Trojan Warning, Core Keygen Warning |
|
![]() ![]() |
Trojan Warning, Core Keygen Warning |
Jul 16 2010, 09:33 PM
Post
#1
|
|
|
Earnest Member ![]() ![]() ![]() ![]() Group: Member Posts: 356 Joined: 10-November 02 Member No.: 6,161 |
I got this 'Trojan Downloader.win32.Exchanger.bbb' Warning about the 'Core' keygen from KIS.
Is it a false positive? Thanx twip |
|
|
|
Jul 16 2010, 09:59 PM
Post
#2
|
|
|
Premium Member ![]() ![]() ![]() ![]() ![]() Group: Supporter Posts: 967 Joined: 31-March 07 Member No.: 44,226 |
Most likely if it was posted on this board. BUT there are cases were bad people attach malware to the real keygens and post those on obscure sites with no quality control.
QUOTE http://blocklistpro.com/latest/when-a-keygen-is-more-than-a-keygen.html The keygen described there is NOT the real CORE keygen as posted on this board here |
|
|
|
Jul 16 2010, 11:59 PM
Post
#3
|
|
|
Earnest Member ![]() ![]() ![]() ![]() Group: Member Posts: 356 Joined: 10-November 02 Member No.: 6,161 |
Thanx jaffala for the reply.
It was on this board. Members area. Suspect: Play With Pictures. twip |
|
|
|
Jul 19 2010, 04:36 AM
Post
#4
|
|
|
Junior Member ![]() Group: True Member Posts: 42 Joined: 5-October 09 Member No.: 55,496 |
i would bet quite some money on it being a trojan, because of three reasons: 1. Core never released a keygen for any Kaspersky produt. 2. The detection string for the Trojan-Downloader.Win32.Exchanger.a (and b) is obvioulsy a program which is capable of accessing a remote computer to download further files. Now, for that happen it needs to utilize specific functions of standard DLLs. Them funtions are specified in the Import Table of a program. For example WININET.InternetOpenA or WININET.InternetReadFile. If none of those imports are present it's not a "Trojan-Downloader". Since keygens dont usually need these functions plus the fact that they are present it looks - let's say - very very suspicious. 3. What better way to infect a computer by knowing it currently has no defence running. If you still have access to that keygen, post a link so i can analyse it - please. nonspin |
|
|
|
Jul 31 2010, 06:14 AM
Post
#5
|
|
|
Earnest Member ![]() ![]() ![]() ![]() Group: Member Posts: 356 Joined: 10-November 02 Member No.: 6,161 |
Sorry for the delay in replying. 1. It was KIS that gave the warning. It was not the app with the suspect core keygen. 2. The app with the 'suspect' is 'Play With Pictures' + core keygen. If you want to look at it, its in the dl area of this board. Good luck. Be very careful! twip |
|
|
|
![]() ![]() |
|
Lo-Fi Version | Time is now: 7th September 2010 - 04:50 AM |