- Dec 30, 2012
- 4,809
yet another statement that avoid the initial questions... i felt something suspicious about you at first. now i'm going to avoid you as much as i can. have a nice day.hi
i have't found any suspicious activity
Hi mate, you're absolutely rightWhat are you talking about?
The sample does not directly import NTAPI functions and call them manually..
I have to admit that I am a bit confused as well... So you are not the only one who felt a bit awkward. :/yet another statement that avoid the initial questions... i felt something suspicious about you at first. now i'm going to avoid you as much as i can. have a nice day.
This is pretty simple to understand... After a malware submission, avira will add a local signature.. But that's usually done in one or two days so.. Avira knows that the sample is malicious but still haven't added it to their databaseshi
weird virus total show that for avira is clean
thanks
h$$ps://www.portablefreeware.com/forums/viewtopic.php?f=2&t=23210&start=15
I'm going to run it on my VM give me a sec.hi
i download here
Code:h$$ps://www.portablefreeware.com/forums/viewtopic.php?f=2&t=23210&start=15
Can you submit it to some AV companies to see their verdict? Already done: Kaspersky, Avira, Microsoft, Symantec, BitdefenderAlright so it is detected by Zemana Anti-Malware:
View attachment 128554
Emsisoft says it's clean:
View attachment 128549
File Details are basically empty (not a good sign):
View attachment 128550
VirusTotal:
View attachment 128552
Both Avira & Dr. Web pick this up as malicious - each are well known AVs & have pretty good signatures.
Could be some sort of Keylogger:
View attachment 128551
I executed the sample:
View attachment 128553
The RAM usage stayed the same most of the time but the CPU went all over the place - between 0 & 12% CPU usage.
View attachment 128548
Whilst typing the CPU usage of the file increased (peaked at about 10%):
View attachment 128547
This could just be a coincidence...
Verdict:
Personally I wouldn't run that file just in case. Several people on VirusTotal say it's malicious and if something has higher than 3 or 4/57 on VirusTotal then it is possible that it is a new threat. Hybrid thinks it's malicious as well so I would not run it. Zemana has picked it up & that also backs up the fact that it's malicious because Zemana Anti-Malware is a brilliant application which has good signatures.
sent to Avast but so far no detection for it yetCan you submit it to some AV companies to see their verdict? Already done: Kaspersky, Avira, Microsoft, Symantec, Bitdefender
Yep later I'm not taking the day off since I got a busy Christmas Day! Merry Xmas!Can you submit it to some AV companies to see their verdict? Already done: Kaspersky, Avira, Microsoft, Symantec, Bitdefender
hiVerdict:
Personally I wouldn't run that file just in case. Several people on VirusTotal say it's malicious and if something has higher than 3 or 4/57 on VirusTotal then it is possible that it is a new threat. Hybrid thinks it's malicious as well so I would not run it. Zemana has picked it up & that also backs up the fact that it's malicious because Zemana Anti-Malware is a brilliant application which has good signatures.
I cannot match the sample to a specific threat type however I do not think that the intent of the sample is for genuine purposes due to the suspicious characteristics, therefore it's risk-ware at the least (thus should be avoided).hi
thank you so much
but it doesn't change files,or registry ,it's easy to close ,doesn't comunicate or using internet or network cable
i have found nothing
thanks
I have not looked at the sample for the moment (currently working on another part).@DardiM what is your opinion on the sample?