someoneother
2006-06-02, 16:21
Hi there
I updated my definitions today (2.6.2006) and did a scan.
Spybot found "Wincontrol" - Keylogger in C:\Windows\SETUP1.exe
I did some other scans at
www.virustotal.com
http://virusscan.jotti.org/
and
with my resident Kaspersky
and
with ad-aware se & AČ
no scanner found anything
Therefore I browsed this forum and found some related topics to the file C:\Windows\SETUP1:
http://forums.spybot.info/showthread.php?t=629&highlight=Setup1.exe
http://forums.spybot.info/showthread.php?t=620&highlight=Phoenix
The File identifies itself as MS Visual Basic....again
I suspect it to be a false positive since it appeared after installing the latest definitions which added Wincontrol.
I copied the md5 sum and the results of the online scan for further study:
AntiVir 6.34.1.37 06.02.2006 no virus found
Authentium 4.93.8 06.02.2006 no virus found
Avast 4.7.844.0 06.01.2006 no virus found
AVG 386 06.01.2006 no virus found
BitDefender 7.2 06.02.2006 no virus found
CAT-QuickHeal 8.00 06.01.2006 no virus found
ClamAV devel-20060426 06.02.2006 no virus found
DrWeb 4.33 06.02.2006 no virus found
eTrust-InoculateIT 23.72.25 06.02.2006 no virus found
eTrust-Vet 12.6.2240 06.02.2006 no virus found
Ewido 3.5 06.02.2006 no virus found
Fortinet 2.77.0.0 06.01.2006 no virus found
F-Prot 3.16f 06.02.2006 no virus found
Ikarus 0.2.65.0 06.02.2006 no virus found
Kaspersky 4.0.2.24 06.02.2006 no virus found
McAfee 4775 06.01.2006 no virus found
Microsoft 1.1441 06.02.2006 no virus found
NOD32v2 1.1575 06.02.2006 no virus found
Norman 5.90.17 06.02.2006 no virus found
Panda 9.0.0.4 06.01.2006 no virus found
Sophos 4.05.0 06.02.2006 no virus found
Symantec 8.0 06.02.2006 no virus found
TheHacker 5.9.8.154 06.01.2006 no virus found
UNA 1.83 06.01.2006 no virus found
VBA32 3.11.0 06.02.2006 no virus found
Aditional Information
File size: 253952 bytes
MD5: c95e569a0afa984a39f05d6dd5adeb3c
SHA1: a6cf7605f236259321f48fe24293075b11516696
thx for your attention :)
someoneelse
---
system: Windows XP Professional SP 2 (including all newer updates)
I updated my definitions today (2.6.2006) and did a scan.
Spybot found "Wincontrol" - Keylogger in C:\Windows\SETUP1.exe
I did some other scans at
www.virustotal.com
http://virusscan.jotti.org/
and
with my resident Kaspersky
and
with ad-aware se & AČ
no scanner found anything
Therefore I browsed this forum and found some related topics to the file C:\Windows\SETUP1:
http://forums.spybot.info/showthread.php?t=629&highlight=Setup1.exe
http://forums.spybot.info/showthread.php?t=620&highlight=Phoenix
The File identifies itself as MS Visual Basic....again
I suspect it to be a false positive since it appeared after installing the latest definitions which added Wincontrol.
I copied the md5 sum and the results of the online scan for further study:
AntiVir 6.34.1.37 06.02.2006 no virus found
Authentium 4.93.8 06.02.2006 no virus found
Avast 4.7.844.0 06.01.2006 no virus found
AVG 386 06.01.2006 no virus found
BitDefender 7.2 06.02.2006 no virus found
CAT-QuickHeal 8.00 06.01.2006 no virus found
ClamAV devel-20060426 06.02.2006 no virus found
DrWeb 4.33 06.02.2006 no virus found
eTrust-InoculateIT 23.72.25 06.02.2006 no virus found
eTrust-Vet 12.6.2240 06.02.2006 no virus found
Ewido 3.5 06.02.2006 no virus found
Fortinet 2.77.0.0 06.01.2006 no virus found
F-Prot 3.16f 06.02.2006 no virus found
Ikarus 0.2.65.0 06.02.2006 no virus found
Kaspersky 4.0.2.24 06.02.2006 no virus found
McAfee 4775 06.01.2006 no virus found
Microsoft 1.1441 06.02.2006 no virus found
NOD32v2 1.1575 06.02.2006 no virus found
Norman 5.90.17 06.02.2006 no virus found
Panda 9.0.0.4 06.01.2006 no virus found
Sophos 4.05.0 06.02.2006 no virus found
Symantec 8.0 06.02.2006 no virus found
TheHacker 5.9.8.154 06.01.2006 no virus found
UNA 1.83 06.01.2006 no virus found
VBA32 3.11.0 06.02.2006 no virus found
Aditional Information
File size: 253952 bytes
MD5: c95e569a0afa984a39f05d6dd5adeb3c
SHA1: a6cf7605f236259321f48fe24293075b11516696
thx for your attention :)
someoneelse
---
system: Windows XP Professional SP 2 (including all newer updates)