Author Topic: please help check this file  (Read 4162 times)

0 Members and 1 Guest are viewing this topic.

leeviruslee

  • Guest
please help check this file
« on: October 18, 2010, 03:51:48 AM »
Hi great guys,

I download a file from below link
hxxp://www.mjbox.com/r/bk/bkys0812/VMware%E6%B3%A8%E5%86%8C%E6%9C%BA.rar

it will enable webcam a short while,and stay in the system without anything
but the virus scan can't find anything?

can you help me to check this file is safe or not?


Thanks~
« Last Edit: October 18, 2010, 04:37:22 AM by leeviruslee »

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89051
  • No support PMs thanks
Re: please help check this file
« Reply #1 on: October 18, 2010, 04:19:51 AM »
First - Please 'modify' your post change the URL from http to hXXp or www to wXw, to break the link and avoid accidental exposure to suspect sites and files, thanks.

Well there are some scanners that at the very least consider it suspect, see http://www.virustotal.com/file-scan/report.html?id=ff23462fcd0966b5fdf2d2bea27f9c956e12aeb2dbf344693fd458359bb681ba-1287368224.

I know under normal circumstances I wouldn't download a file with this kind of file name in the first place.

Send the sample/s to avast as a Undetected Malware:
Open the chest and right click in the Chest and select Add, navigate to where you have the sample and add it to the chest (see image). Once in the chest, right click on the file and select 'Submit to virus lab...' complete the form and submit, the file will be uploaded during the next update.
« Last Edit: October 18, 2010, 04:22:38 AM by DavidR »
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

leeviruslee

  • Guest
Re: please help check this file
« Reply #2 on: October 18, 2010, 04:47:03 AM »
Hi! David ,

Thanks for your help.



First - Please 'modify' your post change the URL from http to hXXp or www to wXw, to break the link and avoid accidental exposure to suspect sites and files, thanks.

Well there are some scanners that at the very least consider it suspect, see http://www.virustotal.com/file-scan/report.html?id=ff23462fcd0966b5fdf2d2bea27f9c956e12aeb2dbf344693fd458359bb681ba-1287368224.

I know under normal circumstances I wouldn't download a file with this kind of file name in the first place.

Send the sample/s to avast as a Undetected Malware:
Open the chest and right click in the Chest and select Add, navigate to where you have the sample and add it to the chest (see image). Once in the chest, right click on the file and select 'Submit to virus lab...' complete the form and submit, the file will be uploaded during the next update.


Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89051
  • No support PMs thanks
Re: please help check this file
« Reply #3 on: October 18, 2010, 05:17:45 AM »
No problem, glad I could help.

Welcome to the forums.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline Marc57

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1944
  • KISS Rules The World!!!
    • KISS Army
Re: please help check this file
« Reply #4 on: October 18, 2010, 06:00:51 AM »
You Wanted the Best You Got the Best the Hottest Band in the World KISS!!!

Offline Marc57

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1944
  • KISS Rules The World!!!
    • KISS Army
Re: please help check this file
« Reply #5 on: October 18, 2010, 07:03:36 AM »
This is definitely a trojan.

Just got this back from Cat-Quickheal.

"Dear Sir,

Thank you for the files.
Found malicious code inside the files.
Solution for the same will be uploaded in next update.

Regards,
- Rahul

Ticket Details
===================
Ticket ID: FMW-467375
Department: VirusLab
Priority: High
Status: Closed"



Sophos:

Hello,

Thank you for contacting Sophos Technical Support.

**Please note that this is an automated response. If you have any questions, require assistance or clarification on this analysis, please feel free to reply to this email quoting this case number in the subject line.**

The file(s) submitted were malicious in nature and detection will be available on the Sophos Databank shortly.


short-VMWARE_1.EXE -- identity created/updated (New detection Troj/Agent-OZS)
VMware.zip -- archive file

Please do not hesitate in contacting us by replying to this email if you have any questions or concerns.

Kind regards,

Sophos Technical Support





« Last Edit: October 18, 2010, 08:26:29 AM by Marc57 »
You Wanted the Best You Got the Best the Hottest Band in the World KISS!!!

Offline Marc57

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1944
  • KISS Rules The World!!!
    • KISS Army
Re: please help check this file
« Reply #6 on: October 18, 2010, 08:19:32 PM »
This is now being detected by Malwarebytes.
You Wanted the Best You Got the Best the Hottest Band in the World KISS!!!

leeviruslee

  • Guest
Re: please help check this file
« Reply #7 on: October 19, 2010, 04:19:47 AM »
Thanks for your kindly and great support!

Offline Marc57

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1944
  • KISS Rules The World!!!
    • KISS Army
Re: please help check this file
« Reply #8 on: October 19, 2010, 04:45:47 AM »
Your Welcome.
You Wanted the Best You Got the Best the Hottest Band in the World KISS!!!

Offline Left123

  • There Is No Patch For Human Stupidity.
  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 1048
  • Proud Community Member&Helper.
AMD Athlon(tm) X2 Dual-Core Processor 4200+ - 2.20 GHz,3,00 GB RAM -
Browser:Mozilla Firefox +WOT - SoftWare:CCleaner - Windows 7 32 bit
No Anti-Virus