Author Topic: Bin* compare tools  (Read 2692 times)

0 Members and 1 Guest are viewing this topic.

MrBabis

  • Guest
Bin* compare tools
« on: January 24, 2006, 11:52:56 AM »
Hi. ;)

Do you know some compare tool for binary files?
Some freeware

I got one virus that may be not virus

In proexe.dat file ("CAD-KAS HTML2Exe Baler 2.0")

Few program repports that it is virus inside of it. Avast too.
But I want to find where. To make difinitioin for clamav. And try to block code inside of it. ???

Offline igor

  • Avast team
  • Serious Graphoman
  • *
  • Posts: 11851
    • AVAST Software
Re: Bin* compare tools
« Reply #1 on: January 24, 2006, 12:39:58 PM »
Sounds like a false positive.

MrBabis

  • Guest
Re: Bin* compare tools
« Reply #2 on: January 24, 2006, 01:06:52 PM »
Here is Jotti results
-------------------
-------------------
      ProtoEXE.dat
Status:    
INFECTED/MALWARE (Note: this file has been scanned before. Therefore, this file's scan results will not be stored in the database)
MD5    d8282c779febd5b8c7d9d0e927b98a7f
Packers detected:    
-
Scanner results
AntiVir    
Found nothing
ArcaVir    
Found nothing
Avast    
Found Win32:Trojan-gen. {Delphi}
AVG Antivirus    
Found nothing
BitDefender    
Found Trojan.Click.657
ClamAV    
Found nothing
Dr.Web    
Found Trojan.DownLoader.6217
F-Prot Antivirus    
Found W32/Downloader.MNC
Fortinet    
Found nothing
Kaspersky Anti-Virus    
Found nothing
NOD32    
Found nothing
Norman Virus Control    
Found nothing
UNA    
Found TrojanClicker.Win32.Delf
VBA32    
Found Trojan.Click.657
-------------------
-------------------

I do not belive that it is virus inside of thet file, but it mat be.

File was downloaded from http://cadkas.de/
And is part of:
Direct path to file is "http:\\www.cadkas.com\ htmbaler!.exe"
(replace \ with / and no spaces)

File is RAR compressed and can be uzipped by adding "RAR" extension type to it or rename .EXE to .RAR

Also files that creates by that program, is "infected".
It deppends on that       ProtoEXE.dat is "sample" that used to create new files. When I replaced first bytes to "CD" that was also in that file that was created.
-------------------
-------------------

Is it possible that few antivirus can have same false possitive?

----------

I found now "WinMerge" and "bin2hex" tools that can be used for that(compare bin files). But if you have some other so please tell me.
« Last Edit: January 25, 2006, 01:05:57 AM by MrBabis »