The Notebook Review forums were hosted by TechTarget, who shut down them down on January 31, 2022. This static read-only archive was pulled by NBR forum users between January 20 and January 31, 2022, in an effort to make sure that the valuable technical information that had been posted on the forums is preserved. For current discussions, many NBR forum users moved over to NotebookTalk.net after the shutdown.
Problems? See this thread at archive.org.

    Question about a Dodgy looking file...

    Discussion in 'Windows OS and Software' started by Dan09, Nov 11, 2009.

  1. Dan09

    Dan09 Notebook Enthusiast

    Reputations:
    0
    Messages:
    46
    Likes Received:
    0
    Trophy Points:
    15
    Hey everyone! I have a quick question regarding running a suspicious looking setup.exe program contained on a .iso file I recently received from a friend.

    I ran a online virus scan on the fishy file and it came up mostly clean. Of all the scanners that check the file, only one called "The Hacker" found something of interest. A lovely Trojan called "Trojan/Banbra.phg" that apparently is made for keylogging online user/pass details on the infected computer.

    Here are the results from Virustotal.com (great site btw)
    Sorry it came out looking all crazy, really the only important line is the one I've bolded, so whatever.
    Code:
    Antivirus 	Version 	Last Update 	Result
    a-squared 	4.5.0.41 	2009.11.10 	-
    AhnLab-V3 	5.0.0.2 	2009.11.06 	-
    AntiVir 	7.9.1.61 	2009.11.10 	-
    Antiy-AVL 	2.0.3.7 	2009.11.10 	-
    Authentium 	5.2.0.5 	2009.11.10 	-
    Avast 	4.8.1351.0 	2009.11.10 	-
    AVG 	8.5.0.423 	2009.11.10 	-
    BitDefender 	7.2 	2009.11.10 	-
    CAT-QuickHeal 	10.00 	2009.11.10 	-
    ClamAV 	0.94.1 	2009.11.10 	-
    Comodo 	2905 	2009.11.10 	-
    DrWeb 	5.0.0.12182 	2009.11.10 	-
    eSafe 	7.0.17.0 	2009.11.10 	-
    eTrust-Vet 	35.1.7113 	2009.11.10 	-
    F-Prot 	4.5.1.85 	2009.11.10 	-
    F-Secure 	9.0.15370.0 	2009.11.09 	-
    Fortinet 	3.120.0.0 	2009.11.10 	-
    GData 	19 	2009.11.10 	-
    Ikarus 	T3.1.1.74.0 	2009.11.10 	-
    Jiangmin 	11.0.800 	2009.11.10 	-
    K7AntiVirus 	7.10.892 	2009.11.09 	-
    Kaspersky 	7.0.0.125 	2009.11.10 	-
    McAfee 	5797 	2009.11.09 	-
    McAfee+Artemis 	5797 	2009.11.09 	-
    McAfee-GW-Edition 	6.8.5 	2009.11.10 	-
    Microsoft 	1.5202 	2009.11.10 	-
    NOD32 	4592 	2009.11.10 	-
    Norman 	6.03.02 	2009.11.09 	-
    nProtect 	2009.1.8.0 	2009.11.10 	-
    Panda 	10.0.2.2 	2009.11.09 	-
    PCTools 	7.0.3.5 	2009.11.10 	-
    Prevx 	3.0 	2009.11.12 	-
    Rising 	22.21.01.09 	2009.11.10 	-
    Sophos 	4.47.0 	2009.11.10 	-
    Sunbelt 	3.2.1858.2 	2009.11.10 	-
    Symantec 	1.4.4.12 	2009.11.10 	-
    [B]TheHacker 	6.5.0.2.064 	2009.11.09 	Trojan/Banbra.phg[/B]
    TrendMicro 	9.0.0.1003 	2009.11.10 	-
    VBA32 	3.12.10.11 	2009.11.09 	-
    ViRobot 	2009.11.10.2029 	2009.11.10 	-
    VirusBuster 	4.6.5.0 	2009.11.09 	-
    Now, this scanner "The Hacker" is a Peruvian Virus scanner that I've personally never heard of. Also, I dont even have an online bank account (I'm not old enough yet).

    So basically what I'm asking is this : Do you guys think I should risk running this program and pray that it is legit? I have great need to install the program that it is for, but I'd still rather not have a Trojan hidden away on my computer...

    Things and stuff: http://www.pctools.com/mrc/infections/id/Trojan.Banbra.EJ/ <---- Description of the Trojan

    http://translate.google.com/translate?hl=en&sl=es&u=http://www.hacksoft.com.pe/&ei=RIr7SrjoN9DanAeciK2aBQ&sa=X&oi=translate&ct=result&resnum=3&ved=0CA8Q7gEwAg&prev=/search%3Fq%3DTheHacker%26hl%3Den%26client%3Dfirefox-a%26rls%3Dorg.mozilla:en-US:eek:fficial%26hs%3Ddn6 <---- Site of this Peruvian Virus Scanner. (translated from Spanish,lol)


    Opinions? Thanks very much!! :confused:
     
  2. surfasb

    surfasb Titles Shmm-itles

    Reputations:
    2,637
    Messages:
    6,370
    Likes Received:
    0
    Trophy Points:
    205
    Get yourself a VM and install it to make sure. Otherwise, I wouldn't risk it, unless your friend is willing to take a bullet for ya.
     
  3. Dan09

    Dan09 Notebook Enthusiast

    Reputations:
    0
    Messages:
    46
    Likes Received:
    0
    Trophy Points:
    15
    Not a bad idea! Any suggestions on what VM to use? I don't have any installed atm. :)
     
  4. surfasb

    surfasb Titles Shmm-itles

    Reputations:
    2,637
    Messages:
    6,370
    Likes Received:
    0
    Trophy Points:
    205