Win32:SkiMorph [Cryp]

HI all

I try install new English learning software from CD and my Avast find this Worm. I buy this software from trusted company and is it very strange :frowning: Also I can’t find anything info about this worm. Maybe this is mistake and don’t need to be afraid? :slight_smile:

Avast find Worm in flashex.exe file and i scan this file with http://www.virustotal.com/. Result: 2/35 (5.71%). Here is log:

Antivirus Version Last Update Result
AhnLab-V3 2008.10.10.1 2008.10.10 -
AntiVir 7.8.1.34 2008.10.11 -
Authentium 5.1.0.4 2008.10.11 -
Avast 4.8.1248.0 2008.10.11 Win32:SkiMorph
AVG 8.0.0.161 2008.10.11 -
BitDefender 7.2 2008.10.12 -
CAT-QuickHeal 9.50 2008.10.11 -
ClamAV 0.93.1 2008.10.12 -
DrWeb 4.44.0.09170 2008.10.12 -
eSafe 7.0.17.0 2008.10.12 -
eTrust-Vet 31.6.6141 2008.10.10 -
Ewido 4.0 2008.10.12 -
F-Prot 4.4.4.56 2008.10.11 -
Fortinet 3.113.0.0 2008.10.12 -
GData 19 2008.10.12 Win32:SkiMorph
Ikarus T3.1.1.34.0 2008.10.12 -
K7AntiVirus 7.10.491 2008.10.11 -
Kaspersky 7.0.0.125 2008.10.12 -
McAfee 5403 2008.10.11 -
Microsoft 1.4005 2008.10.12 -
NOD32 3515 2008.10.11 -
Norman 5.80.02 2008.10.10 -
Panda 9.0.0.4 2008.10.12 -
PCTools 4.4.2.0 2008.10.12 -
Prevx1 V2 2008.10.12 -
Rising 20.65.42.00 2008.10.10 -
SecureWeb-Gateway 6.7.6 2008.10.11 -
Sophos 4.34.0 2008.10.12 -
Sunbelt 3.1.1716.1 2008.10.12 -
Symantec 10 2008.10.12 -
TheHacker 6.3.1.0.108 2008.10.11 -
TrendMicro 8.700.0.1004 2008.10.10 -
VBA32 3.12.8.6 2008.10.12 -
ViRobot 2008.10.10.1416 2008.10.10 -
VirusBuster 4.5.11.0 2008.10.11 -

Thanks for comments and help

It certainly looks like an false positive, as GData uses two scanners one being avast.

If it is indeed a false positive (and it seems that way), see http://forum.avast.com/index.php?topic=34950.msg293451#msg293451, how to report it to avast! and what to do to exclude them until the problem is corrected.

Thanks for help :wink:

No problem, glad I could help.

Welcome to the forums.