PDA

View Full Version : Confirmed: Virtumonde.sdn in iwlandrvxpver.dll



EC120
2009-05-14, 01:27
I just finished scan after downloading today's updates (May 13), and Spybot found the following file as Virtumonde.sdn > iwlandrvxpver.dll located in C:\windows

http://www.picpower.net/images/qw5v7me65ztuk6rcvdh.jpg

virustotal report:
https://www.virustotal.com/analisis/...f1a1ac5b25c96e


file properties
http://www.picpower.net/images/fteo689vxznk9os0s81s.jpg


Windows XP Professional SP3
IE7 + Firefox 3.0.10
Spybot 1.6.2.46, detection update 5/13/2009
False positive occurred in Scan result
file sent to detections(AT)spybot.info


--- Search result list ---
Virtumonde.sdn: [SBI $CEEBD3EB] Library (File, nothing done)
C:\WINDOWS\iwlandrvxpver.dll
Properties.size=53248
Properties.md5=C1430948A900C5E7CA55D0CD17815CBD
Properties.filedate=1183068690
Properties.filedatetext=2007-06-28 15:11:30

Yodama
2009-05-14, 07:56
Thank you for sending in the file for analysis.
I can confirm this false positive. Please set Spybot S&D to ignore this file from further scans. The corrections for this detection will be released with the update scheduled for 2009-05-20