Avast WEBforum

Other => Viruses and worms => Topic started by: altrad on May 06, 2010, 10:30:34 PM

Title: virus dans winrar arabic version
Post by: altrad on May 06, 2010, 10:30:34 PM
Enter here Newsflash warning WinRar to use the Arabic language
A picture of the program
(http://www.ar-tr.com/uploaded/uploading/winrar6.gif)

Arabic version of the company from infected Discovered Kaspersky
(http://img203.imageshack.us/img203/9872/sshot1d.png)

Sits on VirusTotal

5/41
http://www.virustotal.com/analisis/5ffd47f50775c2cef712f90fd97342f516315baf555c7790eaad487e7085429d-1273152057 (http://www.virustotal.com/analisis/5ffd47f50775c2cef712f90fd97342f516315baf555c7790eaad487e7085429d-1273152057)

site web Company winrar

www.rarlab.com
Title: Re: virus dans winrar arabic version
Post by: Hermite15 on May 06, 2010, 10:47:14 PM
hi,

don't post in yellow it's impossible to read ;D
Title: Re: virus dans winrar arabic version
Post by: Pondus on May 06, 2010, 10:52:36 PM
@Logos.......naaaa...you just bend way out to one side...... ;D

just for fun i downloaded the following version and scanned on VirusTotal  32bit Bulgarian / Norwegian / Chinese
all came up CLEAN....so this Arabic version looks to be infected


Anubis Analysis Report
http://anubis.iseclab.org/?action=result&task_id=145cae427390a8aa4fd18411293cc75c5&format=html
Title: Re: virus dans winrar arabic version
Post by: Hermite15 on May 06, 2010, 10:57:52 PM
doesn't work here, I can't read  :'( ;D >>> could be a side effect of that malware ???
Title: Re: virus dans winrar arabic version
Post by: 13thSlayer on May 07, 2010, 05:11:52 AM
I'll translate the first post to a normal language  :-\
I post a warning that popped up while using Arabic version of WinRar
A picture of the program itself:
<pic>
The virus originally was found by Kaspersky, picture of the warning:
<pic>
VirusTotal results:
<link>
WinRar's company site:
<link>
Title: Re: virus dans winrar arabic version
Post by: 13thSlayer on May 07, 2010, 05:13:41 AM
doesn't work here, I can't read  :'( ;D >>> could be a side effect of that malware ???
Just highlight whatever the dude wrote with your mouse or touchpad or whatever. Sheesh.
Title: Re: virus dans winrar arabic version
Post by: Altarir. on May 07, 2010, 05:21:58 AM
By the way, normally winrar doesn't have any file named "wrar393a.exe"

thus, its not related to winrar. although it might be some crack for winrar(infected with trojan  ;))
Title: Re: virus dans winrar arabic version
Post by: polonus on May 07, 2010, 04:30:29 PM
Halio Altarir,

This is the virustotal result for that particular executable: http://www.virustotal.com/analisis/5ffd47f50775c2cef712f90fd97342f516315baf555c7790eaad487e7085429d-1273152057
Malware from a fake torrent download site for Winrar + Keygen:
htxp://wXw.torrentz.com/a9f4be7f3a8c812cf23889a8c56a0690a552447c

polonus
Title: Re: virus dans winrar arabic version
Post by: superhacker on May 07, 2010, 04:50:13 PM
I think who translate the program is the person who put the trojan"so i dont enter arabic websites",and i think also that 7-ZIP is better and anyway is an open source
Title: Re: virus dans winrar arabic version
Post by: 13thSlayer on May 07, 2010, 04:51:02 PM
Halio Altarir,
Altarir is not Halio, whatever that is.
Title: Re: virus dans winrar arabic version
Post by: 13thSlayer on May 07, 2010, 04:51:46 PM
I think who translate the program is the person who put the trojan"so i dont enter arabic websites",and i think also that 7-ZIP is better and anyway is an open source
7-Zip is totally awesome, agreed, however PeaZip is also worth a shot  :)
Title: Re: virus dans winrar arabic version
Post by: Pondus on May 07, 2010, 05:47:06 PM
Confirmed by Norman the detection is good - Refroso.AB
Title: Re: virus dans winrar arabic version
Post by: Marc57 on May 07, 2010, 06:55:54 PM
I sent this to Microsoft, They say this is not malware.
Title: Re: virus dans winrar arabic version
Post by: Pondus on May 07, 2010, 07:15:59 PM
Well i sendt it to avast and MBAM yesterday (5 post before you Marc  ;)  ) so wonder what conclusion they will have   ???


just scanned with MBAM and not detected yet....soooo.....maybe tomorrow..
Title: Re: virus dans winrar arabic version
Post by: Marc57 on May 07, 2010, 07:23:36 PM
I sent it to MBAM also (Sorry I didn't see you had already sent it) So they should be able to do a double take.  ;D ;D
Title: Re: virus dans winrar arabic version
Post by: Pondus on May 08, 2010, 11:40:02 AM
ThreatExpert - infected
http://www.threatexpert.com/report.aspx?md5=c67d415e114eb1efbfbd4450a2b14f39
Title: Re: virus dans winrar arabic version
Post by: polonus on May 08, 2010, 01:42:40 PM
Hi Pondus,

Did you see this inside the malware description?
CLSID{"B41DB860-8EE4-11D2-9906-E49FADC173CA"}
= a malicious CLSID, that the malware you linked to shares with a.o. W32/Sality.gen.e [McAfee] ; Mal/Sality-D [Sophos] ; Virus:Win32/Sality.AT [Microsoft] worms etc. re:, also: http://www.bleepingcomputer.com/forums/lofiversion/index.php/t269541.html
apparently a malicious Winrar plug-in: http://home.mcafee.com/VirusInfo/VirusProfile.aspx?key=168299

polonus
Title: Re: virus dans winrar arabic version
Post by: Pondus on May 10, 2010, 01:14:11 PM
The story continues.....

New mail from Norman the detection was a False Positive so the file is CLEAN
and Avira say CLEAN

end thats the end of that........maybe.... ;D
Title: Re: virus dans winrar arabic version
Post by: hide on May 10, 2010, 05:57:02 PM
McAfee classified the program WinRAR latest version of Trojan-infected can infect the system and crashing to the McAfee report sent to the company producing the program for this injury caused by this program for equipment users in the Arab world

Thank you
   :D
Title: Re: virus dans winrar arabic version
Post by: hide on May 11, 2010, 12:03:57 PM
 ???

What Happened About This Software Winrar v393 Arabic ???

 ??? ??? ???