win32.Virut.n
Norman Virus Control Found W32/Smalltroj.DZVQ
Sophos Antivirus Found Mal/EncPk-AO
VBA32 Found Trojan-PSW.Game.59 (paranoid heuristics) (probable variant)

Back to top
View users profile Send private message
tetak

MIRT Team Lead
Premium Member

Joined: Jan 19, 2007
Posts: 5869

MIRT Premium

PostPosted: Sat May 24, 2008 5:03 pm    Post subject:
Reply with quote

I ran it on a test PC and the file doesn't appear to be malware.


_________________
Got Windows XP? Help protect your PC from malware with Microsofts anti-spyware program Windows Defender.

Download it for free from http://www.microsoft.com/athome/security/spyware/software/default.mspx
Back to top
View users profile Send private message
nosirrah

Security Expert
Special Response Team

Joined: Apr 19, 2006
Posts: 6301
Location: USA
MIRT MVP Premium Rootkit Responders Security Experts SRT

PostPosted: Sat May 24, 2008 10:29 pm    Post subject:
Reply with quote

Many antimalware applications will list every crack/keygen they find as malware no matter which application it is trying break and no matter the file contents are in an effort to combat piracy .

Back to top
View users profile Send private message Send email
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Unknown Files All times are GMT
Page 1 of 1

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You cannot download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer