Results 1 to 8 of 8

Thread: Re: Suspicious File Packer

  1. #1
    Junior Member
    Join Date
    Sep 2006
    Posts
    9

    Default Re: Suspicious File Packer

    I still have the the d/l'ed codec file which I suspect was bogus and is causing me problems (http://forums.spybot.info/showthread.php?t=7416), can I use the SFP to send it to you for analysis?

    -Kit
    Dell Pentium 4, 3.2 ghz, Win XP media center 2005, Firefox,Thunderbird,Spywareblaster,Spybot s&d, Hijack This, Ad Aware, Avast antivirus, Win update auto.

  2. #2
    Member of Team Spybot tashi's Avatar
    Join Date
    Oct 2005
    Location
    USA
    Posts
    30,961

    Default

    Hi there.

    Please send the file zipped to: detections(AT)spybot.info

    Put the name of the file/infection into subject matter, cheers.
    Microsoft MVP Reconnect 2018-
    Windows Insider MVP 2016-2018
    Microsoft Consumer Security MVP 2006-2016

  3. #3
    Junior Member
    Join Date
    Sep 2006
    Posts
    9

    Default

    OK, I have the file now in a .zip format (it was an .exe), and sent it that way to you.

    I ran sfp.exe and it created a .cab, but I don't know what to do with the .cab folder??
    Dell Pentium 4, 3.2 ghz, Win XP media center 2005, Firefox,Thunderbird,Spywareblaster,Spybot s&d, Hijack This, Ad Aware, Avast antivirus, Win update auto.

  4. #4
    Security Expert-Emeritus
    Join Date
    Oct 2005
    Posts
    5,025

    Default

    Once you send the file (xxxx.cab) you can delete it and SFP to
    Not quite sure what you mean by .cab folder
    Thanks
    ~~~~~~~~~~~~~~~~~~~~~~~
    Microsoft MVP Windows-Security 2006

  5. #5
    Junior Member
    Join Date
    Sep 2006
    Posts
    9

    Default

    Your small tool, the Suspicious File Packer, creates a cab folder on the desktop, it is not clear or obvious how to get the suspicious file into it, in order to send.
    Dell Pentium 4, 3.2 ghz, Win XP media center 2005, Firefox,Thunderbird,Spywareblaster,Spybot s&d, Hijack This, Ad Aware, Avast antivirus, Win update auto.

  6. #6
    Security Expert-Emeritus
    Join Date
    Oct 2005
    Posts
    5,025

    Default

    Hi
    If you ran SPF and imput a file , example
    c:\windows\badfile.dll
    and click continue it will have put the file in the .cab that will appear on your desktop, understand ?
    ~~~~~~~~~~~~~~~~~~~~~~~
    Microsoft MVP Windows-Security 2006

  7. #7
    Junior Member
    Join Date
    Sep 2006
    Posts
    9

    Default

    i've got the concept, like, put the file into the cab folder, but I don't know the mechanism re the SFP program . Any way I zipped the suspect file and sent it to detections.

    Will that work?
    Dell Pentium 4, 3.2 ghz, Win XP media center 2005, Firefox,Thunderbird,Spywareblaster,Spybot s&d, Hijack This, Ad Aware, Avast antivirus, Win update auto.

  8. #8
    Security Expert-Emeritus
    Join Date
    Oct 2005
    Posts
    5,025

    Default

    Thats fine, Thanks
    Continue in your topic in the malware section.
    ~~~~~~~~~~~~~~~~~~~~~~~
    Microsoft MVP Windows-Security 2006

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •