0 Members and 1 Guest are viewing this topic.
[ DetectionInfo ] * Filename: C:\analyzer\scan\IAAlive+7Tr-LNG.exe. * Sandbox name: NO_MALWARE * Signature name: W32/Troj_Generic.DVHLP. * Compressed: NO. * TLS hooks: YES. * Executable type: Application. * Executable file structure: OK. * Filetype: PE_I386. [ General information ] * Anti debug/emulation code present. * Display message box (sample.exe) : A debugger has been found running in your system.Please, unload it from memory and restart . * File length: 2086912 bytes. * MD5 hash: e0f54caac36f4dda13268501b037f26d. * SHA1 hash: cebf7a715a0eae3fbac642f8adcf5b4189047d72.
So , You Think it's Not Dangerous Program Or Bad Software And Not Problem , Right ?
So , What Can I Do now ?
VirTool:Win32/Obfuscator are detections for programs that have had their purpose obfuscated to hinder analysis or detection by anti-virus scanners. They commonly employ a combination of methods including encryption, compression, anti-debugging and anti-emulation techniques. These obfuscation techniques are used on various kinds of malware. The malware that lies "underneath" may have virtually any purpose.
Packed.Vmpbad!gen4 is a heuristic detection for files that may have been obfuscated or encrypted in order to conceal them from antivirus software. This heuristic detection is used to detect threats associated with multiple threat families. Quote Quote taken from Symentic Security response, low risk level but Quote files that are detected as Packed.Vmpbad!gen4 are considered malicious same quote source Symantic Security Response technical details.I would therefore classify this rather as riskware than as a possible unwanted program,polonus
Quote taken from Symentic Security response, low risk level but Quote files that are detected as Packed.Vmpbad!gen4 are considered malicious same quote source Symantic Security Response technical details.I would therefore classify this rather as riskware than as a possible unwanted program,polonus
files that are detected as Packed.Vmpbad!gen4 are considered malicious