Jump to content
Jahn

Trojan.Dropper/Multi-MBAD F/P?

Recommended Posts

C:\windows\mota113.exe

6/31 at VT, mostly suspicious.

File sent to nicks.

Thanks

SAS 4.1.1040 Defs 3458/1449

Share this post


Link to post
Share on other sites

I am getting the same thing, turned up suddenly as I have SAS run every night and this started popping up a day or two ago. I ran 5 other scanners none of which see it.

Share this post


Link to post
Share on other sites
What address did you send the file to? Did you send to samples AT superantispyware.com?

OK, I see you received it now. :)

Share this post


Link to post
Share on other sites

My scan found two entries today. Besides MOTA113.EXE it reported DTSX264.EXE. As far as I know that file is part of the DTS X264 video codec?

Trojan.Dropper/Multi-MBAD

C:\WINDOWS\MOTA113.EXE

C:\WINDOWS\SYSTEM32\DTSX264.EXE

The samples will be mailed for evaluation after completing this post.

Nightcap

Share this post


Link to post
Share on other sites
My scan found two entries today. Besides MOTA113.EXE it reported DTSX264.EXE. As far as I know that file is part of the DTS X264 video codec?

Trojan.Dropper/Multi-MBAD

C:\WINDOWS\MOTA113.EXE

C:\WINDOWS\SYSTEM32\DTSX264.EXE

The samples will be mailed for evaluation after completing this post.

Nightcap

Thank you!

Share this post


Link to post
Share on other sites
Guest
This topic is now closed to further replies.

×