Author Topic: Virus or FP  (Read 3396 times)

0 Members and 1 Guest are viewing this topic.

Offline JuninhoSlo

  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 849
Virus or FP
« on: January 16, 2010, 11:19:32 PM »
Hi :)

I sent exe file to VT and get these results:http://www.virustotal.com/analisis/3431f26eb643faaef01be24bfe4506ee3d1f8ba7765c168c921feb319d3f0cd5-1263679810


Could be this possible undetected malware?


http://camas.comodo.com/cgi-bin/submit?file=3431f26eb643faaef01be24bfe4506ee3d1f8ba7765c168c921feb319d3f0cd5


Have a nice day. :)

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89335
  • No support PMs thanks
Re: Virus or FP
« Reply #1 on: January 16, 2010, 11:33:40 PM »
It is highly suspicious as the camas.comodo analysis indicates, copies itself to other locations (so you should search for those) and then deletes itself. So I suggest you send the sample to avast for analysis.

What drew your attention to this file ?
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.5.6116 (build 24.5.9153.762) UI 1.0.808/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline JuninhoSlo

  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 849
Re: Virus or FP
« Reply #2 on: January 16, 2010, 11:49:12 PM »
It is highly suspicious as the camas.comodo analysis indicates, copies itself to other locations (so you should search for those) and then deletes itself. So I suggest you send the sample to avast for analysis.

What drew your attention to this file ?



I will send this file to Avast lab. Anyway thank you for your help but I didn,t install this file. ;)


Have a nice day. :)


Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37613
  • Not a avast user
Re: Virus or FP
« Reply #3 on: January 16, 2010, 11:52:02 PM »
here is an analyze tool i wanted to test, can you upload and post the result if you have the time?
http://norman.com/security_center/security_tools/submit_file/en-us

Offline JuninhoSlo

  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 849
Re: Virus or FP
« Reply #4 on: January 16, 2010, 11:56:37 PM »
here is an analyze tool i wanted to test, can you upload and post the result if you have the time?
http://norman.com/security_center/security_tools/submit_file/en-us


dropper.exe : Not detected by Sandbox (Signature: NO_VIRUS)
 
 
 [ DetectionInfo ]
    * Filename: C:\analyzer\scan\dropper.exe.
    * Sandbox name: NO_MALWARE
    * Signature name: NO_VIRUS.
    * Compressed: NO.
    * TLS hooks: NO.
    * Executable type: Application.
    * Executable file structure: OK.
    * Filetype: PE_I386.
 
 [ General information ]
    * File length:        35840 bytes.
    * MD5 hash: 838c7cdc3a53e460f6dc4ac6b81368cf.
    * SHA1 hash: 6137a03c1920bb03e9d139846f4457e13b72c9fd.

 

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37613
  • Not a avast user
Re: Virus or FP
« Reply #5 on: January 17, 2010, 12:03:33 AM »
just curious how it worked, thanks.. ;)