Author Topic: Win:32 Banker found in C:\WINDOWS\system32\user32.dll (Might Be False Positive)  (Read 5561 times)

0 Members and 1 Guest are viewing this topic.

Offline !Donovan

  • Web Analyst
  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 2219
    • The WAR Against Malware
http://www.virustotal.com/analisis/3f66f73002c31fd0b28b76b5d28e1c30

I don't know if its important or not nor if its a virus or not but only two anti-viruses detect it. Mcafee detected new malware and ESafe detected Win:32 Banker. If it isn't a false positive, what should my next action be? Is it required that I open the dll in notepad and give you the coding in it?

~Donovan
Familiarize Yourself! | Educate Yourself! | Beautify Yourself! | Scan Yourself!
"People who say it cannot be done should not interrupt those who are doing it."

Offline RejZoR

  • Polymorphic Sheep
  • Serious Graphoman
  • *****
  • Posts: 9406
  • We are supersheep, resistance is futile!
    • RejZoR's Flock of Sheep
Erm, avast! is not detecting it so i don't really see a problem here.
Plus the file is in a correct location.
Visit my webpage Angry Sheep Blog

Offline !Donovan

  • Web Analyst
  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 2219
    • The WAR Against Malware
Thanks for your feedback so quick. I wanted to be sure. But then again, it could be real because the first time I download, updated, and ran a full scan with Malwarebytes' Anti-Malware, it found 39 viruses, lots of Myfunweb, Trojans, and bankers.
Familiarize Yourself! | Educate Yourself! | Beautify Yourself! | Scan Yourself!
"People who say it cannot be done should not interrupt those who are doing it."

Offline RejZoR

  • Polymorphic Sheep
  • Serious Graphoman
  • *****
  • Posts: 9406
  • We are supersheep, resistance is futile!
    • RejZoR's Flock of Sheep
Can you pack this user32.dll file to 7z or RAR archive and send it to rejzor@gmail.com ?
I'll check it out for you what it is exactly.
Visit my webpage Angry Sheep Blog

Offline !Donovan

  • Web Analyst
  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 2219
    • The WAR Against Malware
I sent the file in 7z achivement to the email address you told me.


Reply:
It looks normal. But i suggest you send this file to eSafe (the one
which was detecting it as Banker) and wait for their analysis. If it's
a FP, they'll fix it, if it's not, they'll confirm it's a malware.


How do I send it to eSafe?
« Last Edit: May 03, 2009, 05:54:10 PM by Donovansrb10 »
Familiarize Yourself! | Educate Yourself! | Beautify Yourself! | Scan Yourself!
"People who say it cannot be done should not interrupt those who are doing it."