Post a reply

Before posting, please read how to report bug or request support effectively.

Bug reports without an attached log file are usually useless.

Options
Add an Attachment

If you do not want to add an Attachment to your Post, please leave the Fields blank.

(maximum 10 MB; please compress large files; only common media, archive, text and programming file formats are allowed)

Options

Topic review

charles.l.seljos@nasa.gov

Re: trojan "FakeAV.VY" in WinSCP 4.1.8 installer?

The Virus Total website no longer detects this as an infected file; one anti-virus agent on that site did detect it as having a trojan on 2008-12-23. eEye's Blink tool also detected it as having a trojan, but as of 2008-12-26, it does not. False positive.
cs

ClamAV report

ClamAV reports:

/media/Lexar/CONFIG/S-1-5-21-1482476501-1644491937-682003330-1013/Cfg.exe:
Trojan.Inject-1865 FOUND

Contents of autorun.inf:

[autorun]
open=CONFIG\S-1-5-21-1482476501-1644491937-682003330-1013\Cfg.exe
icon=%SystemRoot%\system32\SHELL32.dll,4
action=Open folder to view files
shell\open=Open
shell\open\command=CONFIG\S-1-5-21-1482476501-1644491937-682003330-1013\Cfg.
exe
shell\open\default=1