Seite 1 von 1

Trojan-Banker.Win32.Banbra in kWab.dll by GridinSoft TK

Verfasst: Fr 1. Jan 2010, 17:09
von WFBOX
Need help this is reported when I run GridinSoft Trojan Killer v.2.0.5.9
This happen even reinstalled
(I'm reporting this to GridinSoft as well to check for mistake).
Any help is appreciated

+++++++++++++++++++++++++++++++++++++++++++

GridinSoft Trojan Killer v.2.0.5.9
Report file date: 01/01/2010 16.53.04

Scanning for 802205 virus strains and unwanted programs.

Windows version: Microsoft Windows XP (version 5.1)

Starting the file scan:

Files collected
Scanning...
----- C:\Program Files\MyPhoneExplorer\IconLib.dll ---- General
Broken.Executable (Broken PE file - Section 3 starts beyond the end of file (Offset@ 15C000, Total filesize 1425408)
ProdVer: 1.00
FileVer: 1.00
Name : WinXP
Company:
MD5: 9A5A9B73284CA2CD745CC646DBF0A400:1425408
EP: 00
SEC:
.text:6BDEE8F1633F6AC0A30A8291F1AADC29:4096
.data:620F0B67A91F7F74151BC5BE745B7110:4096
.rsrc:6F60A68042DD499B5CD3003A04E6328C:1413120
.reloc:00000000000000000000000000000000:4096


----- C:\Program Files\MyPhoneExplorer\DLL\kWab.dll ---- General
Trojan-Banker.Win32.Banbra
ProdVer: 1, 2, 0, 1
FileVer: 1, 2, 0, 1
Name : Michele Locati's kWab
Company:
MD5: 206341727B45160BFFC1E17CAD07424A:29184
EP: 80 7C 24 08 01 0F 85 7D 01 00 00 60 BE 00 E0 00 10 8D BE 00 30 FF FF 57 83 CD FF EB 0D 90 90 90 8A 06 46 88 07 47 01 DB 75 07 8B 1E 83 EE FC 11 DB 72 ED B8 01 00 00 00 01 DB 75 07 8B 1E 83 EE FC
SEC:
UPX0:00000000000000000000000000000000:0
UPX1:37C17621CC86993793AC369754E663F5:23040
.rsrc:5D9BC79C2297F1E0A46A94022E279BF6:5120


Scan completed.

Scan result: 2 detected items
Scan completed in: Scan completed in 4 seconds
Files were scanned: 15

Verfasst: Fr 1. Jan 2010, 20:16
von FJ
The file kwab.dll is used for sync with Outlook-Express. Its integrated since 5 years without any change of the file - its also used from some other softwares.

The file IconLib.ddl is a container for graphics and it contains no code. I wrote this file myself

You see - both detects are false-alerts