Jump to content

Malwarebytes

this needs checked for malware


22 replies to this topic

#1
SIR****TMG

    Regular Member

  • Honorary Members
  • PipPip
  • 68 posts
hxxp://lite-anti-virus-scan.com/promo/1/img/flist.js thank you

#2
Marcus

    Elite Member

  • Honorary Members
  • PipPipPipPipPip
  • 592 posts
  • Gender:Male
  • Location:London, UK

View PostSIR****TMG, on Feb 22 2009, 03:29 PM, said:

hxxp://lite-anti-virus-scan.com/promo/1/img/flist.js thank you

Avast! V.4 detects this: "JS:FakeAV-G [Trj]" as being on that site; it reports the same infection as being present on the tradedaublerDOTcom site. Infection stopped pre-download by Avast!

#3
Maniac

    I Love Andriana

  • Experts
  • PipPipPipPipPipPip
  • 10,164 posts
  • Gender:Male
  • Location:Bulgaria, EU
  • Interests:Information security and web development
This file is detected only by Avast! and G-Data. I send e-mail to Avast to check this file again.
Posted Image

My help is free, however, if you wish to make a small donation to show appreciation and to help me continue the fight against Malware, then click here Posted Image

#4
Raid

    Malware Researcher

  • Experts
  • PipPipPipPipPipPip
  • 1,549 posts
  • Gender:Male
  • Location:United States
Hmm.. I think it's being detected for name contents.. here's what I got when I tried to load it:

[code]
var flist=new Array();
flist[0] = '$winnt$.inf';
flist[1] = '12520437.cpx';
flist[2] = '12520850.cpx';
flist[3] = '6to4svc.dll';
flist[4] = 'aaaamon.dll';
flist[5] = 'aaclient.dll';
flist[6] = 'AboutRepliGo.dll';
flist[7] = 'ac3acm.acm';
flist[8] = 'access.cpl';
flist[9] = 'acctres.dll';
flist[10] = 'accwiz.exe';
flist[11] = 'acelpdec.ax';
flist[12] = 'acledit.dll';
flist[13] = 'aclui.dll';
flist[14] = 'activeds.dll';
flist[15] = 'activeds.tlb';
flist[16] = 'actmovie.exe';
flist[17] = 'actxprxy.dll';
flist[18] = 'ADME.DLL';
flist[19] = 'admparse.dll';
flist[20] = 'admwprox.dll';
flist[21] = 'admxprox.dll';
flist[22] = 'adptif.dll';
flist[23] = 'adsiis.dll';
flist[24] = 'adsldp.dll';
flist[25] = 'adsldpc.dll';
flist[26] = 'adsmsext.dll';
flist[27] = 'adsnds.dll';
flist[28] = 'adsnt.dll';
flist[29] = 'adsnw.dll';
flist[30] = 'advapi32.dll';
flist[31] = 'advpack.dll';
flist[32] = 'agas.dll';
flist[33] = 'ahui.exe';
flist[34] = 'alg.exe';
flist[35] = 'alrsvc.dll';
flist[36] = 'amcompat.tlb';
flist[37] = 'amstream.dll';
flist[38] = 'ansi.sys';
flist[39] = 'apcups.dll';
flist[40] = 'append.exe';
flist[41] = 'apphelp.dll';
flist[42] = 'appmgmts.dll';
flist[43] = 'appmgr.dll';
flist[44] = 'appwiz.cpl';
flist[45] = 'ArmAccess.dll';
flist[46] = 'arp.exe';
flist[47] = 'asctrls.ocx';
flist[48] = 'asferror.dll';
flist[49] = 'asfsipc.dll';
flist[50] = 'asr_fmt.exe';
flist[51] = 'asr_ldm.exe';
flist[52] = 'asr_pfu.exe';
flist[53] = 'asycfilt.dll';
flist[54] = 'at.exe';
flist[55] = 'AtalaImg2.dll';
flist[56] = 'AtalaIS.dll';
flist[57] = 'AtalCtrl.ocx';
flist[58] = 'athprxy.dll';
flist[59] = 'ati2cqag.dll';
flist[60] = 'ati2dvag.dll';
flist[61] = 'ati2edxx.dll';
flist[62] = 'ati2evxx.dll';
flist[63] = 'ati2evxx.exe';
flist[64] = 'Ati2mdxx.exe';
flist[65] = 'ati2sgag.exe';
flist[66] = 'ati3duag.dll';
flist[67] = 'ATIDDC.DLL';
flist[68] = 'ATIDEMGR.dll';
flist[69] = 'ATIDEMGX.dll';
flist[70] = 'atifglpf.xml';
flist[71] = 'atiicdxx.dat';
flist[72] = 'atiiiexx.dll';
flist[73] = 'atikvmag.dll';
flist[74] = 'atioglx1.dll';
flist[75] = 'atioglx2.dll';
flist[76] = 'atioglxx.dll';
flist[77] = 'atiok3x2.dll';
flist[78] = 'atipdlxx.dll';
flist[79] = 'atitvo32.dll';
flist[80] = 'ativcoxx.dll';
flist[81] = 'ativva5x.dat';
flist[82] = 'ativva6x.dat';
flist[83] = 'ativvaxx.dat';
flist[84] = 'ativvaxx.dll';
flist[85] = 'atkctrs.dll';
flist[86] = 'atl.dll';
flist[87] = 'atl71.dll';
flist[88] = 'AtlColor.ocx';
flist[89] = 'atmadm.exe';
flist[90] = 'atmfd.dll';
flist[91] = 'atmlib.dll';
flist[92] = 'atmpvcno.dll';
flist[93] = 'atrace.dll';
flist[94] = 'attrib.exe';
flist[95] = 'Audiodev.dll';
flist[96] = 'audiosrv.dll';
flist[97] = 'auditusr.exe';
flist[98] = 'authz.dll';
flist[99] = 'autochk.exe';
flist[100] = 'autoconv.exe';
flist[101] = 'autodisc.dll';
flist[102] = 'AUTOEXEC.NT';
flist[103] = 'autofmt.exe';
flist[104] = 'autolfn.exe';
flist[105] = 'avicap.dll';
flist[106] = 'avicap32.dll';
flist[107] = 'avifil32.dll';
flist[108] = 'avifile.dll';
flist[109] = 'avmeter.dll';
flist[110] = 'avtapi.dll';
flist[111] = 'avwav.dll';
flist[112] = 'basesrv.dll';
flist[113] = 'bass.dll';
flist[114] = 'BASSMOD.dll';
flist[115] = 'basswma.dll';
flist[116] = 'batmeter.dll';
flist[117] = 'batt.dll';
flist[118] = 'BCGCBPRO800.dll';
flist[119] = 'BCGCBPRO800u.dll';
flist[120] = 'BCGPOleAcc.dll';
flist[121] = 'bidispl.dll';
flist[122] = 'bios1.rom';
flist[123] = 'bios4.rom';
flist[124] = 'bitsprx2.dll';
flist[125] = 'bitsprx3.dll';
flist[126] = 'blackbox.dll';
flist[127] = 'blastcln.exe';
flist[128] = 'bootcfg.exe';
flist[129] = 'bootok.exe';
flist[130] = 'bootvid.dll';
flist[131] = 'bootvrfy.exe';
flist[132] = 'bopomofo.uce';
flist[133] = 'browselc.dll';
flist[134] = 'browser.dll';
flist[135] = 'browseui.dll';
flist[136] = 'browsewm.dll';
flist[137] = 'bt2k_ins.dll';
flist[138] = 'BtAudioHelper.dll';
flist[139] = 'btbigbmp.dll';
flist[140] = 'btbip.dll';
flist[141] = 'btcpl.cpl';
flist[142] = 'btcpl.cpl.manifest';
flist[143] = 'btcss.dll';
flist[144] = 'btcss.dll.manifest';
flist[145] = 'btdev.dll';
flist[146] = 'bthci.dll';
flist[147] = 'bthcrp.dll';
flist[148] = 'bthcrpui.dll';
flist[149] = 'bthprops.cpl';
flist[150] = 'bthserv.dll';
flist[151] = 'btins.dll';
flist[152] = 'BTNCopy.dll';
flist[153] = 'BTNCopy.tlb';
flist[154] = 'BTNeighborhood.dll';
flist[155] = 'BTNeighborhood.dll.manifest';
flist[156] = 'BTNeighborhood.tlb';
flist[157] = 'btosif.dll';
flist[158] = 'btosif_notes.dll';
flist[159] = 'btosif_ol.dll';
flist[160] = 'btosif_olx.dll';
flist[161] = 'btpanui.dll';
flist[162] = 'btprn2k.dll';
flist[163] = 'btrez.dll';
flist[164] = 'btrezxp.dll';
flist[165] = 'btsec.dll';
flist[166] = 'btsendto.dll';
flist[167] = 'btsendto_ie.dll';
flist[168] = 'btsendto_lnagent.nsf';
flist[169] = 'btsendto_notes.dll';
flist[170] = 'btsendto_office.dll';
flist[171] = 'btsendto_wab.dll';
flist[172] = 'btwhidcs.dll';
flist[173] = 'BtWiaExt.dll';
flist[174] = 'BtWizard.dll';
flist[175] = 'btwpimif.dll';
flist[176] = 'btw_ci.dll';
flist[177] = 'BTXPPanel.dll';
flist[178] = 'BTXPPanel.tlb';
flist[179] = 'BtXpShell.dll';
flist[180] = 'C-XLS.dll';
flist[181] = 'cabinet.dll';
flist[182] = 'cabview.dll';
flist[183] = 'cacls.exe';
flist[184] = 'calc.exe';
flist[185] = 'camocx.dll';
flist[186] = 'capesnpn.dll';
flist[187] = 'cards.dll';
flist[188] = 'catsrv.dll';
flist[189] = 'catsrvps.dll';
flist[190] = 'catsrvut.dll';
flist[191] = 'ccfgnt.dll';
flist[192] = 'ccrpbds6.dll';
flist[193] = 'ccrpprg6.ocx';
flist[194] = 'cdfview.dll';
flist[195] = 'cdm.dll';
flist[196] = 'cdmodem.dll';
flist[197] = 'cdosys.dll';
flist[198] = 'cdplayer.exe.manifest';
flist[199] = 'CDRip3.dll';
flist[200] = 'certcli.dll';
flist[201] = 'certmgr.dll';
flist[202] = 'certmgr.msc';
flist[203] = 'CEWMDM.dll';
flist[204] = 'cfgbkend.dll';
flist[205] = 'cfgmgr32.dll';
flist[206] = 'charmap.exe';
flist[207] = 'ChCfg.exe';
flist[208] = 'chcp.com';
flist[209] = 'chkdsk.exe';
flist[210] = 'chkntfs.exe';
flist[211] = 'ciadmin.dll';
flist[212] = 'ciadv.msc';
flist[213] = 'cic.dll';
flist[214] = 'cidaemon.exe';
flist[215] = 'ciodm.dll';
flist[216] = 'cipher.exe';
flist[217] = 'cisvc.exe';
flist[218] = 'ckcnv.exe';
flist[219] = 'clb.dll';
flist[220] = 'clbcatex.dll';
flist[221] = 'clbcatq.dll';
flist[222] = 'cleanmgr.exe';
flist[223] = 'cliconf.chm';
flist[224] = 'cliconfg.dll';
flist[225] = 'cliconfg.exe';
flist[226] = 'cliconfg.rll';
flist[227] = 'clipbrd.exe';
flist[228] = 'clipsrv.exe';
flist[229] = 'clspack.exe';
flist[230] = 'clusapi.dll';
flist[231] = 'cmcfg32.dll';
flist[232] = 'cmd.exe';
flist[233] = 'cmdial32.dll';
flist[234] = 'CMDIALOG.SRG';
flist[235] = 'cmdl32.exe';
flist[236] = 'cmdlib.wsc';
flist[237] = 'CmdLineExt.dll';
flist[238] = 'cmmgr32.hlp';
flist[239] = 'cmmon32.exe';
flist[240] = 'cmos.ram';
flist[241] = 'cmpbk32.dll';
flist[242] = 'cmprops.dll';
flist[243] = 'cmsetACL.dll';
flist[244] = 'cmstp.exe';
flist[245] = 'cmutil.dll';
flist[246] = 'cnbjmon.dll';
flist[247] = 'cnetcfg.dll';
flist[248] = 'cnvfat.dll';
flist[249] = 'colbact.dll';
flist[250] = 'comaddin.dll';
flist[251] = 'comcat.dll';
flist[252] = 'comct232.ocx';
flist[253] = 'comct332.ocx';
flist[254] = 'COMCTL.SRG';
flist[255] = 'COMCTL2.SRG';
flist[256] = 'comctl32.dll';
flist[257] = 'comctl32.ocx';
flist[258] = 'comdlg32.dll';
flist[259] = 'comdlg32.ocx';
flist[260] = 'comm.drv';
flist[261] = 'command.com';
flist[262] = 'commdlg.dll';
flist[263] = 'COMMTB32.DLL';
flist[264] = 'comp.exe';
flist[265] = 'compact.exe';
flist[266] = 'CompareFilesX.ocx';
flist[267] = 'compatUI.dll';
flist[268] = 'compmgmt.msc';
flist[269] = 'compobj.dll';
flist[270] = 'compstui.dll';
flist[271] = 'comrepl.dll';
flist[272] = 'comres.dll';
flist[273] = 'comsnap.dll';
flist[274] = 'comsvcs.dll';
flist[275] = 'comuid.dll';
flist[276] = 'config.hsp';
flist[277] = 'CONFIG.NT';
flist[278] = 'CONFIG.TMP';
flist[279] = 'confmsp.dll';
flist[280] = 'conime.exe';
flist[281] = 'console.dll';
flist[282] = 'control.exe';
flist[283] = 'convert.exe';
flist[284] = 'convlog.exe';
flist[285] = 'corpol.dll';
flist[286] = 'country.sys';
flist[287] = 'credui.dll';
flist[288] = 'crtdll.dll';
flist[289] = 'crypt32.dll';
flist[290] = 'cryptdlg.dll';
flist[291] = 'cryptdll.dll';
flist[292] = 'cryptext.dll';
flist[293] = 'cryptnet.dll';
flist[294] = 'cryptsvc.dll';
flist[295] = 'cryptui.dll';
flist[296] = 'cscdll.dll';
flist[297] = 'cscript.exe';
flist[298] = 'cscui.dll';
flist[299] = 'CSH.DLL';
flist[300] = 'csrsrv.dll';
flist[301] = 'csrss.exe';
flist[302] = 'csseqchk.dll';
flist[303] = 'CSVSpecialProcessing.dll';
flist[304] = 'ctfmon.exe';
flist[305] = 'ctl3d32.dll';
flist[306] = 'ctl3dv2.dll';
flist[307] = 'ctype.nls';
flist[308] = 'c_037.nls';
flist[309] = 'c_10000.nls';
flist[310] = 'c_10006.nls';
flist[311] = 'c_10007.nls';
flist[312] = 'c_10010.nls';
flist[313] = 'c_10017.nls';
flist[314] = 'c_10029.nls';
flist[315] = 'c_10079.nls';
flist[316] = 'c_10081.nls';
flist[317] = 'c_10082.nls';
flist[318] = 'c_1026.nls';
flist[319] = 'c_1250.nls';
flist[320] = 'c_1251.nls';
flist[321] = 'c_1252.nls';
flist[322] = 'c_1253.nls';
flist[323] = 'c_1254.nls';
flist[324] = 'c_1255.nls';
flist[325] = 'c_1256.nls';
flist[326] = 'c_1257.nls';
flist[327] = 'c_1258.nls';
flist[328] = 'c_20127.nls';
flist[329] = 'c_20261.nls';
flist[330] = 'c_20866.nls';
flist[331] = 'c_20905.nls';
flist[332] = 'c_21866.nls';
flist[333] = 'c_28591.nls';
flist[334] = 'c_28592.nls';
flist[335] = 'c_28593.nls';
flist[336] = 'C_28594.NLS';
flist[337] = 'C_28595.NLS';
flist[338] = 'C_28597.NLS';
flist[339] = 'c_28598.nls';
flist[340] = 'c_28599.nls';
flist[341] = 'c_28603.nls';
flist[342] = 'c_28605.nls';
flist[343] = 'c_437.nls';
flist[344] = 'c_500.nls';
flist[345] = 'c_737.nls';
flist[346] = 'c_775.nls';
flist[347] = 'c_850.nls';
flist[348] = 'c_852.nls';
flist[349] = 'c_855.nls';
flist[350] = 'c_857.nls';
flist[351] = 'c_860.nls';
flist[352] = 'c_861.nls';
flist[353] = 'c_863.nls';
flist[354] = 'c_865.nls';
flist[355] = 'c_866.nls';
flist[356] = 'c_869.nls';
flist[357] = 'c_874.nls';
flist[358] = 'c_875.nls';
flist[359] = 'c_932.nls';
flist[360] = 'c_936.nls';
flist[361] = 'c_949.nls';
flist[362] = 'c_950.nls';
flist[363] = 'd3d8.dll';
flist[364] = 'd3d8caps.dat';
flist[365] = 'd3d8thk.dll';
flist[366] = 'd3d9.dll';
flist[367] = 'd3d9caps.dat';
flist[368] = 'd3dim.dll';
flist[369] = 'd3dim700.dll';
flist[370] = 'd3dpmesh.dll';
flist[371] = 'd3dramp.dll';
flist[372] = 'd3drm.dll';
flist[373] = 'd3dx9_24.dll';
flist[374] = 'd3dx9_25.dll';
flist[375] = 'd3dx9_26.dll';
flist[376] = 'd3dx9_27.dll';
flist[377] = 'd3dx9_28.dll';
flist[378] = 'd3dx9_29.dll';
flist[379] = 'd3dx9_30.dll';
flist[380] = 'd3dx9_31.dll';
flist[381] = 'd3dx9_32.dll';
flist[382] = 'd3dxof.dll';
flist[383] = 'danim.dll';
flist[384] = 'dataclen.dll';
flist[385] = 'datime.dll';
flist[386] = 'davclnt.dll';
flist[387] = 'daxctle.ocx';
flist[388] = 'dbgeng.dll';
flist[389] = 'dbghelp.dll';
flist[390] = 'dbmsrpcn.dll';
flist[391] = 'DBMSSHRN.DLL';
flist[392] = 'DBMSSOCN.DLL';
flist[393] = 'dbnetlib.dll';
flist[394] = 'dbnmpntw.dll';
flist[395] = 'Dcache.bin';
flist[396] = 'dciman32.dll';
flist[397] = 'dcomcnfg.exe';
flist[398] = 'ddeml.dll';
flist[399] = 'ddeshare.exe';
flist[400] = 'ddraw.dll';
flist[401] = 'ddrawex.dll';
flist[402] = 'debug.exe';
flist[403] = 'defrag.exe';
flist[404] = 'desk.cpl';
flist[405] = 'deskadp.dll';
flist[406] = 'deskmon.dll';
flist[407] = 'deskperf.dll';
flist[408] = 'desktop.ini';
flist[409] = 'devenum.dll';
flist[410] = 'devmgmt.msc';
flist[411] = 'devmgr.dll';
flist[412] = 'dfrg.msc';
flist[413] = 'dfrgfat.exe';
flist[414] = 'dfrgntfs.exe';
flist[415] = 'dfrgres.dll';
flist[416] = 'dfrgsnap.dll';
flist[417] = 'dfrgui.dll';
flist[418] = 'dfshim.dll';
flist[419] = 'dfsshlex.dll';
flist[420] = 'dgnet.dll';
flist[421] = 'dgrpsetu.dll';
flist[422] = 'dgsetup.dll';
flist[423] = 'dhcpcsvc.dll';
flist[424] = 'dhcpmon.dll';
flist[425] = 'dhcpsapi.dll';
flist[426] = 'diactfrm.dll';
flist[427] = 'diantz.exe';
flist[428] = 'DiffDoc.CNT';
flist[429] = 'DiffDoc.HLP';
flist[430] = 'digest.dll';
flist[431] = 'dimap.dll';
flist[432] = 'dinput.dll';
flist[433] = 'dinput8.dll';
flist[434] = 'diskcomp.com';
flist[435] = 'diskcopy.com';
flist[436] = 'diskcopy.dll';
flist[437] = 'diskmgmt.msc';
flist[438] = 'diskpart.exe';
flist[439] = 'diskperf.exe';
flist[440] = 'dispex.dll';
flist[441] = 'dllhost.exe';
flist[442] = 'dllhst3g.exe';
flist[443] = 'dmadmin.exe';
flist[444] = 'dmband.dll';
flist[445] = 'dmcompos.dll';
flist[446] = 'dmconfig.dll';
flist[447] = 'dmdlgs.dll';
flist[448] = 'dmdskmgr.dll';
flist[449] = 'dmdskres.dll';
flist[450] = 'dmime.dll';
flist[451] = 'dmintf.dll';
flist[452] = 'dmloader.dll';
flist[453] = 'dmocx.dll';
flist[454] = 'dmremote.exe';
flist[455] = 'dmscript.dll';
flist[456] = 'dmserver.dll';
flist[457] = 'dmstyle.dll';
flist[458] = 'dmsynth.dll';
flist[459] = 'dmusic.dll';
flist[460] = 'dmutil.dll';
flist[461] = 'dmview.ocx';
flist[462] = 'dns-sd.exe';
flist[463] = 'dnsapi.dll';
flist[464] = 'dnsrslvr.dll';
flist[465] = 'dnssd.dll';
flist[466] = 'docprop.dll';
flist[467] = 'docprop2.dll';
flist[468] = 'doskey.exe';
flist[469] = 'dosx.exe';
flist[470] = 'dpcdll.dll';
flist[471] = 'dplay.dll';
flist[472] = 'dplaysvr.exe';
flist[473] = 'dplayx.dll';
flist[474] = 'dpmodemx.dll';
flist[475] = 'dpnaddr.dll';
flist[476] = 'dpnet.dll';
flist[477] = 'dpnhpast.dll';
flist[478] = 'dpnhupnp.dll';
flist[479] = 'dpnlobby.dll';
flist[480] = 'dpnmodem.dll';
flist[481] = 'dpnsvr.exe';
flist[482] = 'dpnwsock.dll';
flist[483] = 'dpserial.dll';
flist[484] = 'dpvacm.dll';
flist[485] = 'dpvoice.dll';
flist[486] = 'dpvsetup.exe';
flist[487] = 'dpvvox.dll';
flist[488] = 'dpwsock.dll';
flist[489] = 'dpwsockx.dll';
flist[490] = 'Drake.dll';
flist[491] = 'DrakeCom.dll';
flist[492] = 'driverquery.exe';
flist[493] = 'drmclien.dll';
flist[494] = 'drmstor.dll';
flist[495] = 'drmupgds.exe';
flist[496] = 'drmv2clt.dll';
flist[497] = 'drprov.dll';
flist[498] = 'DRVSSRVR.HLP';
flist[499] = 'DRVVFP.CNT';
flist[500] = 'DRVVFP.HLP';
flist[501] = 'drwatson.exe';
flist[502] = 'drwtsn32.exe';
flist[503] = 'ds16gt.dLL';
flist[504] = 'ds32gt.dll';
flist[505] = 'dsauth.dll';
flist[506] = 'dsdmo.dll';
flist[507] = 'dsdmoprp.dll';
flist[508] = 'dskquota.dll';
flist[509] = 'dskquoui.dll';
flist[510] = 'dsound.dll';
flist[511] = 'dsound.vxd';
flist[512] = 'dsound3d.dll';
flist[513] = 'dsprop.dll';
flist[514] = 'dsprpres.dll';
flist[515] = 'dsquery.dll';
flist[516] = 'dssec.dat';
flist[517] = 'dssec.dll';
flist[518] = 'dssenh.dll';
flist[519] = 'dsuiext.dll';
flist[520] = 'dswave.dll';
flist[521] = 'DTCCM.DLL';
flist[522] = 'DTCTRACE.DLL';
flist[523] = 'DTCUTIL.DLL';
flist[524] = 'dumprep.exe';
flist[525] = 'DUNZIP32.DLL';
flist[526] = 'duser.dll';
flist[527] = 'dvdplay.exe';
flist[528] = 'dvdupgrd.exe';
flist[529] = 'dwwin.exe';
flist[530] = 'dx3j.dll';
flist[531] = 'dx7vb.dll';
flist[532] = 'dx8vb.dll';
flist[533] = 'dxdiag.exe';
flist[534] = 'dxdiagn.dll';
flist[535] = 'dxmasf.dll';
flist[536] = 'dxtmsft.dll';
flist[537] = 'dxtrans.dll';
flist[538] = 'DZIP32.DLL';
flist[539] = 'EBLang.dll';
flist[540] = 'EBLang_407.dll';
flist[541] = 'edit.com';
flist[542] = 'edit.hlp';
flist[543] = 'edlin.exe';
flist[544] = 'efsadu.dll';
flist[545] = 'ega.cpi';
flist[546] = 'ehETW.dll';
flist[547] = 'els.dll';
flist[548] = 'emptyregdb.dat';
flist[549] = 'encapi.dll';
flist[550] = 'encdec.dll';
flist[551] = 'english.dic';
flist[552] = 'EqnClass.Dll';
flist[553] = 'ersvc.dll';
flist[554] = 'es.dll';
flist[555] = 'esent.dll';
flist[556] = 'esent97.dll';
flist[557] = 'esentprf.dll';
flist[558] = 'esentprf.hxx';
flist[559] = 'esentprf.ini';
flist[560] = 'esentutl.exe';
flist[561] = 'eudcedit.exe';
flist[562] = 'eula.txt';
flist[563] = 'eventcls.dll';
flist[564] = 'eventcreate.exe';
flist[565] = 'eventlog.dll';
flist[566] = 'eventquery.vbs';
flist[567] = 'eventtriggers.exe';
flist[568] = 'eventvwr.exe';
flist[569] = 'eventvwr.msc';
flist[570] = 'exe2bin.exe';
flist[571] = 'expand.exe';
flist[572] = 'expsrv.dll';
flist[573] = 'exstrace.dll';
flist[574] = 'extmgr.dll';
flist[575] = 'extrac32.exe';
flist[576] = 'exts.dll';
flist[577] = 'fastopen.exe';
flist[578] = 'faultrep.dll';
flist[579] = 'fc.exe';
flist[580] = 'fde.dll';
flist[581] = 'fdeploy.dll';
flist[582] = 'feclient.dll';
flist[583] = 'ff_vfw.dll';
flist[584] = 'ff_vfw.dll.manifest';
flist[585] = 'FifX.ocx';
flist[586] = 'filemgmt.dll';
flist[587] = 'filevw80.ocx';
flist[588] = 'find.exe';
flist[589] = 'findstr.exe';
flist[590] = 'finger.exe';
flist[591] = 'firewall.cpl';
flist[592] = 'fixmapi.exe';
flist[593] = 'fldrclnr.dll';
flist[594] = 'fldrvw80.ocx';
flist[595] = 'fltlib.dll';
flist[596] = 'fltmc.exe';
flist[597] = 'FM20.DLL';
flist[598] = 'FM20ENU.DLL';
flist[599] = 'fmifs.dll';
flist[600] = 'FNTCACHE.DAT';
flist[601] = 'fontext.dll';
flist[602] = 'fontsub.dll';
flist[603] = 'fontview.exe';
flist[604] = 'forcedos.exe';
flist[605] = 'format.com';
flist[606] = 'framebuf.dll';
flist[607] = 'freecell.exe';
flist[608] = 'fsmgmt.msc';
flist[609] = 'fsquirt.exe';
flist[610] = 'fsusd.dll';
flist[611] = 'fsutil.exe';
flist[612] = 'ftp.exe';
flist[613] = 'ftpctrs.h';
flist[614] = 'ftpctrs.ini';
flist[615] = 'ftpctrs2.dll';
flist[616] = 'ftpsapi2.dll';
flist[617] = 'ftsrch.dll';
flist[618] = 'fwcfg.dll';
flist[619] = 'g711codc.ax';
flist[620] = 'Gauge32.OCX';
flist[621] = 'gb2312.uce';
flist[622] = 'gcdef.dll';
flist[623] = 'gdi.exe';
flist[624] = 'gdi32.dll';
flist[625] = 'gdiplus.dll';
flist[626] = 'geo.nls';
flist[627] = 'getmac.exe';
flist[628] = 'getuname.dll';
flist[629] = 'glmf32.dll';
flist[630] = 'glu32.dll';
flist[631] = 'gpedit.dll';
flist[632] = 'gpedit.msc';
flist[633] = 'gpkcsp.dll';
flist[634] = 'gpkrsrc.dll';
flist[635] = 'gpresult.exe';
flist[636] = 'gptext.dll';
flist[637] = 'gpupdate.exe';
flist[638] = 'graftabl.com';
flist[639] = 'graphics.com';
flist[640] = 'graphics.pro';
flist[641] = 'grfcxl32.dll';
flist[642] = 'grid32.ocx';
flist[643] = 'grpconv.exe';
flist[644] = 'grsapx32.dll';
flist[645] = 'gsdll32.dll';
flist[646] = 'h323.tsp';
flist[647] = 'h323log.txt';
flist[648] = 'h323msp.dll';
flist[649] = 'h5dlg32.dll';
flist[650] = 'h5icon32.dll';
flist[651] = 'h5krnl32.dll';
flist[652] = 'h5menu32.dll';
flist[653] = 'h5rtf32.dll';
flist[654] = 'h5tool32.dll';
flist[655] = 'hal.dll';
flist[656] = 'haspdos.sys';
flist[657] = 'haspvdd.dll';
flist[658] = 'hccoin.dll';
flist[659] = 'HdAProp.dll';
flist[660] = 'HdAShCut.exe';
flist[661] = 'HdAudRes.dll';
flist[662] = 'hdwwiz.cpl';
flist[663] = 'help.exe';
flist[664] = 'hhctrl.ocx';
flist[665] = 'hhsetup.dll';
flist[666] = 'hid.dll';
flist[667] = 'hidphone.tsp';
flist[668] = 'himem.sys';
flist[669] = 'hlink.dll';
flist[670] = 'HLP95EN.DLL';
flist[671] = 'hnetcfg.dll';
flist[672] = 'hnetmon.dll';
flist[673] = 'hnetwiz.dll';
flist[674] = 'homepage.inf';
flist[675] = 'hostname.exe';
flist[676] = 'hotplug.dll';
flist[677] = 'HPBHEALR.DLL';
flist[678] = 'HPBMMON.DLL';
flist[679] = 'HPDOMON.DLL';
flist[680] = 'hticons.dll';
flist[681] = 'html.iec';
flist[682] = 'httpapi.dll';
flist[683] = 'htui.dll';
flist[684] = 'huffyuv.dll';
flist[685] = 'hypertrm.dll';
flist[686] = 'I263_32.drv';
flist[687] = 'i420vfw.dll';
flist[688] = 'iac25_32.ax';
flist[689] = 'Iacenc.dll';
flist[690] = 'iasacct.dll';
flist[691] = 'iasads.dll';
flist[692] = 'iashlpr.dll';
flist[693] = 'iasnap.dll';
flist[694] = 'iaspolcy.dll';
flist[695] = 'iasrad.dll';
flist[696] = 'iasrecst.dll';
flist[697] = 'iassam.dll';
flist[698] = 'iassdo.dll';
flist[699] = 'iassvcs.dll';
flist[700] = 'icaapi.dll';
flist[701] = 'iccvid.dll';
flist[702] = 'icfgnt5.dll';
flist[703] = 'icm32.dll';
flist[704] = 'icmp.dll';
flist[705] = 'icmui.dll';
flist[706] = 'iconv.dll';
flist[707] = 'icudt20.dll';
flist[708] = 'icuin20.dll';
flist[709] = 'icuuc20.dll';
flist[710] = 'icwdial.dll';
flist[711] = 'icwphbk.dll';
flist[712] = 'ideograf.uce';
flist[713] = 'idq.dll';
flist[714] = 'ie4uinit.exe';
flist[715] = 'ieakeng.dll';
flist[716] = 'ieaksie.dll';
flist[717] = 'ieakui.dll';
flist[718] = 'iedkcs32.dll';
flist[719] = 'ieencode.dll';
flist[720] = 'iepeers.dll';
flist[721] = 'iernonce.dll';
flist[722] = 'iesetup.dll';
flist[723] = 'ieuinit.inf';
flist[724] = 'iexpress.exe';
flist[725] = 'ifmon.dll';
flist[726] = 'ifsutil.dll';
flist[727] = 'igmpagnt.dll';
flist[728] = 'iisext.dll';
flist[729] = 'iismap.dll';
flist[730] = 'iismui.dll';
flist[731] = 'iisreset.exe';
flist[732] = 'iisrstap.dll';
flist[733] = 'iisrtl.dll';
flist[734] = 'iissuba.dll';
flist[735] = 'ils.dll';
flist[736] = 'imaadp32.acm';
flist[737] = 'imagehlp.dll';
flist[738] = 'imapi.exe';
flist[739] = 'IMC32.acm';
flist[740] = 'imeshare.dll';
flist[741] = 'imgutil.dll';
flist[742] = 'imm32.dll';
flist[743] = 'imon1.dat';
flist[744] = 'impact.qlm';
flist[745] = 'inetcfg.dll';
flist[746] = 'inetcomm.dll';
flist[747] = 'inetcpl.cpl';
flist[748] = 'inetcplc.dll';
flist[749] = 'inetmib1.dll';
flist[750] = 'inetpp.dll';
flist[751] = 'inetppui.dll';
flist[752] = 'inetres.dll';
flist[753] = 'inetsloc.dll';
flist[754] = 'INETWH32.dll';
flist[755] = 'infoadmn.dll';
flist[756] = 'infoctrs.dll';
flist[757] = 'infoctrs.h';
flist[758] = 'infoctrs.ini';
flist[759] = 'infosoft.dll';
flist[760] = 'initpki.dll';
flist[761] = 'INKED.DLL';
flist[762] = 'input.dll';
flist[763] = 'inseng.dll';
flist[764] = 'instcat.sql';
flist[765] = 'intl.cpl';
flist[766] = 'iologmsg.dll';
flist[767] = 'ipconf.tsp';
flist[768] = 'ipconfig.exe';
flist[769] = 'iphlpapi.dll';
flist[770] = 'ipmontr.dll';
flist[771] = 'ipnathlp.dll';
flist[772] = 'ippromon.dll';
flist[773] = 'iprop.dll';
flist[774] = 'iprtprio.dll';
flist[775] = 'iprtrmgr.dll';
flist[776] = 'ipsec6.exe';
flist[777] = 'ipsecsnp.dll';
flist[778] = 'ipsecsvc.dll';
flist[779] = 'ipsmsnap.dll';
flist[780] = 'ipv6.exe';
flist[781] = 'ipv6mon.dll';
flist[782] = 'Ipx32d56.dll';
flist[783] = 'Ipx32_56.dll';
flist[784] = 'ipxmontr.dll';
flist[785] = 'ipxpromn.dll';
flist[786] = 'ipxrip.dll';
flist[787] = 'ipxroute.exe';
flist[788] = 'ipxrtmgr.dll';
flist[789] = 'ipxsap.dll';
flist[790] = 'ipxwan.dll';
flist[791] = 'ir32_32.dll';
flist[792] = 'ir41_32.ax';
flist[793] = 'ir41_qc.dll';
flist[794] = 'ir41_qcx.dll';
flist[795] = 'ir50_32.dll';
flist[796] = 'ir50_qc.dll';
flist[797] = 'ir50_qcx.dll';
flist[798] = 'irclass.dll';
flist[799] = 'irftp.exe';
flist[800] = 'irmon.dll';
flist[801] = 'irprops.cpl';
flist[802] = 'isign32.dll';
flist[803] = 'isqlext.dll';
flist[804] = 'isrdbg32.dll';
flist[805] = 'itircl.dll';
flist[806] = 'itss.dll';
flist[807] = 'iuengine.dll';
flist[808] = 'ivfsrc.ax';
flist[809] = 'Ixpert.qlm';
flist[810] = 'ixsso.dll';
flist[811] = 'iyuv_32.dll';
flist[812] = 'java.exe';
flist[813] = 'JavaAccessBridge.dll';
flist[814] = 'javacpl.cpl';
flist[815] = 'javacypt.dll';
flist[816] = 'javaee.dll';
flist[817] = 'javaprxy.dll';
flist[818] = 'javart.dll';
flist[819] = 'javasup.vxd';
flist[820] = 'javaw.exe';
flist[821] = 'javaws.exe';
flist[822] = 'jdbgmgr.exe';
flist[823] = 'jet500.dll';
flist[824] = 'jgaw400.dll';
flist[825] = 'jgdw400.dll';
flist[826] = 'jgmd400.dll';
flist[827] = 'jgpl400.dll';
flist[828] = 'jgsd400.dll';
flist[829] = 'jgsh400.dll';
flist[830] = 'jit.dll';
flist[831] = 'jobexec.dll';
flist[832] = 'joy.cpl';
flist[833] = 'jscript.dll';
flist[834] = 'jsproxy.dll';
flist[835] = 'jupdate-1.5.0_05-b05.log';
flist[836] = 'jupdate-1.5.0_09-b01.log';
flist[837] = 'jview.exe';
flist[838] = 'kanji_1.uce';
flist[839] = 'kanji_2.uce';
flist[840] = 'kb16.com';
flist[841] = 'KBDAL.DLL';
flist[842] = 'kbdaze.dll';
flist[843] = 'kbdazel.dll';
flist[844] = 'kbdbe.dll';
flist[845] = 'kbdbene.dll';
flist[846] = 'kbdblr.dll';
flist[847] = 'kbdbr.dll';
flist[848] = 'kbdbu.dll';
flist[849] = 'kbdca.dll';
flist[850] = 'kbdcan.dll';
flist[851] = 'kbdcr.dll';
flist[852] = 'kbdcz.dll';
flist[853] = 'kbdcz1.dll';
flist[854] = 'kbdcz2.dll';
flist[855] = 'kbdda.dll';
flist[856] = 'kbddv.dll';
flist[857] = 'kbdes.dll';
flist[858] = 'kbdest.dll';
flist[859] = 'kbdfc.dll';
flist[860] = 'kbdfi.dll';
flist[861] = 'kbdfi1.dll';
flist[862] = 'kbdfo.dll';
flist[863] = 'kbdfr.dll';
flist[864] = 'kbdgae.dll';
flist[865] = 'kbdgkl.dll';
flist[866] = 'kbdgr.dll';
flist[867] = 'kbdgr1.dll';
flist[868] = 'kbdhe.dll';
flist[869] = 'kbdhe220.dll';
flist[870] = 'kbdhe319.dll';
flist[871] = 'kbdhela2.dll';
flist[872] = 'kbdhela3.dll';
flist[873] = 'kbdhept.dll';
flist[874] = 'kbdhu.dll';
flist[875] = 'kbdhu1.dll';
flist[876] = 'kbdic.dll';
flist[877] = 'kbdinbe1.dll';
flist[878] = 'kbdinben.dll';
flist[879] = 'kbdinmal.dll';
flist[880] = 'kbdir.dll';
flist[881] = 'kbdit.dll';
flist[882] = 'kbdit142.dll';
flist[883] = 'kbdkaz.dll';
flist[884] = 'kbdkyr.dll';
flist[885] = 'kbdla.dll';
flist[886] = 'kbdlt.dll';
flist[887] = 'kbdlt1.dll';
flist[888] = 'kbdlv.dll';
flist[889] = 'kbdlv1.dll';
flist[890] = 'kbdmac.dll';
flist[891] = 'kbdmaori.dll';
flist[892] = 'kbdmlt47.dll';
flist[893] = 'kbdmlt48.dll';
flist[894] = 'kbdmon.dll';
flist[895] = 'kbdne.dll';
flist[896] = 'kbdnec.dll';
flist[897] = 'kbdno.dll';
flist[898] = 'kbdno1.dll';
flist[899] = 'kbdpl.dll';
flist[900] = 'kbdpl1.dll';
flist[901] = 'kbdpo.dll';
flist[902] = 'kbdro.dll';
flist[903] = 'kbdru.dll';
flist[904] = 'kbdru1.dll';
flist[905] = 'kbdsf.dll';
flist[906] = 'kbdsg.dll';
flist[907] = 'kbdsl.dll';
flist[908] = 'kbdsl1.dll';
flist[909] = 'kbdsmsfi.dll';
flist[910] = 'kbdsmsno.dll';
flist[911] = 'kbdsp.dll';
flist[912] = 'kbdsw.dll';
flist[913] = 'kbdtat.dll';
flist[914] = 'kbdtuf.dll';
flist[915] = 'kbdtuq.dll';
flist[916] = 'kbduk.dll';
flist[917] = 'kbdukx.dll';
flist[918] = 'kbdur.dll';
flist[919] = 'kbdus.dll';
flist[920] = 'kbdusl.dll';
flist[921] = 'kbdusr.dll';
flist[922] = 'kbdusx.dll';
flist[923] = 'kbduzb.dll';
flist[924] = 'kbdycc.dll';
flist[925] = 'kbdycl.dll';
flist[926] = 'kd1394.dll';
flist[927] = 'kdcom.dll';
flist[928] = 'kerberos.dll';
flist[929] = 'kernel32.dll';
flist[930] = 'key01.sys';
flist[931] = 'keyboard.drv';
flist[932] = 'keyboard.sys';
flist[933] = 'keymgr.dll';
flist[934] = 'kmddsp.tsp';
flist[935] = 'korean.uce';
flist[936] = 'krnl386.exe';
flist[937] = 'ksproxy.ax';
flist[938] = 'ksuser.dll';
flist[939] = 'l3codeca.acm';
flist[940] = 'l3codecp.acm';
flist[941] = 'l3codecx.ax';
flist[942] = 'label.exe';
flist[943] = 'lameACM.acm';
flist[944] = 'lame_acm.xml';
flist[945] = 'LAME_ENC.DLL';
flist[946] = 'langwrbk.dll';
flist[947] = 'lanman.drv';
flist[948] = 'LAPRXY.dll';
flist[949] = 'lcppn201.dll';
flist[950] = 'lcppn21.dll';
flist[951] = 'LegitCheckControl.dll';
flist[952] = 'lhacm.acm';
flist[953] = 'libeay32.dll';
flist[954] = 'libmysql5a.dll';
flist[955] = 'librfc32.dll';
flist[956] = 'librfc32u.dll';
flist[957] = 'libsapu16.dll';
flist[958] = 'licdll.dll';
flist[959] = 'licmgr10.dll';
flist[960] = 'licwmi.dll';
flist[961] = 'lights.exe';
flist[962] = 'linkinfo.dll';
flist[963] = 'lmhsvc.dll';
flist[964] = 'lmrt.dll';
flist[965] = 'lnkstub.exe';
flist[966] = 'loadfix.com';
flist[967] = 'loadperf.dll';
flist[968] = 'locale.nls';
flist[969] = 'localsec.dll';
flist[970] = 'localspl.dll';
flist[971] = 'localui.dll';
flist[972] = 'locator.exe';
flist[973] = 'lodctr.exe';
flist[974] = 'logagent.exe';
flist[975] = 'loghours.dll';
flist[976] = 'login.cmd';
flist[977] = 'logman.exe';
flist[978] = 'logoff.exe';
flist[979] = 'logon.scr';
flist[980] = 'logonui.exe';
flist[981] = 'logonui.exe.manifest';
flist[982] = 'lpk.dll';
flist[983] = 'lpq.exe';
flist[984] = 'lpr.exe';
flist[985] = 'lprhelp.dll';
flist[986] = 'lprmonui.dll';
flist[987] = 'lsasrv.dll';
flist[988] = 'lsass.exe';
flist[989] = 'lusrmgr.msc';
flist[990] = 'lz32.dll';
flist[991] = 'lzexpand.dll';
flist[992] = 'l_except.nls';
flist[993] = 'l_intl.nls';
flist[994] = 'magnify.exe';
flist[995] = 'mag_hook.dll';
flist[996] = 'main.cpl';
flist[997] = 'makecab.exe';
flist[998] = 'MALSLIB.DLL';
flist[999] = 'mapi32.dll';
flist[1000] = 'mapistub.dll';
flist[1001] = 'mapisvc.inf';
flist[1002] = 'MBLLNK.CPL';
flist[1003] = 'mcastmib.dll';
flist[1004] = 'mcd32.dll';
flist[1005] = 'mcdsrv32.dll';
flist[1006] = 'mchgrcoi.dll';
flist[1007] = 'mciavi.drv';
flist[1008] = 'mciavi32.dll';
flist[1009] = 'mcicda.dll';
flist[1010] = 'mciole16.dll';
flist[1011] = 'mciole32.dll';
flist[1012] = 'mciqtz32.dll';
flist[1013] = 'mciseq.dll';
flist[1014] = 'mciseq.drv';
flist[1015] = 'mciwave.dll';
flist[1016] = 'mciwave.drv';
flist[1017] = 'mdhcp.dll';
flist[1018] = 'mdimon.dll';
flist[1019] = 'mdminst.dll';
flist[1020] = 'mdwmdmsp.dll';
flist[1021] = 'mem.exe';
flist[1022] = 'mf3216.dll';
flist[1023] = 'mfc40.dll';
flist[1024] = 'mfc40u.dll';
flist[1025] = 'mfc42.dll';
flist[1026] = 'MFC42ENU.DLL';
flist[1027] = 'mfc42u.dll';
flist[1028] = 'mfc71.dll';
flist[1029] = 'mfc71u.dll';
flist[1030] = 'mfcans32.dll';
flist[1031] = 'mfcsubs.dll';
flist[1032] = 'mfcuia32.dll';
flist[1033] = 'mfcuiw32.dll';
flist[1034] = 'MFPLAT.dll';
flist[1035] = 'mgmtapi.dll';
flist[1036] = 'mib.bin';
flist[1037] = 'midimap.dll';
flist[1038] = 'miglibnt.dll';
flist[1039] = 'migpwd.exe';
flist[1040] = 'mimefilt.dll';
flist[1041] = 'mlang.dat';
flist[1042] = 'mlang.dll';
flist[1043] = 'mll_hp.dll';
flist[1044] = 'mll_mtf.dll';
flist[1045] = 'mll_qic.dll';
flist[1046] = 'MM32DCMP.DLL';
flist[1047] = 'mmc.exe';
flist[1048] = 'mmcbase.dll';
flist[1049] = 'mmcndmgr.dll';
flist[1050] = 'mmcshext.dll';
flist[1051] = 'mmdriver.inf';
flist[1052] = 'mmdrv.dll';
flist[1053] = 'mmfutil.dll';
flist[1054] = 'mmsys.cpl';
flist[1055] = 'mmsystem.dll';
flist[1056] = 'mmtask.tsk';
flist[1057] = 'mmutilse.dll';
flist[1058] = 'mnmdd.dll';
flist[1059] = 'mnmsrvc.exe';
flist[1060] = 'mobsync.dll';
flist[1061] = 'mobsync.exe';
flist[1062] = 'mode.com';
flist[1063] = 'modemui.dll';
flist[1064] = 'modex.dll';
flist[1065] = 'more.com';
flist[1066] = 'moricons.dll';
flist[1067] = 'mountvol.exe';
flist[1068] = 'mouse.drv';
flist[1069] = 'mp3fhg.acm';
flist[1070] = 'MP43DECD.dll';
flist[1071] = 'MP43DMOD.dll';
flist[1072] = 'MP4SDECD.dll';
flist[1073] = 'MP4SDMOD.dll';
flist[1074] = 'mpeg2data.ax';
flist[1075] = 'mpg2splt.ax';
flist[1076] = 'MPG4DECD.dll';
flist[1077] = 'MPG4DMOD.dll';
flist[1078] = 'mpg4ds32.ax';
flist[1079] = 'mplay32.exe';
flist[1080] = 'mpnotify.exe';
flist[1081] = 'mpr.dll';
flist[1082] = 'mprapi.dll';
flist[1083] = 'mprddm.dll';
flist[1084] = 'mprdim.dll';
flist[1085] = 'mprmsg.dll';
flist[1086] = 'mprui.dll';
flist[1087] = 'mqad.dll';
flist[1088] = 'mqbkup.exe';
flist[1089] = 'mqcertui.dll';
flist[1090] = 'mqdscli.dll';
flist[1091] = 'mqgentr.dll';
flist[1092] = 'mqise.dll';
flist[1093] = 'mqlogmgr.dll';
flist[1094] = 'mqoa.dll';
flist[1095] = 'mqoa.tlb';
flist[1096] = 'mqoa10.tlb';
flist[1097] = 'mqoa20.tlb';
flist[1098] = 'mqperf.dll';
flist[1099] = 'mqperf.ini';
[/quote]

#5
Marcus

    Elite Member

  • Honorary Members
  • PipPipPipPipPip
  • 592 posts
  • Gender:Male
  • Location:London, UK
That is some list! Glad it wasn't allowed to be downloaded on my lappy. How come only Avast! and G-Data are detecting this? (according to Maniac).

#6
Maniac

    I Love Andriana

  • Experts
  • PipPipPipPipPipPip
  • 10,164 posts
  • Gender:Male
  • Location:Bulgaria, EU
  • Interests:Information security and web development
Information is from Virustotal:
http://www.virustotal.com/analisis/fd3499b...7f5f18d9d8cb57b

This is FP.
Posted Image

My help is free, however, if you wish to make a small donation to show appreciation and to help me continue the fight against Malware, then click here Posted Image

#7
lordpake

    Advanced Member

  • Honorary Members
  • PipPipPip
  • 215 posts
  • Gender:Male
  • Location:Helsinki / European Union
  • Interests:Anime / Manga / Comp. security
Frankly, who cares about the f/p in this case?

Have you checked the site? It's AV 2009 website. And that's a rogue for sure!
Men make good pets.

~i~System info~i~

#8
Maniac

    I Love Andriana

  • Experts
  • PipPipPipPipPipPip
  • 10,164 posts
  • Gender:Male
  • Location:Bulgaria, EU
  • Interests:Information security and web development
We talk about this:
/lite-anti-virus-scan.com/promo/1/img/flist.js

Not about Antivirus 2009. Maybe this file is part of Antivirus 2009, but he isn't dangerous.
Posted Image

My help is free, however, if you wish to make a small donation to show appreciation and to help me continue the fight against Malware, then click here Posted Image

#9
lordpake

    Advanced Member

  • Honorary Members
  • PipPipPip
  • 215 posts
  • Gender:Male
  • Location:Helsinki / European Union
  • Interests:Anime / Manga / Comp. security
So let me get this straight: a filelist file, which obviously is used by the rogue in question to fool people (ever seen one of their scripted scans?) gets detected and you are willing to go to lengths to report this as f/p? <_<


In my opinion, the original detection as fake AV javascript is correct.
Men make good pets.

~i~System info~i~

#10
MysteryFCM

    Forum Deity

  • Moderators
  • PipPipPipPipPipPip
  • 4,232 posts
  • Gender:Male
  • Location:Tyneside, UK
It's NOT an F/P

http://hosts-file.ne...67&view=matches
http://hosts-file.ne...40&view=matches

Ref:
http://hosts-file.ne...-virus-scan.com
Steven Burn
Research Engineer

Posted Image

Follow us: Twitter, Become a fan: Facebook

#11
Maniac

    I Love Andriana

  • Experts
  • PipPipPipPipPipPip
  • 10,164 posts
  • Gender:Male
  • Location:Bulgaria, EU
  • Interests:Information security and web development

View Postlordpake, on Feb 22 2009, 08:58 PM, said:

So let me get this straight: a filelist file, which obviously is used by the rogue in question to fool people (ever seen one of their scripted scans?) gets detected and you are willing to go to lengths to report this as f/p? <_<


In my opinion, the original detection as fake AV javascript is correct.

File itself is not dangerous, but you obviously didn't know.

I speak only for file flist.js, not the site or AV 2009.
Posted Image

My help is free, however, if you wish to make a small donation to show appreciation and to help me continue the fight against Malware, then click here Posted Image

#12
lordpake

    Advanced Member

  • Honorary Members
  • PipPipPip
  • 215 posts
  • Gender:Male
  • Location:Helsinki / European Union
  • Interests:Anime / Manga / Comp. security

View PostManiac, on Feb 22 2009, 09:13 PM, said:

File itself is not dangerous, but you obviously didn't know.

I speak only for file flist.js, not the site or AV 2009.
So do I.

And you don't get it, do you? That file is dangerous, not in the sense of "hey, I here push exploits to your PC, weeeeeeeee1!" but in the sense of being part of social engineering attack against the sorry person who sees that.

As it stands, the original fake AV javascript detection is correct.
Men make good pets.

~i~System info~i~

#13
Maniac

    I Love Andriana

  • Experts
  • PipPipPipPipPipPip
  • 10,164 posts
  • Gender:Male
  • Location:Bulgaria, EU
  • Interests:Information security and web development

View Postlordpake, on Feb 22 2009, 09:29 PM, said:

As it stands, the original fake AV javascript detection is correct.

We'll see...
Posted Image

My help is free, however, if you wish to make a small donation to show appreciation and to help me continue the fight against Malware, then click here Posted Image

#14
MysteryFCM

    Forum Deity

  • Moderators
  • PipPipPipPipPipPip
  • 4,232 posts
  • Gender:Male
  • Location:Tyneside, UK
Simplicity = Whilst the individual file is not itself "malicious", the site IS, therefor, detection of it's files is warranted.

/edit

malicious changed to "malicious" as it's still part of an engineered attack vector.
Steven Burn
Research Engineer

Posted Image

Follow us: Twitter, Become a fan: Facebook

#15
Maniac

    I Love Andriana

  • Experts
  • PipPipPipPipPipPip
  • 10,164 posts
  • Gender:Male
  • Location:Bulgaria, EU
  • Interests:Information security and web development

View Postlordpake, on Feb 22 2009, 09:29 PM, said:

So do I.

And you don't get it, do you? That file is dangerous, not in the sense of "hey, I here push exploits to your PC, weeeeeeeee1!" but in the sense of being part of social engineering attack against the sorry person who sees that.

As it stands, the original fake AV javascript detection is correct.

Why don't go play with children outside?

Answears:

From Kaspersky:

Quote

>Hello,
>
>No malicious software was found in the attached file.
>
>> Is this file a harmful?
>>
>>
>> Borislav Ivanov (Maniac)
>> The biggest Bulgarian fan of ESET
>> ESET Smart Security Beta Tester
>--------------------
>Regards, Vitaly Yakutenko
>Virus analyst, Kaspersky Lab.
>10/1, 1st Volokolamsky Proezd, Moscow, 123060, Russia
>Tel./Fax: + 7 (495) 797 8700
>http://www.kaspersky.com http://www.viruslist.com
>
>

From Symantec:

Quote

>This message is an automatically generated reply. This system is designed to analyze and process virus submissions into the Symantec Security Response and cannot accept correspondence or inquiries.
>Please contact your Technical Support representative if more detailed
>information about your submission is required. Do not reply to this
>message.
>
>Below is a status update on your virus submission:
>
>Date: February 22, 2009
>
>Borislav Ivanov
>None
>
>
>
>Dear Borislav Ivanov,
>
>We have analyzed your submission. The following is a report of our
>findings for each file you have submitted:
>
>filename: flist.js
>machine: Machine
>result: See the developer notes
>
>Customer notes:
>Is this file a harmful
>
>
>Developer notes:
> flist.js contains no malicious code.
>
>
>
>
>Should you have any questions about your submission, please contact
>your regional technical support from the Symantec website and give them
>the tracking number in the subject of this message.
>
>-----------------------------------------------------------------------
>This message was generated by Symantec Security Response automation.
>
>For USA:
>For electronic support options, Symantec provides On-Line Services at
>http://www.symantec.com/techsupp/
>
>
>--------------------------------------------
>

Tomorrow I expect a response from other antivirus laboratories.


Please explain to me how it will be used by hackers and others, then it contains only names of files? To work properly need AV 2009, after having gone - no problem.
Posted Image

My help is free, however, if you wish to make a small donation to show appreciation and to help me continue the fight against Malware, then click here Posted Image

#16
MysteryFCM

    Forum Deity

  • Moderators
  • PipPipPipPipPipPip
  • 4,232 posts
  • Gender:Male
  • Location:Tyneside, UK

View PostManiac, on Feb 22 2009, 07:48 PM, said:

Why don't go play with children outside?


Keep it civil guys ..... this isn't a competition
Steven Burn
Research Engineer

Posted Image

Follow us: Twitter, Become a fan: Facebook

#17
Maniac

    I Love Andriana

  • Experts
  • PipPipPipPipPipPip
  • 10,164 posts
  • Gender:Male
  • Location:Bulgaria, EU
  • Interests:Information security and web development

View PostMysteryFCM, on Feb 22 2009, 09:52 PM, said:

Keep it civil guys ..... this isn't a competition

Sorry, but the problem is there that he thinks he knows more than me but I try to prove that its intellectual level is below mine.

Good night!
Posted Image

My help is free, however, if you wish to make a small donation to show appreciation and to help me continue the fight against Malware, then click here Posted Image

#18
lordpake

    Advanced Member

  • Honorary Members
  • PipPipPip
  • 215 posts
  • Gender:Male
  • Location:Helsinki / European Union
  • Interests:Anime / Manga / Comp. security

View PostManiac, on Feb 22 2009, 09:56 PM, said:

Sorry, but the problem is there that he thinks he knows more than me but I try to prove that its intellectual level is below mine.

Good night!


<_<
Men make good pets.

~i~System info~i~

#19
MysteryFCM

    Forum Deity

  • Moderators
  • PipPipPipPipPipPip
  • 4,232 posts
  • Gender:Male
  • Location:Tyneside, UK
Like I said, this isn't a competition to see who's ego is biggest, or who's experience level is best. All behaviour like this is going to do, is give a bad impression to the users, especially when it's done in a public thread.

We're supposed to be on the same side, so I suggest acting as such and letting it go.
Steven Burn
Research Engineer

Posted Image

Follow us: Twitter, Become a fan: Facebook

#20
lordpake

    Advanced Member

  • Honorary Members
  • PipPipPip
  • 215 posts
  • Gender:Male
  • Location:Helsinki / European Union
  • Interests:Anime / Manga / Comp. security

View PostManiac, on Feb 22 2009, 09:48 PM, said:

Please explain to me how it will be used by hackers and others, then it contains only names of files?

Do you understand the concept of social engineering?


That file is obviously part of the fake online scan used by rogue. That scan is used to fool people into believing their PC is being scanned, and even that malicious files were found. The only purpose is to get them to download and purchase the rogue.


While that file itself does not contain malicious payload, it's purpose in life is to ensure the delivery of malicious payload. It has no legit use.
Men make good pets.

~i~System info~i~





1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users

Follow Us