Is it a virus?

gwarbot

Senior member
Nov 18, 2004
508
0
0
My friend said the file sent to him made his compuer freak out. So I opened it with Pe explorer and disassembled it.

I found thes lines.

; Imports from kernel32.dll
;
extrn LoadLibraryA
extrn GetProcAddress
extrn VirtualAlloc
extrn VirtualFree
db 00h;
mov eax, L00456C4C

Im not sure if these are malicious or not, but Avg isn't picking it up as a virus. But then again my friends pc went to crap after opening it, he froze up and restarted.
 

FlyingPenguin

Golden Member
Nov 1, 2000
1,793
0
0
If you think it's a virus, put it on a disk and scan it with an up to date virus scanner. The virus can't infect you unless you execute it.
 

mechBgon

Super Moderator<br>Elite Member
Oct 31, 1999
30,699
1
0
You could also run it through Kaspersky's one-file scanner here and see what the result is. Kaspersky >> AVG.
 

mechBgon

Super Moderator<br>Elite Member
Oct 31, 1999
30,699
1
0
Actually, if you wouldn't mind emailing me a copy of it, send 'er to tmcfadden omnicast net :) I can scan it with Kaspersky and also submit it to McAfee/NAI WebImmune.
 

superfly27

Senior member
Jun 25, 2005
293
0
0
Gee, if it's in the "my documents" folder, it would be simple to use Mcafee freescan right?
 

xtknight

Elite Member
Oct 15, 2004
12,974
0
71
Doesn't sound too good. VirtualAlloc is low-level memory function, potentially dangerous. What was it supposed to do? Why did he run it in the first place? Was he expecting something else?
 

gwarbot

Senior member
Nov 18, 2004
508
0
0
my friend is a complete moron, he shouldn't be allowed to use a computer anyways someone sent it to him and he clicked it for no reason his computer crashed, then he sent it to me and asked what it was. Since im a newb to code, I really didnt have a clue as to what it did.
 

gwarbot

Senior member
Nov 18, 2004
508
0
0
Yeah, I used house call, Avg,Norton,Mcafee. Found nothing. But my friends pc is pretty messed up. I told him to unhook his internet until we get it fixed. So it doesn't spread if it does spread. A few hours after opening it he had cool www search.
 

Kaspian

Golden Member
Aug 30, 2004
1,713
0
0
Originally posted by: gwarbot
my friend is a complete moron, he shouldn't be allowed to use a computer anyways someone sent it to him and he clicked it for no reason his computer crashed, then he sent it to me and asked what it was. Since im a newb to code, I really didnt have a clue as to what it did.


Well, he is not the only one. Some of my friends and co-workers are the same way. It doesnt matter how many times or in what language you tell them to "NOT OPEN ANY ATTATCHMENTS."
 

mechBgon

Super Moderator<br>Elite Member
Oct 31, 1999
30,699
1
0
Originally posted by: gwarbot
Yeah, I used house call, Avg,Norton,Mcafee. Found nothing. But my friends pc is pretty messed up. I told him to unhook his internet until we get it fixed. So it doesn't spread if it does spread. A few hours after opening it he had cool www search.
All the more reason to send me a copy so I can submit it to McAfee and get it on their radar, then.
 

gwarbot

Senior member
Nov 18, 2004
508
0
0
Originally posted by: Kaspian
Originally posted by: gwarbot
my friend is a complete moron, he shouldn't be allowed to use a computer anyways someone sent it to him and he clicked it for no reason his computer crashed, then he sent it to me and asked what it was. Since im a newb to code, I really didnt have a clue as to what it did.


Well, he is not the only one. Some of my friends and co-workers are the same way. It doesnt matter how many times or in what language you tell them to "NOT OPEN ANY ATTATCHMENTS."

No kidding, what they don't realize either is by opening these files they can hurt other people if they spread.
 

gwarbot

Senior member
Nov 18, 2004
508
0
0
Originally posted by: mechBgon
Originally posted by: gwarbot
Yeah, I used house call, Avg,Norton,Mcafee. Found nothing. But my friends pc is pretty messed up. I told him to unhook his internet until we get it fixed. So it doesn't spread if it does spread. A few hours after opening it he had cool www search.
All the more reason to send me a copy so I can submit it to McAfee and get it on their radar, then.

I'll just submitt it myself. I don't think passing around a potentially dangerous file around is a good idea. No offense against you.
 

gwarbot

Senior member
Nov 18, 2004
508
0
0
I thought I'd just update, my friend formatted and his pc is back to normal. I'd say give it a week before, i'll go through another fiasco with him.