I hope i helped fight malware (my first ever post)
exile360
Jan 29 2009, 02:22 PM
You sure did, thanks.
But for future reference, please don't upload the files here as other forum users may download the malware and infect themselves. Instead, please upload the files here: http://uploads.malwarebytes.org/
Serious
Jan 29 2009, 02:23 PM
Yeah i realised that i would of removed but there wasn't any edit button but still glad i could help
exile360
Jan 29 2009, 02:26 PM
Yeah, unfortunately you don't get the edit button until you reach at least 50 posts. The mods implemented this policy due to some users altering their logs in the HijackThis help forum area.
Jaxryley
Jan 29 2009, 02:32 PM
Hi Serious, welcome to the forum and nice first post.
I already had a InstallAVg_880116.exe in my samples at the same size but packed differently.
As you can see my older installer is getting flagged by quite a few engines where as your newer installer isn't.
QUOTE
File InstallAVg_880116.exe received on 01.29.2009 15:24:18 (CET) Current status: finished Result: 20/38 (52.63%)
Yeah, only 3 flagged it, and one of those that did (F-Secure) only caught it with heuristics (meaning it didn't have a specific definition for it, it just looked suspicious). Good find.
Serious
Jan 29 2009, 02:37 PM
Very interesting. I can't wait till malwarebytes see's this as 'infected'
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.