Log in

View Full Version : Disinfecting a program.


Greyhound2004
September 20th, 2008, 08:02
Kaspersky tells me that a Prog that I downloaded is infected with
Win32.Bagle.aag it also tells me that it can't dissinfect and gives me the option to delete the file.

Is it possible or feasable to manually dissinfect this program or at least render its payload harmless?

I'm guessing that as a starter I could run it within a VM container and have a look at the code.

Has anybody here looked at this Trojan?

Regards,

Greyhound2004
September 20th, 2008, 09:12
I did open the file within a VM container and got a dialogue box "Themida has detected a debugger running on your system please unload and restart program." I have read the stuff about Themida and VM ware aware Viri so have deleted this file.

evaluator
September 20th, 2008, 16:36
you did good
i think, if it was protected with Themida, then it was itself malware, not some infected program.

deroko
September 21st, 2008, 07:52
well AVs can't fight themida very well, most of the times you will receive alert about "probably new w32 | Win32.Themida" as themida is quite chalanging for our "great" AV "experts". a few years ago I remember submitting some aspacked - hello world.exe to virtustotal.com and it was detected as some worm, because "smart" AV used aspack signature to identify virus, I think it was recognized as mydoom or some similar worm...