Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
WinToUSB Trojan!?
#11
Post information to the creator of the software, it could be a false positive, because virustotal shows up clean.
Could you please removed confirmed Virus from title until we are 100% positive its a virus.
<left><form action="https://www.paypal.com/cgi-bin/webscr" method="post">If you are satisfied with my help, consider a donation. Thank you so much for your continued support! 
<input type="hidden" name="cmd" value="_s-xclick">
<input type="hidden" name="hosted_button_id" value="Y4ZDLXGFS4F8Q">
<input type="image" src="https://www.paypalobjects.com/en_US/GB/i/btn/btn_donateCC_LG.gif" border="0" name="submit" alt="PayPal — The safer, easier way to pay online.">
<img alt="" border="0" src="https://www.paypalobjects.com/en_GB/i/scr/pixel.gif" width="0" height="0">
</form>

   </div></left> 
Reply

#12
Sure, but do you not think that a dll called WATCHER.DLL is dodgy? And then when you run the program kaspersky detects that it is watching you and asks to delete it? I really am inclined to believe it is a virus.
Reply

#13
You could well be right about it being a virus, but we need to b e sure, I will take a look at it in a day or so.
What I don't want is we start to post content saying is a virus and its a false positive, we need to be 100% sure before we warn people away from the software.
<left><form action="https://www.paypal.com/cgi-bin/webscr" method="post">If you are satisfied with my help, consider a donation. Thank you so much for your continued support! 
<input type="hidden" name="cmd" value="_s-xclick">
<input type="hidden" name="hosted_button_id" value="Y4ZDLXGFS4F8Q">
<input type="image" src="https://www.paypalobjects.com/en_US/GB/i/btn/btn_donateCC_LG.gif" border="0" name="submit" alt="PayPal — The safer, easier way to pay online.">
<img alt="" border="0" src="https://www.paypalobjects.com/en_GB/i/scr/pixel.gif" width="0" height="0">
</form>

   </div></left> 
Reply

#14
There are legit watcher.dll files and some can/are malicious in some way, but as Brian says contact the owner of the software to let them know. Also I would contact Kaspersky and talk them through it as they may wish to investigate further.

[additional]

Ran a little check on WintoUSB 1.6 beta (couldnt get the 1.5 version to work) using Ghex and the only thing I could tell from the brief view (and it was quite brief) is that it has a "mailslot" program which could be perfectly legit. ClamAV, chrootkit both showed no problems, here's an image of the hex;

   
Reply

#15
I was going to say, if it was a bad program, I am sure virustotal would of have at least 3 or 4 virus detections, Kaspersky detected it as a virus, but that was a 2013 version I see, Kaspersky is one of many antivirus company's on virustotal and it did not detect it, maybe the programs has talked with these company's and its now classed as a false positive.

I will take a look when I get time.
<left><form action="https://www.paypal.com/cgi-bin/webscr" method="post">If you are satisfied with my help, consider a donation. Thank you so much for your continued support! 
<input type="hidden" name="cmd" value="_s-xclick">
<input type="hidden" name="hosted_button_id" value="Y4ZDLXGFS4F8Q">
<input type="image" src="https://www.paypalobjects.com/en_US/GB/i/btn/btn_donateCC_LG.gif" border="0" name="submit" alt="PayPal — The safer, easier way to pay online.">
<img alt="" border="0" src="https://www.paypalobjects.com/en_GB/i/scr/pixel.gif" width="0" height="0">
</form>

   </div></left> 
Reply



Forum Jump:


Users browsing this thread:
1 Guest(s)

Powered By MyBB, © 2002-2024 Melroy van den Berg.