Author Topic: Suspicious file  (Read 4615 times)

0 Members and 1 Guest are viewing this topic.

aquilax

  • Guest
Suspicious file
« on: April 08, 2008, 10:53:22 AM »
Someone is posting in different forums a link to download a rar file with inside an exe, avast! antivirus has found nothing but perhaps is a new trojan or virus.

hxxp://www.tng7.com/the_list/1206578326-pstats.rar
« Last Edit: April 08, 2008, 05:18:11 PM by aquilax »

Offline Maxx_original

  • Moderator
  • Super Poster
  • *
  • Posts: 1479
Re: Suspicious file
« Reply #1 on: April 08, 2008, 01:18:52 PM »
we'll take a look..

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: Suspicious file
« Reply #2 on: April 08, 2008, 01:36:25 PM »
It's better do not post live links to malware or false positives.
Can you edit http to hxxp for instance.
The best things in life are free.

aquilax

  • Guest
Re: Suspicious file
« Reply #3 on: April 14, 2008, 02:20:26 PM »
Here a link to the same host to download another suspicious file

hxxp://tng7.com/downloads/wow_nude_patch_1.11.zip

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: Suspicious file
« Reply #4 on: April 14, 2008, 04:24:32 PM »
hxxp://tng7.com/downloads/wow_nude_patch_1.11.zip
Hope the virus analysts take a look on this one...
The best things in life are free.

Tin_W

  • Guest
Re: Suspicious file
« Reply #5 on: April 14, 2008, 11:21:06 PM »
The first one is detected by AVG and Antivir and some others as a virus.

The second one was only detected by Ikarus , Mcafee and Webwasher.

I've also uploaded the second file to anubis and it's clear that it's a pretty nasty virus/trojan.


Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33926
  • malware fighter
Re: Suspicious file
« Reply #6 on: April 14, 2008, 11:57:10 PM »
Hallo Tin_W,

Kun je nog even aangeven wat de namen waren van de gevonden malware. Overigens bedankt voor de alerte melding,

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Maxx_original

  • Moderator
  • Super Poster
  • *
  • Posts: 1479
Re: Suspicious file
« Reply #7 on: April 15, 2008, 08:59:24 AM »
the files were analyzed yesterday.. a proper detection will be released soon...

Tin_W

  • Guest
Re: Suspicious file
« Reply #8 on: April 15, 2008, 12:50:36 PM »
@polonus,

De eerste werd herkend door antivir als heur/malware (als k het goed heb zit nu op school dus kan niet alles even opnieuw uploaden)
Maar heb hem geupload naar avira en het is een virus.

De 2de heb ik gisteren naar avira gestuurd en dat is een trojan.