Antivirus Pgm and massdown

  • Thread starter Thread starter whodunit
  • Start date Start date
W

whodunit

I was given an AV program for my antiquated laptop for which few AV
programs will run.

An AV scan with sophos determines it contains massdown.exe which is not
classified as a virus but "malware"

Can I install this safely on my little laptop and if so, what, if any
bad effects might await me?

Thanks for any nice, useful answers to my question.
 
whodunit said:
I was given an AV program for my antiquated laptop for which few AV
programs will run.

Does this AV have a name - or is it a secret AV program?
An AV scan with sophos determines it contains massdown.exe which is not
classified as a virus but "malware"

You scanned the mystery AV with Sophos and it found a potentially
malicious program (hacktool).
Can I install this safely on my little laptop and if so, what, if any
bad effects might await me?

Sounds to me like the mystery AV is a trojan form of the massdown.exe
hacktool. I'm not sure, but it might be a downloader trojan in which case
*anything* can happen - it depends on just what gets downloaded and
executed.
Thanks for any nice, useful answers to my question.

Submit the file to virustotal.com or jotti.org to see what opinions some
other AVs have about the file. I don't think you want to execute that
program.
 
Does this AV have a name - or is it a secret AV program?

You scanned the mystery AV with Sophos and it found a potentially
malicious program (hacktool).


Sounds to me like the mystery AV is a trojan form of the massdown.exe
hacktool. I'm not sure, but it might be a downloader trojan in which
case *anything* can happen - it depends on just what gets downloaded
and executed.

thanks for the site names. what type of analysis do they generall give?
it's a downloader but it might be to register the program, not sure
 
whodunit said:
thanks for the site names. what type of analysis do they generall give?

They identify most known malware. Several AV's and AM detection
engines are used.
it's a downloader but it might be to register the program, not sure

Not likely, Sophos is seldom wrong about what it detects.

[snip]
 
Back
Top