1 (edited by Schokomuesli 2011-07-02 23:18:39)

Topic: Trojan found in crapnet.exe

Hi there,

After compiling TeeWorlds 0.6.0 my Antivirus Application immediately warned me that the file "crapnet.exe" contains malware with the name "TR/ATRAPS.Gen".

I compiled the new version a million times, but since today something is going wrong.

Well, I uploaded the executable to the Support of the AV App because I think it's a false positive.
Isn't it?


Antivirus results

AhnLab-V3 - 2011.07.03.00 - 2011.07.02 - -

AntiVir - 7.11.10.199 - 2011.07.02 - TR/ATRAPS.Gen

Antiy-AVL - 2.0.3.7 - 2011.07.02 - -

Avast - 4.8.1351.0 - 2011.07.02 - -

Avast5 - 5.0.677.0 - 2011.07.02 - -

AVG - 10.0.0.1190 - 2011.07.02 - -

BitDefender - 7.2 - 2011.07.02 - -

CAT-QuickHeal - 11.00 - 2011.07.02 - -

ClamAV - 0.97.0.0 - 2011.07.02 - -

Commtouch - 5.3.2.6 - 2011.07.02 - -

Comodo - 9254 - 2011.07.02 - -

DrWeb - 5.0.2.03300 - 2011.07.02 - -

eSafe - 7.0.17.0 - 2011.06.29 - -

eTrust-Vet - 36.1.8421 - 2011.07.01 - -

F-Prot - 4.6.2.117 - 2011.07.02 - -

F-Secure - 9.0.16440.0 - 2011.07.02 - -

Fortinet - 4.2.257.0 - 2011.07.02 - -

GData - 22 - 2011.07.02 - -

Ikarus - T3.1.1.104.0 - 2011.07.02 - -

Jiangmin - 13.0.900 - 2011.07.02 - -

K7AntiVirus - 9.107.4863 - 2011.07.01 - -

Kaspersky - 9.0.0.837 - 2011.07.02 - -

McAfee - 5.400.0.1158 - 2011.07.02 - -

McAfee-GW-Edition - 2010.1D - 2011.07.02 - -

Microsoft - 1.7000 - 2011.07.02 - -

NOD32 - 6260 - 2011.07.02 - -

Norman - 6.07.10 - 2011.07.02 - -

nProtect - 2011-07-02.01 - 2011.07.02 - -

Panda - 10.0.3.5 - 2011.07.02 - -

PCTools - 8.0.0.5 - 2011.07.01 - -

Prevx - 3.0 - 2011.07.02 - -

Rising - 23.64.04.03 - 2011.07.01 - -

Sophos - 4.67.0 - 2011.07.02 - -

SUPERAntiSpyware - 4.40.0.1006 - 2011.07.02 - -

Symantec - 20111.1.0.186 - 2011.07.02 - -

TheHacker - 6.7.0.1.246 - 2011.07.01 - -

TrendMicro - 9.200.0.1012 - 2011.07.02 - -

TrendMicro-HouseCall - 9.200.0.1012 - 2011.07.02 - -

VBA32 - 3.12.16.4 - 2011.07.01 - -

VIPRE - 9752 - 2011.07.02 - -

ViRobot - 2011.7.2.4546 - 2011.07.02 - -

VirusBuster - 14.0.106.1 - 2011.07.02 - -


File info:

MD5: 005ce9114294a3e6f41e3b18aa824784
SHA1: bd5db3de2a1b63c4a942d72c4fefdc8418f2153c
SHA256: b9aeb19505643f3572c594b740398fc9208771b3671c818debfe095d5788343a

File size: 255488 bytes

Scan date: 2011-07-02 21:02:31 (UTC)

Regards,
Schokomuesli

2

Re: Trojan found in crapnet.exe

No, crapnet, as its name says, is a malware that makes your inet becoming crap. It's been coded precisely to trap people like you double clicking on random binary files.

Not Luck, Just Magic.

3

Re: Trojan found in crapnet.exe

Dune wrote:

No, crapnet, as its name says, is a malware that makes your inet becoming crap. It's been coded precisely to trap people like you double clicking on random binary files.

Omo you're not funny any more..., you're banal. Crapnet is used for tests, TeeWorlds sources are clean, you probably get a virus alert only in avira because of an update... (daa), nothing to be worried of, the version of avast 5.x in your post is 20x times better than avira and it reports clean (so does all the other av software) you should disable your protection while compiling or simply get Avast, the free edition, you should check it out, nothing to be worried of, Slayer had that alarm too smile.

4

Re: Trojan found in crapnet.exe

Dune wrote:

No, crapnet, as its name says, is a malware that makes your inet becoming crap. It's been coded precisely to trap people like you double clicking on random binary files.

tongue

Hip-Hop_BLOND wrote:

Slayer had that alarm too

Tbx for opening this topic Schokomuesli big_smile I'd planned to reinstall my system in the near future^^

5

Re: Trojan found in crapnet.exe

The signature for that trojan is coninciding with some part of your crapnet.exe. No idea if they're gonna change their signature but you could just add crapnet as exception in AntiVir. There's also methods of detecting which part of the file matches the signature.. just in case you have nothing better to do. smile