PDA

View Full Version : Spybot says SetIEInstalledDate.exe is a trojan?



Blitzteh
2010-04-23, 18:36
On my computer, Spybot finds this on my computer and it says SetIEInstalledDate.exe is a trojan, I've sent this file using Suspicious File Packer to BleepingComputer.com and my helper says the file is clean.

This is a spybot report of it.

--

Win32.Exchanger.ch: [SBI $93F36CF0] Executable (File, nothing done)
C:\WINDOWS\System32\SetIEInstalledDate.exe
Properties.size=107008


--- Spybot - Search & Destroy version: 1.6.2 (build: 20090126) ---

2009-01-26 blindman.exe (1.0.0.8)
2009-01-26 SDFiles.exe (1.6.1.7)
2009-01-26 SDMain.exe (1.0.0.6)
2009-01-26 SDShred.exe (1.0.2.5)
2009-01-26 SDUpdate.exe (1.6.0.12)
2009-01-26 SDWinSec.exe (1.0.0.12)
2009-01-26 SpybotSD.exe (1.6.2.46)
2009-03-05 TeaTimer.exe (1.6.6.32)
2009-12-01 unins000.exe (51.49.0.0)
2009-01-26 Update.exe (1.6.0.7)
2009-11-04 advcheck.dll (1.6.5.20)
2007-04-02 aports.dll (2.1.0.0)
2008-06-14 DelZip179.dll (1.79.11.1)
2009-01-26 SDHelper.dll (1.6.2.14)
2008-06-19 sqlite3.dll
2009-01-26 Tools.dll (2.1.6.10)
2009-01-16 UninsSrv.dll (1.0.0.0)
2010-02-17 Includes\Adware.sbi (*)
2010-04-20 Includes\AdwareC.sbi (*)
2010-01-25 Includes\Cookies.sbi (*)
2009-11-03 Includes\Dialer.sbi (*)
2010-04-13 Includes\DialerC.sbi (*)
2010-01-25 Includes\HeavyDuty.sbi (*)
2009-05-26 Includes\Hijackers.sbi (*)
2010-04-13 Includes\HijackersC.sbi (*)
2010-01-20 Includes\Keyloggers.sbi (*)
2010-04-13 Includes\KeyloggersC.sbi (*)
2004-11-29 Includes\LSP.sbi (*)
2010-03-02 Includes\Malware.sbi (*)
2010-04-20 Includes\MalwareC.sbi (*)
2009-03-25 Includes\PUPS.sbi (*)
2010-04-13 Includes\PUPSC.sbi (*)
2010-01-25 Includes\Revision.sbi (*)
2009-01-13 Includes\Security.sbi (*)
2010-04-13 Includes\SecurityC.sbi (*)
2008-06-03 Includes\Spybots.sbi (*)
2008-06-03 Includes\SpybotsC.sbi (*)
2010-03-02 Includes\Spyware.sbi (*)
2010-04-20 Includes\SpywareC.sbi (*)
2010-03-08 Includes\Tracks.uti
2010-03-03 Includes\Trojans.sbi (*)
2010-04-13 Includes\TrojansC-02.sbi (*)
2010-04-20 Includes\TrojansC-03.sbi (*)
2010-04-20 Includes\TrojansC-04.sbi (*)
2010-04-20 Includes\TrojansC-05.sbi (*)
2010-04-20 Includes\TrojansC.sbi (*)
2008-03-04 Plugins\Chai.dll
2008-03-05 Plugins\Fennel.dll
2008-02-26 Plugins\Mate.dll
2007-12-24 Plugins\TCPIPAddress.dll

Matt
2010-04-26, 14:43
Hi Blitzteh,

can you please upload the file to VirusTotal (http://www.virustotal.com/) and sent us the results? :thanks:

Moreover, this thread should be important for you:
http://forums.spybot.info/showthread.php?t=19117

Blitzteh
2010-04-27, 06:12
Hey,

For some reason I have trouble uploading the file directly to VirusTotal so I used Suspicious File Packer to zip it and upload it, not sure if it'll affect anything

I'm not sure if this is the correct way to post VirusTotal results.

--

File requested-files_2010-04-26_22_59_ received on 2010.04.27 03:02:58 (UTC)
Current status: finished
Result: 0/41 (0%)

Antivirus Version Last Update Result
a-squared 4.5.0.50 2010.04.27 -
AhnLab-V3 5.0.0.2 2010.04.27 -
AntiVir 8.2.1.224 2010.04.26 -
Antiy-AVL 2.0.3.7 2010.04.26 -
Authentium 5.2.0.5 2010.04.27 -
Avast 4.8.1351.0 2010.04.26 -
Avast5 5.0.332.0 2010.04.26 -
AVG 9.0.0.787 2010.04.26 -
BitDefender 7.2 2010.04.27 -
CAT-QuickHeal 10.00 2010.04.26 -
ClamAV 0.96.0.3-git 2010.04.27 -
Comodo 4685 2010.04.27 -
DrWeb 5.0.2.03300 2010.04.27 -
eSafe 7.0.17.0 2010.04.26 -
eTrust-Vet 35.2.7452 2010.04.26 -
F-Prot 4.5.1.85 2010.04.26 -
F-Secure 9.0.15370.0 2010.04.26 -
Fortinet 4.0.14.0 2010.04.26 -
GData 21 2010.04.27 -
Ikarus T3.1.1.80.0 2010.04.27 -
Jiangmin 13.0.900 2010.04.26 -
Kaspersky 7.0.0.125 2010.04.27 -
McAfee 5.400.0.1158 2010.04.27 -
McAfee-GW-Edition 6.8.5 2010.04.26 -
Microsoft 1.5703 2010.04.27 -
NOD32 5063 2010.04.26 -
Norman 6.04.11 2010.04.26 -
nProtect 2010-04-26.01 2010.04.26 -
Panda 10.0.2.7 2010.04.26 -
PCTools 7.0.3.5 2010.04.27 -
Prevx 3.0 2010.04.27 -
Rising 22.45.01.01 2010.04.27 -
Sophos 4.53.0 2010.04.27 -
Sunbelt 6226 2010.04.27 -
Symantec 20091.2.0.41 2010.04.27 -
TheHacker 6.5.2.0.269 2010.04.26 -
TrendMicro 9.120.0.1004 2010.04.26 -
TrendMicro-HouseCall 9.120.0.1004 2010.04.27 -
VBA32 3.12.12.4 2010.04.26 -
ViRobot 2010.4.26.2294 2010.04.26 -
VirusBuster 5.0.27.0 2010.04.26 -
Additional information
File size: 12115 bytes
MD5...: 33513212014b2569d2b4e6c3ba650af5
SHA1..: bcefa32da2e86a6e5f32f205970cb1fa18aba450
SHA256: 0bf4e597ad5bcb1d3e58c7ba1421faee1c8e96adc872e5eaa451af2c30f20151
ssdeep: 192:oRF/iJOrXhKpI5LlV93zzHvxJ+aCIxTilZl2z9GjgJKZ20AmMqy6wcgF:oX6
JuRKG5hVt3H+raqZl2zg6KZTAmXWF
PEiD..: -
PEInfo: -
RDS...: NSRL Reference Data Set
-
pdfid.: -
trid..: Microsoft Cabinet Archive (99.9%)
Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%)
sigcheck:
publisher....: n/a
copyright....: n/a
product......: n/a
description..: n/a
original name: n/a
internal name: n/a
file version.: n/a
comments.....: n/a
signers......: -
signing date.: -
verified.....: Unsigned
Symantec Reputation Network: Suspicious.Insight http://www.symantec.com/security_response/writeup.jsp?docid=2010-021223-0550-99

Edit
http://forums.spybot.info/showthread.php?p=368823#post368823

Yodama
2010-04-27, 15:25
The file is a trojan horse and you should terminate it as soon as possible.

The file you uploaded to virus total is the archive containing the trojan exe. Virustotal does not unpack the file, you can see this in the scan results, for instance in the file size.

tashi
2010-04-27, 20:45
Hello Blitzteh,

Please post back to your topic in the malware removal forum: http://forums.spybot.info/showthread.php?p=368823

Best regards. :)