RAZOR.EXE from Tiberian Sun game

E

E.F.

Kaspersky On-Line scanner identified RAZOR.EXE as a trojan dropper (details
below).

Could it be a false positive? This seems to be a fairly old file and this
infection is reported as quite new.

BTW, SpyBot does not detect it.

----------------------------------------------------------------------------
---
KASPERSKY ON-LINE SCANNER REPORT
Wednesday, October 19, 2005 22:52:59
Operating System: Microsoft Windows 98 SE
Kaspersky On-line Scanner version: 5.0.67.0
Kaspersky Anti-Virus database last update: 20/10/2005
Kaspersky Anti-Virus database records: 145762
----------------------------------------------------------------------------
---

Scan Settings:
Scan using the following antivirus database: standard
Scan Archives: true
Scan Mail Bases: true

Scan Target - Critical Areas:
C:\WINDOWS
c:\windows\TEMP\

Scan Statistics:
Total number of scanned objects: 47112
Number of viruses found: 2
Number of infected objects: 2
Number of suspicious objects: 0
Duration of the scan process: 2344 sec

Infected Object Name - Virus Name
C:\WINDOWS\Application
Data\Mozilla\Profiles\default\obpev9je.slt\Cache\DCC6EDB7d01 Infected:
Trojan-Spy.HTML.Bayfraud.cy
C:\WINDOWS\Desktop\Tiberian Sun\RAZOR.EXE Infected:
Trojan-Dropper.Win32.Small.ux

Scan process completed.
---------------------------------------------------------------
 
I

Ian Kenefick

Kaspersky On-Line scanner identified RAZOR.EXE as a trojan dropper (details
below).

Could it be a false positive? This seems to be a fairly old file and this
infection is reported as quite new.

send the detected file to (e-mail address removed) for analysis. It's
pretty pointless asking us since prognosis by file name alone is
unreliable to say the least.
 
A

Adam Piggott

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

E.F. said:
Kaspersky On-Line scanner identified RAZOR.EXE as a trojan dropper (details
below).

Could it be a false positive? This seems to be a fairly old file and this
infection is reported as quite new.

I've got Tiberian Sun and haven't got a RAZOR.EXE. If you submit it to
http://www.virustotal.com it'll be scanned by multiple anti-virus programs
to give you a good idea if it's malign or not.

HTH
- --
Adam Piggott, Proprietor, Proactive Services (Computing).
http://www.proactiveservices.co.uk/

Please replace dot invalid with dot uk to email me.
Apply personally for PGP public key.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.2 (MingW32)

iD8DBQFDV0oZ7uRVdtPsXDkRAnCpAKCDh2bC0fo9GOGWN4XK5ORKSdfr5wCcDcuc
E6gBW4Yu41zew5OSVJuU04w=
=WevN
-----END PGP SIGNATURE-----
 
I

Ian Kenefick

Kaspersky On-Line scanner identified RAZOR.EXE as a trojan dropper (details
below).

In addition to my initial post. I googled the Razor.exe and tiberian
sun in Google. The results are suspect.

http://www.google.ie/search?hl=en&h...S:official_s&q=razor.exe+tiberian+sun&spell=1

if wraped...

http://tinyurl.com/9ju7x

Many share the same faith as you and all found infections in razor.exe

Moving on.. Multi AV.exe has a module with kaspersky antivirus. This
detects the suspected infection. You can get this Multi AV tool at
www.ik-cs.com/got-a-virus.htm
 
D

David H. Lipman

From: "E.F." <[email protected]>

| Kaspersky On-Line scanner identified RAZOR.EXE as a trojan dropper (details
| below).
|
| Could it be a false positive? This seems to be a fairly old file and this
| infection is reported as quite new.
|
| BTW, SpyBot does not detect it.
|
| ----------------------------------------------------------------------------
| ---
| KASPERSKY ON-LINE SCANNER REPORT
| Wednesday, October 19, 2005 22:52:59
| Operating System: Microsoft Windows 98 SE
| Kaspersky On-line Scanner version: 5.0.67.0
| Kaspersky Anti-Virus database last update: 20/10/2005
| Kaspersky Anti-Virus database records: 145762
| ----------------------------------------------------------------------------
| ---
|
| Scan Settings:
| Scan using the following antivirus database: standard
| Scan Archives: true
| Scan Mail Bases: true
|
| Scan Target - Critical Areas:
| C:\WINDOWS
| c:\windows\TEMP\
|
| Scan Statistics:
| Total number of scanned objects: 47112
| Number of viruses found: 2
| Number of infected objects: 2
| Number of suspicious objects: 0
| Duration of the scan process: 2344 sec
|
| Infected Object Name - Virus Name
| C:\WINDOWS\Application
| Data\Mozilla\Profiles\default\obpev9je.slt\Cache\DCC6EDB7d01 Infected:
| Trojan-Spy.HTML.Bayfraud.cy
| C:\WINDOWS\Desktop\Tiberian Sun\RAZOR.EXE Infected:
| Trojan-Dropper.Win32.Small.ux
|
| Scan process completed.
| ---------------------------------------------------------------
|


Download MULTI_AV.EXE from the URL --
http://www.ik-cs.com/programs/virtools/Multi_AV.exe

It is a self-extracting ZIP file that contains the Kixtart Script Interpreter {
http://kixtart.org Kixtart is CareWare } 4 batch files, 6 Kixtart scripts, one Link
(.LNK) file, a PDF instruction file and two utilities; UNZIP.EXE and WGET.EXE. It will
simplify the process of using; Sophos, Trend, Kasperski and McAfee Anti Virus Command
Line Scanners to remove viruses, Trojans and various other malware.

C:\AV-CLS\StartMenu.BAT -- { or Double-click on 'Start Menu' in C:\AV-CLS}
This will bring up the initial menu of choices and should be executed in Normal Mode.
This way all the components can be downloaded from each AV vendor's web site.
The choices are; Sophos, Trend, McAfee, Kaspersky, Exit this menu and Reboot the PC.

You can choose to go to each menu item and just download the needed files or you can
download the files and perform a scan in Normal Mode. Once you have downloaded the files
needed for each scanner you want to use, you should reboot the PC into Safe Mode [F8 key
during boot] and re-run the menu again and choose which scanner you want to run in Safe
Mode. It is suggested to run the scanners in both Safe Mode and Normal Mode.

When the menu is displayed hitting 'H' or 'h' will bring up a more comprehensive PDF help
file.

To use this utility, perform the following...
Execute; Multi_AV.exe { Note: You must use the default folder C:\AV-CLS }
Choose; Unzip
Choose; Close

Execute; C:\AV-CLS\StartMenu.BAT
{ or Double-click on 'Start Menu' in C:\AV-CLS }

NOTE: You may have to disable your software FireWall or allow WGET.EXE to go through your
FireWall to allow it to download the needed AV vendor related files.

* * * Please report back your results * * *
 
S

Sue Perficial

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1



I've got Tiberian Sun and haven't got a RAZOR.EXE. If you submit it to
http://www.virustotal.com it'll be scanned by multiple anti-virus programs
to give you a good idea if it's malign or not.

Weren't RAZOR an old piracy/cracking group? Perhaps it's a pirate
version of Tiberian Sun?
 
E

Eugene F.

Run the file (renamed to RAZOR._EXE) through VirusTotal.

More than half of the scanners found a problem. NOD32, eTrust and
McAfee were among those that did not.
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top