View Single Post
  #10  
Old 29-04-2018, 08:40
KaktoR's Avatar
KaktoR KaktoR is offline
Lame User
 
Join Date: Jan 2012
Location: From outer space
Posts: 4,689
Thanks: 1,106
Thanked 7,338 Times in 2,839 Posts
KaktoR is on a distinguished road
Most probably cat.exe (i am 99% sure this is the file).

I don't even know for what this file is exactly. It was a part of CIUv2.0.4.0

Edit:
Like i said. But i can tell you that's just a false positive at all. I don't think that Yener or BAMsE would ever include a virus inside the script.

Edit 2:
Code:
https://www.virustotal.com/de/file/93914d62c9ff89f34ecd12205c6369e836f3962262d956351a38491714129b92/analysis/1525017027/#item-detail
According to PEiD:
Code:
https://www.rosseaux.net/page40_BeRoEXEPacker.html
http://www.pouet.net/prod.php?which=59239
Btw the same file is also included in Gupta's latest CIUv2.0.5g. Maybe ask him what this file does actually.
Attached Images
File Type: png Unbenannt.png (6.0 KB, 63 views)
__________________
Haters gonna hate

Last edited by KaktoR; 29-04-2018 at 08:57.
Reply With Quote