The file "KeyFinder.exe", which is a component file inside
keyfinder.zip, is being flagged as:
W32.W.Kolab (detected by AegisLab)
Only Aegislab is giving a positive detection on that file.
https://www.virustotal.com/en/file/02e402436a42814cf7009d493332d694f7f25529ccd9
6150ef4011712dd2b090/analysis/1457876601/
A .dll and .ocx file that is also part of this package comes back with
no detections.
The program in question is known as the SterJo Key Finder v.1.8
http://www.sterjosoft.com/key-finder.html
This was the portable version I was submitting to VT. There are no
comments or votes on VT regarding these files.
There is almost nothing on the net regarding "Kolab" (in relation to
malware) other than this:
https://www.f-secure.com/v-descs/net-worm_w32_kolab_qa.shtml
Aegislab.com has a file-submission interface, which works but does not
follow through and give any indication that it's performing an analysis
or will display any scan results.
Comments?
--- NewsGate v1.0 gamma 2
* Origin: News Gate @ Net396 -Huntsville, AL - USA (1:396/4)
|