See what we have here: unknown_file_$INSTDIR/SkyMonk.exe infected with PAK_Generic.001
See where it resides:
http://www.virustotal.com/url-scan/report.html?id=2dc1aa59754d1414e08b910b75d2b130-1323276410See the file scan results:
http://www.virustotal.com/file-scan/report.html?id=0ca983e14180413f2173d7653a716e1bec144cd384ecd77560c8d55ba385f554-1323280198Found to be suspicious here:
http://siteinspector.comodo.com/public/reports/754269See:
http://r.virscan.org/b42b1172ffe8f5047c4cb46a41671455Here the scan was given clean:
Checking: -http://letitbit.net/skymonk_25436578_91.exe
Engine version: 5.0.2.3300
Total virus-finding records: 2892364
File size: 3.56 MB
File MD5: 50023ad4b9fcd92ec3432575b084cefa
-http://letitbit.net/skymonk_25436578_91.exe - archive NSIS
>-http://letitbit.net/skymonk_25436578_91.exe/script.bin - Ok
>-http://letitbit.net/skymonk_25436578_91.exe/___\modern-header.bmp - Ok
>-http://letitbit.net/skymonk_25436578_91.exe/___\InstallOptions.dll - Ok
>-http://letitbit.net/skymonk_25436578_91.exe/State - Ok
>-http://letitbit.net/skymonk_25436578_91.exe/SkyMonk.exe packed by UPX
>>-http://letitbit.net/skymonk_25436578_91.exe/SkyMonk.exe - Ok
>-http://letitbit.net/skymonk_25436578_91.exe/update.exe packed by UPX
>>-http://letitbit.net/skymonk_25436578_91.exe/update.exe - Ok
>-http://letitbit.net/skymonk_25436578_91.exe/filter.dll packed by UPX
>>-http://letitbit.net/skymonk_25436578_91.exe/filter.dll - Ok
>-http://letitbit.net/skymonk_25436578_91.exe/english.loc packed by UPX
>>-http://letitbit.net/skymonk_25436578_91.exe/english.loc - Ok
>-http://letitbit.net/skymonk_25436578_91.exe/russian.loc packed by UPX
>>-http://letitbit.net/skymonk_25436578_91.exe/russian.loc - Ok
>-http://letitbit.net/skymonk_25436578_91.exe/skymonk.dat - Ok
>-http://letitbit.net/skymonk_25436578_91.exe/marker.exe packed by UPX
>>-http://letitbit.net/skymonk_25436578_91.exe/marker.exe - Ok
>-http://letitbit.net/skymonk_25436578_91.exe/MailRuSputnik_rfrletitbit2_s_mpcln9514_lite.exe - Ok
>-http://letitbit.net/skymonk_25436578_91.exe/___\md5dll.dll packed by UPX
>>-http://letitbit.net/skymonk_25436578_91.exe/___\md5dll.dll - Ok
>-http://letitbit.net/skymonk_25436578_91.exe/___\InetLoad.dll - Ok
>-http://letitbit.net/skymonk_25436578_91.exe/___\UserInfo.dll - Ok
>-http://letitbit.net/skymonk_25436578_91.exe/___\System.dll - Ok
>-http://letitbit.net/skymonk_25436578_91.exe/___\endownload.ini - Ok
>-http://letitbit.net/skymonk_25436578_91.exe/___\rudownload.ini - Ok
>-http://letitbit.net/skymonk_25436578_91.exe/___\ensetup.ini - Ok
>-http://letitbit.net/skymonk_25436578_91.exe/___\rusetup.ini - Ok
-http://letitbit.net/skymonk_25436578_91.exe - Ok
Is that so, really?
See:
http://vscan.urlvoid.com/file/50023ad4b9fcd92ec3432575b084cefa/c2t5bW9uay0yNTQzNjU3OC05MS1leGU=/polonus