x.264.exe
#1
Posted 14 February 2008 - 02:04 AM
#2
Posted 14 February 2008 - 06:50 AM
I may be wrong about it being a trojan (still not sure) but it does seem to be junk .
I am going to look into this one a lot more today .
#3
Posted 14 February 2008 - 07:14 AM
When you google any of the files involved with super c all you get is hijackthis help forum threads .
I can find experts removing them , I can find experts not removing them .
I can find VirusTotal reports where these files are listed with 3 to 5 heuristic hits but no actual direct hits for malware .
One thing I cant find are reports where is this is outright listed as malware .
I am removing this for now , I will look into this further though .
These are the reasons I added it to begin with :
1. Searching for its files netted nothing but help forum threads .
2. Multiple reports of it being removed because for various reasons all involving people not being happy with it .
3. Multiple reports of it being uninstalled but leaving some of its files behind .
4. It hiding its files from the user .
5. Some evidence of other vendors detecting it as malware .
#4
Posted 14 February 2008 - 07:28 AM
This seems to be the downlad page . I want to test this further but the download is not working .
I am trying to find something that is not a strike against this software but I just cant .
#5
Posted 14 February 2008 - 07:43 AM
I have removed it for now , next update will up soon .
If anyone can find me a link to this software I would be grateful .
#6
Posted 14 February 2008 - 03:52 PM
hxxp://www.download.com/3001-2194_4-108011...a696a53874d62c5
Edited by JeanInMontana, 14 February 2008 - 04:02 PM.
mung live link
#7
Posted 14 February 2008 - 04:04 PM
Cobra, on Feb 14 2008, 01:52 PM, said:
hxxp://www.download.com/3001-2194_4-108011...a696a53874d62c5
Please don't post live links to malware. We appreciate your help but munged links are to protect others.
#10
Posted 14 February 2008 - 05:23 PM
#11
Posted 14 February 2008 - 05:56 PM
- below Super picture> link Download and use for free
- next link (on the new page) > Start Downloading SUPER ©
- next page> link: download and use
- on the last page you need to wait 10 seconds and you'll get the download link near the bottom of the page.
Btw, file (C:\WINDOWS\system32\) x.264.exe:
Antivirus Version Last Update Result
eSafe 7.0.15.0 2008.02.14 suspicious Trojan/Worm
FileAdvisor 1 2008.02.14 High threat detected
Additional information
File size: 240128 bytes
MD5: 5fdd7d827c1cc58567367d03d24548ce
SHA1: 9937882f96f025991634b2833c5f4bcaef70beb2
PEiD: UPX 2.90 [LZMA] -> Markus Oberhumer, Laszlo Molnar & John Reiser
packers: UPX
Bit9 info: http://fileadvisor.bit9.com/services/extin...7367d03d24548ce
packers: UPX
packers: UPX
#13
Posted 14 February 2008 - 08:13 PM
These guys have a funny definition of the term uninstall .
At the very most their uninstaller removed 10% of this software .
I just may build a removal tool for this , should be real easy .
I am also taking a close look at all of the files left behind , what still loads and what this file is that runs for a split second after you uninstall .
#14
Posted 14 February 2008 - 08:30 PM
Here is the deal , two things combine to make this "look" like malware .
First it removes next to nothing that it adds to windows and system 32 .
Next a lot of these files are hidden from the user and many also have no version info .
But .....
None of whats left is set to load and all detection on these files are based on their executable packers , they use a lot that malware also uses .
#15
Posted 14 February 2008 - 08:42 PM
#16
Posted 23 April 2008 - 04:02 PM
nosirrah, on Feb 14 2008, 09:13 PM, said:
These guys have a funny definition of the term uninstall .
At the very most their uninstaller removed 10% of this software .
I just may build a removal tool for this , should be real easy .
I am also taking a close look at all of the files left behind , what still loads and what this file is that runs for a split second after you uninstall .
#17
Posted 03 May 2008 - 02:39 AM
#18
Posted 03 May 2008 - 03:42 AM
SUPER © is NOT Malware. It is just a front end GUI to a bunch of command line audio/video tools for video manipulation.
I've used the program off and on for a long time now and had no problems with it.
I don't care for how he has you get to the actual download link but hey it's his software.
If you follow through to either the 3rd or 4th page the link to download is at the very bottom of the page.
I can sniff the actual link if you really need or want it.
#19
Posted 18 June 2008 - 09:19 AM
nosirrah, on Feb 15 2008, 01:13 AM, said:
These guys have a funny definition of the term uninstall .
At the very most their uninstaller removed 10% of this software .
I just may build a removal tool for this , should be real easy .
I am also taking a close look at all of the files left behind , what still loads and what this file is that runs for a split second after you uninstall .
#20
Posted 18 June 2008 - 09:33 AM
CJS, on Jun 18 2008, 10:19 AM, said:
At the very least a list of what's left behind would allow one of us to create a BFU script to automate the cleanup.
For we wrestle not against flesh and blood, but against principalities, against powers, and against the worldly governors, the princes of the darkness of this world...
0 user(s) are reading this topic
0 members, 0 guests, 0 anonymous users













