Author Topic: Win32:Trojan-gen {Other} AND trafly.zip  (Read 10348 times)

0 Members and 1 Guest are viewing this topic.

Bubbator

  • Guest
Win32:Trojan-gen {Other} AND trafly.zip
« on: August 19, 2008, 06:35:34 PM »
Hi!
I tried to download a game cheat, trafly.zip, and ;D Avast stopped me and prevented "Win32:Trojan-gen {Other}" from being downloaded. The cheat is for Tomb Raider Anniversary and videos of it in use are all over the web. The advice on unofficial Tomb Raider forums was to go ahead, disable antivirus, and not to worry. :o So, I came here. I see a lot of sad tales of  Win32:Trojan-gen {Other} and a lot of False Positive references.
I am not about to "drink the Kool-Aid" but I am wondering if there is a definitive answer about trafly.zip and FP's on Win32:Trojan-gen {Other} out there?
:-\
B.

Offline Justin_22

  • Avast Evangelist
  • Poster
  • ***
  • Posts: 445
  • Free your soul and let it fly
Re: Win32:Trojan-gen {Other} AND trafly.zip
« Reply #1 on: August 19, 2008, 07:26:19 PM »
Not to promote cheats and things but to be sure if a File is a false Positive please upload the file to www.virustotal.com and use the "Browse" feature to find the file and post the report here

-Justin
Avast!  2014 beta - Sandboxie - K9 Web Protection

Bubbator

  • Guest
Re: Win32:Trojan-gen {Other} AND trafly.zip
« Reply #2 on: August 19, 2008, 07:59:00 PM »
Hi and Thanks!
How do I safely upload the file? Avast won't let me download it.
B.

Online DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89690
  • No support PMs thanks
Re: Win32:Trojan-gen {Other} AND trafly.zip
« Reply #3 on: August 19, 2008, 08:20:02 PM »
First pause the web shield, that will allow for it to be downloaded, but don't open it as the standard shield would then alert if you extract the files.

Create a folder called Suspect in the C:\ drive, e.g. C:\Suspect. Now exclude that folder in the Standard Shield, Customize, Advanced, Add, type (or copy and paste) C:\Suspect\* That will stop the standard shield scanning any file you put in that folder. You should now be able to export any file in the chest (or other HDD location) to this folder and upload it to VirusTotal without avast alerting.

Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD - 27" external monitor 1440p 2560x1440 resolution - avast! free  24.9.6130 (build 24.9.9452.762) UI 1.0.818/ Firefox, uBlock Origin Lite, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Bubbator

  • Guest
Re: Win32:Trojan-gen {Other} AND trafly.zip
« Reply #4 on: August 19, 2008, 08:27:44 PM »
Super!
Thanks!
Will post when I find out.
Gotta go.
B.

Online DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89690
  • No support PMs thanks
Re: Win32:Trojan-gen {Other} AND trafly.zip
« Reply #5 on: August 19, 2008, 09:13:45 PM »
No problem, glad I could help.

Welcome to the forums.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD - 27" external monitor 1440p 2560x1440 resolution - avast! free  24.9.6130 (build 24.9.9452.762) UI 1.0.818/ Firefox, uBlock Origin Lite, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Bubbator

  • Guest
Re: Win32:Trojan-gen {Other} AND trafly.zip
« Reply #6 on: August 20, 2008, 05:10:47 AM »
 :( virustotal.com finds 53% of all engines [19/36] don't like trafly.zip. several different worms are blamed. since trafly is a 'hacking' kind of product I won't trust or install it.
Hats off to your good work!
B.

Bubbator

  • Guest
Re: Win32:Trojan-gen {Other} AND trafly.zip
« Reply #7 on: August 20, 2008, 05:12:44 AM »
File TRAFly.zip received on 08.03.2008 21:29:19 (CET)
Current status: finished

Result: 19/36 (52.78%)
 Compact Print results 
Antivirus Version Last Update Result
AhnLab-V3 - - -
AntiVir - - -
Authentium - - -
Avast - - Win32:Trojan-gen {Other}
AVG - - -
BitDefender - - Trojan.Generic.175504
CAT-QuickHeal - - -
ClamAV - - PUA.Packed.NPack-3
DrWeb - - -
eSafe - - Suspicious File
eTrust-Vet - - Win32/VMalum.DCCU
Ewido - - -
F-Prot - - -
F-Secure - - W32/Suspicious_N.gen
Fortinet - - -
GData - - Win32:Trojan-gen 
Ikarus - - Trojan-PWS.Win32.Lmir.beu
K7AntiVirus - - -
Kaspersky - - -
McAfee - - New Malware.aq
Microsoft - - -
NOD32v2 - - -
Norman - - W32/Suspicious_N.gen
Panda - - -
PCTools - - Packed/NSPack
Prevx1 - - Malicious Software
Rising - - Backdoor.Win32.Small.jn
Sophos - - Mal/Packer
Sunbelt - - -
Symantec - - Trojan Horse
TheHacker - - W32/Behav-Heuristic-063
TrendMicro - - PAK_Generic.001
VBA32 - - -
ViRobot - - -
VirusBuster - - Packed/NSPack
Webwasher-Gateway - - Win32.Malware.gen (suspicious)
Additional information
MD5: cd6198bff6697823b96ce45452977c1e
SHA1: 4271bd14bb08fdabba19cc07566c8a1000eb0895
SHA256: 23722ab06618b11d354292ceafe4d16639c4503382f6d3664605b8ab2ccbc5f0
SHA512: daa300227e23f735a05b29eb5565a9c0458c63e783b59541b08de71e202c36ee6a0238d0727b21268e5e5a61d02883bf1f6e7c3594791b9036f490b70ccb49a4

wyrmrider

  • Guest
Re: Win32:Trojan-gen {Other} AND trafly.zip
« Reply #8 on: August 20, 2008, 05:22:50 AM »
since the detections are general or heuristic how about uploading it to avast for a look-see
actually VT will do that for you
check the detection again in a couple of weeks and see if avast still detects

Online DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89690
  • No support PMs thanks
Re: Win32:Trojan-gen {Other} AND trafly.zip
« Reply #9 on: August 20, 2008, 03:39:20 PM »
I wouldn't rely on VT sending anything to Alwil, as there is no info on when and how these would be sent; also there have been a few posts in the forums that much of what they get from VT isn't good/helpful.

However, in this particular case they wouldn't send anything anyway as the only send samples to participating AVs if they 'don't' detect a sample as infected.

So it is most certainly up to the user to send the sample if they feel it needs further analysis.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD - 27" external monitor 1440p 2560x1440 resolution - avast! free  24.9.6130 (build 24.9.9452.762) UI 1.0.818/ Firefox, uBlock Origin Lite, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Bubbator

  • Guest
Re: Win32:Trojan-gen {Other} AND trafly.zip
« Reply #10 on: August 20, 2008, 04:21:27 PM »
Hi again,
I sent file to virus@avast.com. I didn't (know how to) password protect it, so I hope it gets there.
B

Online DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89690
  • No support PMs thanks
Re: Win32:Trojan-gen {Other} AND trafly.zip
« Reply #11 on: August 20, 2008, 04:39:03 PM »
You can also add the file to the User Files (File, Add) section of the avast chest (if it isn't already there) where it can do no harm and send it from there (select the file, right click, email to Alwil Software). No need to zip and PW protect when the sample is sent from chest. A copy of the file/s will remain in the original location, so any further action you take can remove that.

Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD - 27" external monitor 1440p 2560x1440 resolution - avast! free  24.9.6130 (build 24.9.9452.762) UI 1.0.818/ Firefox, uBlock Origin Lite, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Bubbator

  • Guest
Re: Win32:Trojan-gen {Other} AND trafly.zip
« Reply #12 on: August 20, 2008, 05:23:25 PM »
OOHHH!
That was easy!
Thanks,
B.
 8)
« Last Edit: August 20, 2008, 05:25:00 PM by Bubbator »

Online DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89690
  • No support PMs thanks
Re: Win32:Trojan-gen {Other} AND trafly.zip
« Reply #13 on: August 20, 2008, 07:06:46 PM »
You're welcome, easy is good ;D
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD - 27" external monitor 1440p 2560x1440 resolution - avast! free  24.9.6130 (build 24.9.9452.762) UI 1.0.818/ Firefox, uBlock Origin Lite, uMatrix/ MailWasher Pro/ Avast! Mobile Security

wyrmrider

  • Guest
Re: Win32:Trojan-gen {Other} AND trafly.zip
« Reply #14 on: August 20, 2008, 07:46:54 PM »
I learn something new every post
thanks
DavidR