Welcome, Guest. Please login or register.
January 01, 2010, 07:08:16 PM

Login with username, password and session length

346709 Posts
38326 Topics
87059 Members

Latest Member: Panda K

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Desktop Security Products
| |-+  Comodo Internet Security - CIS
| | |-+  Virus/Malware Removal Assistance
| | | |-+  Need help understanding virus total analysis
« previous next »
Pages: [1] Go Down Print
Author Topic: Need help understanding virus total analysis  (Read 666 times)
Babasan
Newbie
*
Offline Offline

Posts: 1


« on: September 29, 2009, 10:52:08 AM »

I recently uploaded a file to virustotal and got this link.

Am I supposed to use best judgement (It's obvious that the majority of scanners found something wrong with this file)
Or os there another part of viruis total that has their official opinion onit?

thanks!

newbie

system scan results are as follows.
 

 File SystemMechanic_9.0.3.3_getLinkPro received on 2009.08.27 06:14:08 (UTC)
Current status: finished
Result: 30/41 (73.17%)
Compact Compact
Print results Print results
Antivirus    Version    Last Update    Result
a-squared    4.5.0.24    2009.08.27    -
AhnLab-V3    5.0.0.2    2009.08.26    -
AntiVir    7.9.1.7    2009.08.26    TR/PCK.Black.A.3102
Antiy-AVL    2.0.3.7    2009.08.24    Packed/Win32.Black.gen
Authentium    5.1.2.4    2009.08.27    W32/Heuristic-210!Eldorado
Avast    4.8.1335.0    2009.08.26    Win32:Trojan-gen {Other}
AVG    8.5.0.406    2009.08.26    Win32/Themida
BitDefender    7.2    2009.08.27    Trojan.Generic.2147042
CAT-QuickHeal    10.00    2009.08.25    Trojan.Black.a
ClamAV    0.94.1    2009.08.27    Trojan.Packed-142
Comodo    2100    2009.08.27    TrojWare.Win32.Black.a
DrWeb    5.0.0.12182    2009.08.27    Trojan.Packed.650
eSafe    7.0.17.0    2009.08.26    Win32.Packed.Black.A
eTrust-Vet    31.6.6703    2009.08.26    -
F-Prot    4.5.1.85    2009.08.26    W32/Heuristic-210!Eldorado
F-Secure    8.0.14470.0    2009.08.27    Packed.Win32.Black.a
Fortinet    3.120.0.0    2009.08.27    W32/Black.A
GData    19    2009.08.27    Trojan.Generic.2147042
Ikarus    T3.1.1.68.0    2009.08.27    Trojan.Crypt
Jiangmin    11.0.800    2009.08.27    Packed.Black.deg
K7AntiVirus    7.10.828    2009.08.26    Packed.Win32.Black.a
Kaspersky    7.0.0.125    2009.08.27    Packed.Win32.Black.a
McAfee    5721    2009.08.26    New Malware.jn
McAfee+Artemis    5721    2009.08.26    New Malware.jn
McAfee-GW-Edition    6.8.5    2009.08.26    Trojan.PCK.Black.A.3102
Microsoft    1.4903    2009.08.27    VirTool:Win32/Obfuscator.XX
NOD32    4371    2009.08.26    probably a variant of Win32/Obfuscated
Norman       2009.08.26    -
nProtect    2009.1.8.0    2009.08.26    -
Panda    10.0.2.2    2009.08.26    Trj/CI.A
PCTools    4.4.2.0    2009.08.26    Packed/Themida.RGa
Prevx    3.0    2009.08.27    -
Rising    21.44.11.00    2009.08.25    -
Sophos    4.44.0    2009.08.27    Mal/Generic-A
Sunbelt    3.2.1858.2    2009.08.26    -
Symantec    1.4.4.12    2009.08.27    Trojan Horse
TheHacker    6.3.4.3.388    2009.08.25    Trojan/Black.a
TrendMicro    8.950.0.1094    2009.08.27    -
VBA32    3.12.10.10    2009.08.27    -
ViRobot    2009.8.26.1904    2009.08.27    -
VirusBuster    4.6.5.0    2009.08.26    Trojan.Black.DOI
Additional information
File size: 19466497 bytes
MD5   : 4f43a36c41ae77d55ebaa1c28968720d
SHA1  : 7915787951196c36d86ea5929b9c4a5a5033e3b5
SHA256: d4d38cc15513e3d37f255fd668040defafb6375729830e6e77d6114c9760186c
TrID  : File type identification
RAR Archive (83.3%)
REALbasic Project (16.6%)
ssdeep: 393216:gVycQK4IuVuCBYh4v91QxIPT7ykmzw3GYswVT4XhBY0:gVycQvR3BoxIPyFzJgT4XhBp
PEiD  : -
packers (Kaspersky): ASPack, ASPack, ASPack, ASPack, ASPack, ASPack, ASPack, ASPack, ASPack, ASPack, ASPack, ASPack, ASPack, ASPack, ASPack, ASPack, ASPack, ASPack, ASPack, ASPack, ASPack, ASPack, ASPack, ASPack, ASPack
packers (F-Prot): Themida
packers (Authentium): Themida
RDS   : NSRL Reference Data Set
-

ATENTION ATTENTION: VirusTotal is a free service offered by Hispasec Sistemas. There are no guarantees about the availability and continuity of this service. Although the detection rate afforded by the use of multiple antivirus engines is far superior to that offered by just one product, these results DO NOT guarantee the harmlessness of a file. Currently, there is not any solution that offers a 100% effectiveness rate for detecting viruses and malware.
Logged
OmeletGuy
Good gamer, Omelet Chef, Rogue AV hater!
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 1704


The only thing i ask for are eggs.


WWW
« Reply #1 on: September 29, 2009, 03:11:03 PM »

I would say with that many detections its malware.. Remove the file.


The problem is that sometimes there can be FP detections... or sometimes a malware files gets no detection.
Logged

Happy New Year and Holidays
Please follow forum policy. Thank you.
Endymion
Comodo's Hero
*****
Offline Offline

Posts: 975


Reality is subordinate to perception


WWW
« Reply #2 on: September 29, 2009, 03:48:32 PM »

According to Trojan:W32/Black.A: What you Need to Know it looks a  file packed with a stolen portion of Themida cryptor.
« Last Edit: September 29, 2009, 03:50:15 PM by Endymion » Logged

I have learnt silence from the talkative, toleration from the intolerant, and kindness from the unkind; yet strange, I am ungrateful to these teachers.
Kahlil Gibran (1883 - 1931)
Tags: win32  trojan  Virus 
Pages: [1] Go Up Print 
« previous next »
Jump to:  

SSL Certificate Free Virus Removal Firewall
Page created in 0.041 seconds with 19 queries.
Powered by SMF 1.1.11 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com