Warning for fitsec site and question about FP for free security tool?

Hi forum friends,

Tried to go to -http://fitsec.com/blog/index.php/2011/08/15/tool-release-a-banking-trojan-detection-tool/ just to find out more about this free tool, and I am being blocked by a TrafficLight warning not to go there. Message: The page you are trying to access contains malware.
Sucuri says the page is safe: Web site: http://fitsec.com/blog/index.php/2011/08/15/tool-release-a-banking-trojan-detection-tool/
status: Verified Clean
web trust: Not Blacklisted
Safe here: http://siteinspector.comodo.com/public/reports/306965
It also is flagged by DrWeb as “fitsec.com is in Dr.Web malicious sites list!”;
Suspicious: http://www.urlvoid.com/scan/fitsec.com
-www.fitsec.com/tools/DeBank.exe qualified as Trojan?
Only eSafe and ParetoLogic flag it.
http://www.virustotal.com/url-scan/report.html?id=f890efbf23dad4fbd09064776faaa31d-1315294135
http://www.virustotal.com/file-scan/report.html?id=a71cc9beccec10e55431a466ab8a41328503e83ea0a6aa6a543ce74bce5d3e11-1315301340
See: http://anubis.iseclab.org/?action=result&task_id=1c6caae0e1dd11224657df7f460d24c0d&format=html
So is this a false positive and is this free security tool and code scanner for
Zeus, SpyEye, Carberp, Gozi en Patcher banking Trojans secure and can we use it?

polonus

Pol…i survived ;D

VirusTotal - DeBank.exe - 1/42
http://www.virustotal.com/file-scan/report.html?id=a71cc9beccec10e55431a466ab8a41328503e83ea0a6aa6a543ce74bce5d3e11-1315324553

Tool Release: A Banking Trojan Detection Tool 15, Aug, 2011

As many of our readers know, banking trojans have become extremely widespread over the course of last few years. There are hundreds of thousands, if not millions, of computers on the internet that are infected by these malicious programs.

We created an experimental tool that can detect almost all variants from the TOP 5 of banking trojan families: Zeus, SpyEye, Carberp, Gozi and Patcher, if they are active and running on the infected computer. The tool works by scanning the memory of each running process, looking for telltale signs of these malwares. If any signs are detected, the tool will report the malware name and the affected process name.

The advantage of the tool is that it doesn’t use a conventional signature database, where a detection can be usually avoided by re-packing the malware with a new obfuscation layer. Instead it looks for pieces of code that belong to the actual malware itself.

We’d love to hear any improvement suggestions and comments, feel free to contact us at info(at)fitsec.com

The tool can be downloaded here: hxxp://wxw.fitsec.com/tools/DeBank.exe

By downloading and/or using the tool you agree to the license terms that are described here: hxxp://wxw.fitsec.com/tools/license.txt

Hi Pondus,

Does the tool have a valid digital signature?
Well, at Jotti’s 3 out of 20 scanners reported malware:
http://virusscan.jotti.org/en/scanresult/2c45c3eba074691a0b5c4787cc9b35c182ed509e/85f66c05a80653981ba97e11c82220991ff42931
1 of them found here: http://www.malware-control.com/statics-pages/539bc6962479b7bed83ee55e0bf7e9ab.php
Also see: http://www.threatexpert.com/report.aspx?md5=539bc6962479b7bed83ee55e0bf7e9ab
6 vendors detected according to:
Xandora scan: http://www.xandora.net/xangui/malware/view/539bc6962479b7bed83ee55e0bf7e9ab
(Suspicious)-DNAScan
WS.Reputation.1
Win32.GenHeur.RP.Xcw
UnclassifiedMalware
Gen.Trojan.Heur!IK

Registry Keyes changed: software_Microsoft_Windows_CurrentVersion_Group_Policy_State_Machine_Extension-List
software_Microsoft_Windows_CurrentVersion_Group_Policy_State_Machine_Extension-List
software_Microsoft_Windows_CurrentVersion_Group_Policy_State_S-1-5-21-790525478-1390067357-1417001333-500_Extension-List
software_Microsoft_Windows_CurrentVersion_Group_Policy_State_S-1-5-21-790525478-1390067357-1417001333-500_Extension-List
software_Microsoft_Windows_NT_CurrentVersion_AeDebug

disk checking performed,

polonus

Well, at Jotti's 3 out of 20 scanners reported malware:
well it is actually 2 as Emsisioft is using Ikarus AV engine......and the scan date say 2011-08-21

here is the new
http://virusscan.jotti.org/en/scanresult/fdef78aeaad3f24d9b9fb92b60ecec1d69d23e72

Hi Pondus,

From what we have established so far in this thread now we can safely say that the earlier detections were just heuristical flags because of the packers used, e.g. Packers (Drweb): PESTUB, VMPROTECT. So the tool should be OK. VT community verdict is - goodware -. Still in experimental stage, this free tool can be used occasionally when one has certain suspicion about a banking trojan infection and wants to to scan the memory space of every running process looking for banking trojans’ pieces of code. Another free tool to add to the toolchest of the qualified malware removers, like we have here on our forum, like: essexboy, oldman, argus, etc.

polonus