N
null
A user I have been helping discovered a Trojan in a freeware MP3 to
WAV converter named ABLEMP3.EXE from this site:
http://www.all4you.dk/FreewareWorld/links.php
It's called Trojan.Dropper.Small.GT by KAV and it's in the file named
WU1345RD.EXE located in \temp\data\app\0\temp
Most av scanners won't find it when scanning the install file since
they are incapable of scanning within the CAB archive within the SFX.
This particular one can have its files extracted first to a temp
folder using Power Archiver (or whatever), and then the files scanned
on-demand. When the culprit WU1345RD.EXE files is this exposed for
scanning, several av will then alert. I've also confirmed through
contact with Kaspersky that the file is indeed infested.
Art
http://www.epix.net/~artnpeg
WAV converter named ABLEMP3.EXE from this site:
http://www.all4you.dk/FreewareWorld/links.php
It's called Trojan.Dropper.Small.GT by KAV and it's in the file named
WU1345RD.EXE located in \temp\data\app\0\temp
Most av scanners won't find it when scanning the install file since
they are incapable of scanning within the CAB archive within the SFX.
This particular one can have its files extracted first to a temp
folder using Power Archiver (or whatever), and then the files scanned
on-demand. When the culprit WU1345RD.EXE files is this exposed for
scanning, several av will then alert. I've also confirmed through
contact with Kaspersky that the file is indeed infested.
Art
http://www.epix.net/~artnpeg