infected Win32:Trojan-gen by Babylon 6 install file.

hello all :slight_smile:

FYI:
I downloaded Babylon 6 translator+keygen software and installed on XP por with Avast! 7.7.844 updated. first i canceled for Repare/Delete.
Rundll32 and Rundll is corrupted and no access to any apps.
In safe mode\ unistall the avast! AV and then installed it again and checked in startup mode.
now i don’t have any problem.

Win32:Trojan-gen. {Other}
Virus/Worm
0631-2, 08/02/2006

C:\DOCUME~1\admin\LOCALS~1\Temp\Rar$EX06.172\Babylon6_setup_eng_eng_britannica.exe

BR/hs366

Key-generators have in the past been known to include some surprises.

You could also check the offending/suspect file at: VirusTotal - Multi engine on-line virus scanner
Or Jotti - Multi engine on-line virus scanner if any other scanners here detect them it is less likely to be a false positive. You can’t do this with the file in the chest, you will need to move it out.

Let us know the results.

Result from http://www.virustotal.com

STATUS: FINISHEDComplete scanning result of “Babylon6_setup_eng_eng_britannica”, received in VirusTotal at 08.05.2006, 07:23:43 (CET).

Antivirus Version Update Result
AntiVir 6.35.1.0 08.04.2006 TR/Dldr.Slime.B.2
Authentium 4.93.8 08.04.2006 W32/Slimerdownloader.A - Packed
Avast 4.7.844.0 08.04.2006 Win32:Trojan-gen. {Other}
AVG 386 08.04.2006 Downloader.Small.20.AY
BitDefender 7.2 08.05.2006 Trojan.Downloader.Slime.B
CAT-QuickHeal 8.00 08.04.2006 no virus found
ClamAV devel-20060426 08.04.2006 no virus found
DrWeb 4.33 08.04.2006 Trojan.Slime
eTrust-InoculateIT 23.72.87 08.04.2006 Win32/DlSlime.A!Trojan
eTrust-Vet 12.6.2324 08.04.2006 Win32/DlSlime.A
Ewido 4.0 08.04.2006 Downloader.Slime.b
Fortinet 2.77.0.0 08.05.2006 W32/Slime.B!tr
F-Prot 3.16f 08.04.2006 W32/Slimerdownloader.A - Packed
F-Prot4 4.2.1.29 08.04.2006 Possibly a new unknown PE_Virus!Maximus
Ikarus 0.2.65.0 08.04.2006 Trojan-Downloader.Win32.Slime.B
Kaspersky 4.0.2.24 08.05.2006 Trojan-Downloader.Win32.Slime.b
McAfee 4822 08.04.2006 Downloader-EW
Microsoft 1.1508 08.04.2006 TrojanDownloader:Win32/Slime.B
NOD32v2 1.1693 08.05.2006 Win32/TrojanDownloader.Slime.B
Norman 5.90.23 08.04.2006 W32/DLoader.XJY
Panda 9.0.0.4 08.04.2006 Trj/Slime.A
Sophos 4.08.0 08.05.2006 W32/Slime-B
Symantec 8.0 08.05.2006 W32.Slime
TheHacker 5.9.8.186 08.04.2006 no virus found
UNA 1.83 08.04.2006 no virus found
VBA32 3.11.0 08.04.2006 Trojan-Downloader.Win32.Slime.b
VirusBuster 4.3.7:9 08.04.2006 no virus found

Aditional Information
File size: 10381914 bytes
MD5: f82210adfbb97ac9ea21b5e5af21b884
SHA1: ff2faca66dec7c79e6abee477f8dd8d25001b61b
packers: TeLock
packers: ZIP, TeLock

So it is confirmed that you got a little trojan surprise in your key generator when only 5 out of 27 AV scans failed to detect this malware (slime). Trojan downloaders attempt to download more of the same and other malware, so I would say you should remove this program completely.

So if you managed to get it installed, your system could be compromised, especially if you don’t have a firewall that checks unauthorised internet access (not so with XP’s firewall). Any malware that manages to get past your defences will have free reign to connect to the internet to either download more of the same, pass your personal data (user names, passwords, keylogger retrieved data, etc.) or open a backdoor to your computer, so outbound protection is essential.

Hi hs366,

Here is the manual removal instruction for this slime:

http://de.trendmicro-europe.com/consumer/vinfo/encyclopedia.php?LYstr=VMAINDATA&vNav=2&VName=TROJ_SLIME.B

polonus

Thank you so much for help :smiley:

Glad we could help, a belated welcome to the forums.