Pdox runtime 9 trojan (not)
- From: "Jon" <nono@*.com>
- Date: Mon, 16 Jul 2007 08:33:56 +0200
Some of my customers have lately been reporting to me that a file I've been
distributing with a paradox program is infected with a trojan.
Obviously I tested their setup and it turns out it is a file in the paradox
9 runtime that is flagged as a trojan. The file 'AXDISTEX.EXE' is reported
as being infected with TROJ_CIH.DAM by the latest definitions in Trend Micro
Office Scan Version7. As the file was last changed 11/2-1998 and not found
by any other the other 3 antivirus programs I tested with I considered this
a 100% false positive and submitted it to the Trend Micro lab to have it
cleared in their next update.
However the exe file does not execute properly (dunno if it requires params
to work or it really is broken) so the response from Trend Micro after
having analyzed it is that they consider it not normal and quote "acting
suspicious". From the fileinfo I can see that the original borland filename
is regarc.exe suggesting that it's used to do registry functions but since
it won't run I haven't been able to monitor what it is doing with
file/regmon.
Has anyone else run into this or a similar situation and can suggest what to
do? I dont have access to a newer version of the runtime so if anyone could
check if this file is in the newer versions as well I'd appreciate it..
.
- Follow-Ups:
- Re: Pdox runtime 9 trojan (not)
- From: Egbert Babst
- Re: Pdox runtime 9 trojan (not)
- Prev by Date: Re: Pdox Dos
- Next by Date: Re: Vista is running slowly on multiuser app (Pdox9 RT)
- Previous by thread: Re: Pdox Dos
- Next by thread: Re: Pdox runtime 9 trojan (not)
- Index(es):