VDOWN - Best SoftWARE We Down
VDOWN , Hotfile, MegaUpload, Easy-Share, Filefactory, VIP-File, LetItBit, BitRoad, Up-File Reseller  

Welcome Guest ( Log In | Register )

 
Reply to this topicStart new topic
Trojan Warning, Core Keygen Warning
twip
post Jul 16 2010, 09:33 PM
Post #1


Earnest Member
****

Group: Member
Posts: 356
Joined: 10-November 02
Member No.: 6,161



I got this 'Trojan Downloader.win32.Exchanger.bbb' Warning about the 'Core' keygen from KIS.

Is it a false positive?


Thanx

twip
Go to the top of the page
 
+Quote Post
jalaffa
post Jul 16 2010, 09:59 PM
Post #2


Premium Member
*****

Group: Supporter
Posts: 967
Joined: 31-March 07
Member No.: 44,226



Most likely if it was posted on this board. BUT there are cases were bad people attach malware to the real keygens and post those on obscure sites with no quality control.

QUOTE
http://blocklistpro.com/latest/when-a-keygen-is-more-than-a-keygen.html


The keygen described there is NOT the real CORE keygen as posted on this board here
Go to the top of the page
 
+Quote Post
twip
post Jul 16 2010, 11:59 PM
Post #3


Earnest Member
****

Group: Member
Posts: 356
Joined: 10-November 02
Member No.: 6,161



Thanx jaffala for the reply.

It was on this board. Members area.

Suspect: Play With Pictures.

twip
Go to the top of the page
 
+Quote Post
nonspin
post Jul 19 2010, 04:36 AM
Post #4


Junior Member
*

Group: True Member
Posts: 42
Joined: 5-October 09
Member No.: 55,496




i would bet quite some money on it being a trojan, because of three reasons:

1. Core never released a keygen for any Kaspersky produt.

2. The detection string for the Trojan-Downloader.Win32.Exchanger.a (and b)
is obvioulsy a program which is capable of accessing a remote computer to download further files.
Now, for that happen it needs to utilize specific functions of standard DLLs.
Them funtions are specified in the Import Table of a program.

For example WININET.InternetOpenA or WININET.InternetReadFile.
If none of those imports are present it's not a "Trojan-Downloader".
Since keygens dont usually need these functions plus the fact that they are
present it looks - let's say - very very suspicious.

3. What better way to infect a computer by knowing it currently has no defence running.


If you still have access to that keygen, post a link so i can analyse it - please.

nonspin



Go to the top of the page
 
+Quote Post
twip
post Jul 31 2010, 06:14 AM
Post #5


Earnest Member
****

Group: Member
Posts: 356
Joined: 10-November 02
Member No.: 6,161



QUOTE (nonspin @ Jul 19 2010, 05:36 AM) *


Sorry for the delay in replying.

1. It was KIS that gave the warning. It was not the app with the suspect core keygen.

2. The app with the 'suspect' is 'Play With Pictures' + core keygen. If you want to look at it, its in the dl area of this board.

Good luck. Be very careful!

twip
Go to the top of the page
 
+Quote Post

Reply to this topicStart new topic
1 User(s) are reading this topic (1 Guests and 0 Anonymous Users)
0 Members:

 



RSS Lo-Fi Version Time is now: 7th September 2010 - 04:50 AM