Post Reply 
WinRAR Trojan?
Author Message
robertotron
Storm Trooper

Posts: 1,056.7330
Threads: 51
Joined: 1st Apr 2007
Reputation: -6.23995
E-Pigs: 8.2526
Offline
Post: #1
WinRAR Trojan?
just before while i was using WinDirStat to check my HardDrive usage, and while that was going, Norman (my anti-virus) came up with a message that it detected a trojan. It said, "Location: C:/Program Files/WinRAR/default.sfx" and the name of the trojan is "Vundo.gen29". after googling this, i found on Norman's page of recent Virus Definitions, that this was included. how of all things could WinRAR be infected? should i delete the apparent "trojan" or do you think it is a false positive?
18/06/2007 01:40 AM
Find all posts by this user Quote this message in a reply
ZiNgA BuRgA
Smart Alternative

Posts: 17,022.2988
Threads: 1,174
Joined: 19th Jan 2007
Reputation: -1.71391
E-Pigs: 446.1274
Offline
Post: #2
RE: WinRAR Trojan?
The .sfx file is the base for making self-extracting archives.  If you want, you can rename the .sfx file to .exe, and it'll be a (sort-of) working program.
I guess perhaps a virus overwrote the .sfx file? (so whenever you make a self-extracting archive, it's a virus?)

Dunno, but if you don't make self-extracting archives, the file is unnecessary.
18/06/2007 02:24 AM
Visit this user's website Find all posts by this user Quote this message in a reply
robertotron
Storm Trooper

Posts: 1,056.7330
Threads: 51
Joined: 1st Apr 2007
Reputation: -6.23995
E-Pigs: 8.2526
Offline
Post: #3
RE: WinRAR Trojan?
sweet thanks alot Zinga :D
18/06/2007 03:20 AM
Find all posts by this user Quote this message in a reply
Assassinator
...

Posts: 6,646.6190
Threads: 176
Joined: 24th Apr 2007
Reputation: 8.53695
E-Pigs: 140.8363
Offline
Post: #4
RE: WinRAR Trojan?
Meh, i don't even have WinRAR installed.

7zip> Winrar.
18/06/2007 05:02 AM
Find all posts by this user Quote this message in a reply
ZiNgA BuRgA
Smart Alternative

Posts: 17,022.2988
Threads: 1,174
Joined: 19th Jan 2007
Reputation: -1.71391
E-Pigs: 446.1274
Offline
Post: #5
RE: WinRAR Trojan?
WinRAR has uses, for example, extracting out of various SFX archives and dodgey archive formats etc.  WinRAR has a much nicer interface too, like drag-dropping etc.
18/06/2007 05:22 AM
Visit this user's website Find all posts by this user Quote this message in a reply
Assassinator
...

Posts: 6,646.6190
Threads: 176
Joined: 24th Apr 2007
Reputation: 8.53695
E-Pigs: 140.8363
Offline
Post: #6
RE: WinRAR Trojan?
ZiNgA BuRgA Wrote:WinRAR has uses, for example, extracting out of various SFX archives and dodgey archive formats etc.  WinRAR has a much nicer interface too, like drag-dropping etc.

7zip can extract out of SFX archives. And as with dodgey archive formats, it depends on how dodgey.

WinRAR does have a better interface though. BUT unless if u pay, or get a crack, it shows this annoyinh message when u load it, and i really can't be screwed getting a crack when i have to get a new one each time it updates.

7zip compresses strictly better than WinRAR in almost every situation. So I'm not bothering with WinRAR and getting cracks and stuff.
18/06/2007 06:19 AM
Find all posts by this user Quote this message in a reply
amzter
The bird stole my shoe.

Posts: 1,830.3066
Threads: 342
Joined: 3rd May 2007
Reputation: -4.56241
E-Pigs: 54.7074
Offline
Post: #7
RE: WinRAR Trojan?
fudge that virus was coded by a smart mother fudgeer

please mind the language

[Image: 494851774.png]
Search:
18/06/2007 08:35 AM
Visit this user's website Find all posts by this user Quote this message in a reply
ZiNgA BuRgA
Smart Alternative

Posts: 17,022.2988
Threads: 1,174
Joined: 19th Jan 2007
Reputation: -1.71391
E-Pigs: 446.1274
Offline
Post: #8
RE: WinRAR Trojan?
Assassinator Wrote:
ZiNgA BuRgA Wrote:WinRAR has uses, for example, extracting out of various SFX archives and dodgey archive formats etc.  WinRAR has a much nicer interface too, like drag-dropping etc.

7zip can extract out of SFX archives. And as with dodgey archive formats, it depends on how dodgey.
It's limited.  It can extract from some Deflate and LZMA based SFX archives, but ones, such as those based on Microsoft's CAB format (which most InstallShield installers use) can't be extracted by 7zip.

Assassinator Wrote:WinRAR does have a better interface though. BUT unless if u pay, or get a crack, it shows this annoyinh message when u load it, and i really can't be screwed getting a crack when i have to get a new one each time it updates.
Don't update, that's what I do.  I mean, what do you get when you update?

Assassinator Wrote:7zip compresses strictly better than WinRAR in almost every situation. So I'm not bothering with WinRAR and getting cracks and stuff.
Not everyone can extract from 7z archives.  I used to distribute my programs in 7z, but it seems many people have issues extracting from it.  Only more recent versions of WinRAR support it, and they seem to have issues with solid 7z archives.
The other part is that deflate isn't as resource taxing as LZMA.
(This post was last modified: 19/06/2007 02:18 AM by ZiNgA BuRgA.)
19/06/2007 02:18 AM
Visit this user's website Find all posts by this user Quote this message in a reply
Assassinator
...

Posts: 6,646.6190
Threads: 176
Joined: 24th Apr 2007
Reputation: 8.53695
E-Pigs: 140.8363
Offline
Post: #9
RE: WinRAR Trojan?
ZiNgA BuRgA Wrote:Not everyone can extract from 7z archives.  I used to distribute my programs in 7z, but it seems many people have issues extracting from it.  Only more recent versions of WinRAR support it, and they seem to have issues with solid 7z archives.
The other part is that deflate isn't as resource taxing as LZMA.


It's only a matter of time until 7z replaces RAR. Like how RAR replaced ZIP. Change is happening steadily already.
19/06/2007 02:26 AM
Find all posts by this user Quote this message in a reply
ZiNgA BuRgA
Smart Alternative

Posts: 17,022.2988
Threads: 1,174
Joined: 19th Jan 2007
Reputation: -1.71391
E-Pigs: 446.1274
Offline
Post: #10
RE: WinRAR Trojan?
Yeah it probably will.  Took a few years for RAR to "replace" ZIP.  Adaption to 7zip is gonna be slightly more difficult, primarily cause of the use of LZMA (which brings some portable devices to knees) and the fact that it's open source.
19/06/2007 02:58 AM
Visit this user's website Find all posts by this user Quote this message in a reply
Post Reply 


Forum Jump:


User(s) browsing this thread: 2 Guest(s)

 Quick Theme: