XRumer Demo with Trojan?

SebastianJu

Power Member
Joined
Mar 27, 2008
Messages
679
Reaction score
130
I downloaded the XRumer Demo and got a warning from Antivir that the xrumer.exe is a trojan.

13 of 41 scanner of Virustotal.com says its a Trojan too.

Code:
http://www.virustotal.com/de/analisis/742285666b72abcc3c285b1a1553aeb7959c1e140a55534979e33dfc93b31842-1262704749

So what is it? A false positive because of what? Or a good hidden Trojan that only some scanner finds?

Is it the same with the xrumer.exe of the normal version?
 
But its from the official site of Xrumer... Cant believe they would risk their business by doing that...

Edit: On the other hand... Botmaster would have a new meaning then... :)
 
Russians... On the other hand, it says that the trojan is a downloader, I don't know how they update their program.
 
You just gotta trust botmaster. You don't have much of a choice. Maybe it's listed their because it's a spam tool according to some.
 
But a spamtool wouldnt have something to do with Trojan-Downloader... And it would probably be hard to have suddenly a xrumer.exe on the own pc when you didnt bought it... So no need to implement this thing into virusscanners...
Or if it would be implemented, for example useful for businesses that want to check the activity of their employees, it wouldnt be recogniced as a Trojan-Downloader but instead of a not suitable program...
 
it's not a trojan. botmaster is trusted by thousands of users you have nothing to worry about he would not want to ruin his reputation.
 
the other possibility is you have several trojans on your PC itself which are infecting downloads. Meaning you download X, when it comes onto your pc, something attaches itself or does something - just a thought.
 
the other possibility is you have several trojans on your PC itself which are infecting downloads. Meaning you download X, when it comes onto your pc, something attaches itself or does something - just a thought.

Could be easily found out when another person downloads. But I dont think thats the case because: The file I scanned was scanned before multiple times in virustotal. So the exe cant be changed. And I downloaded a lot things the last days and such thing didnt happen to another download...
 
Why download the demo anyways? All you can do is make 1 post to show that the program works. You're serious about the trojan? :D:rolleyes:
 
Didnt know the demo is so limited. I wanted to test Hrefer but it wasnt included in the demo as far as I see...
In the filecheck of virustotal checked in november last year only 9 scanner found a virus. Now 13. So im wondering whats the thing there... Im sure there are files with false positives but 13 false positives? Its not a crack or something. There I would see that its sometimes possible to use code that can be seen as virus but a legit demo?
 
Didnt know the demo is so limited. I wanted to test Hrefer but it wasnt included in the demo as far as I see...
In the filecheck of virustotal checked in november last year only 9 scanner found a virus. Now 13. So im wondering whats the thing there... Im sure there are files with false positives but 13 false positives? Its not a crack or something. There I would see that its sometimes possible to use code that can be seen as virus but a legit demo?

I've responded to this a long time ago. With this kind of mindset you're not ready for xRumer.

What I was saying is that I find it quite stupid of someone who purchased xRumer through the legal way, downloaded it off Botmaster's site etc. I believe in the help it even says that some AVs could treat it like some kind of trojan, so turn your AV off.. Botmasters forum same thing; turn your AV off. There are hundreds to thousands of people who have downloaded the same files that you did, no one ever reporting an actual backdoor/keylogger whatsoever, even though there $80-ish AVs could have shown red alerts with a $500 soft that spams and is very strongly secured.
 
Ok, I see your point. But still wondering what makes a legit software exe seen as a trojan. What kind of code has to be implemented that avs alerts.

But I doubt this can be answered here. So never mind...
 
Ok, I see your point. But still wondering what makes a legit software exe seen as a trojan. What kind of code has to be implemented that avs alerts.

But I doubt this can be answered here. So never mind...

FYI xRumer is not really classified as a 'legit software' ;)
 
Those who think that botmaster is to be trusted...think again. I am pretty sure that even the full version (the exe archive) comes packed with an ill famed virus that can very well steal your credit card info and so on. If the warning given by antivirus is something like 'spam tool' then that's understandable but anything else, I won't take that lightly. So guys, just because u have spent $540 on that piece of software don't think that "botmaster" will not give u some free bots as a gift. There is a reason that he calls himself by that name. And then thr is a reason that he is banned on BHW.
 
Those who think that botmaster is to be trusted...think again. I am pretty sure that even the full version (the exe archive) comes packed with an ill famed virus that can very well steal your credit card info and so on. If the warning given by antivirus is something like 'spam tool' then that's understandable but anything else, I won't take that lightly. So guys, just because u have spent $540 on that piece of software don't think that "botmaster" will not give u some free bots as a gift. There is a reason that he calls himself by that name. And then thr is a reason that he is banned on BHW.
botmaster is legit, end of story

if he wanted to spread a bot that stored and sent him your cc info he wouldn't put it in $540 software that's mainly ran on dedicated servers
 
Although, the idea is fairly smart. Produce software that would be ran on powerful dedi servers, spread it (and earn money at the same time) and have thousands of bots with great connections on hosts that probably don't care much about spam. It would be a powerful botnet.

(Note: I'm not saying Xrumer has any of this, just saying that the concept isn't absurd)
 
I don't think its a trojan.If you really got that from their official site then it is well enough to work with.
 
AVAST Antivirus reports the Xrumer demo as trojan too.

i got the demo at SEnuke http://www.botmasternet.com

let me know if this is the legit site of Xrumer..
 
bluegarden that is the legit site. Also xrumer do not have harmful trogans, those are false positives. Botmaster would not ruin his business reputation.
 
There are times when legitimate programs get attacked because they innocently trigger one of the AI's that anti-virus programs use. I know programs that create a variety of serial numbers and registrations are particularly prone to being listed, falsely, as virii.

I don't imagine it is too difficult for other programs like xrumer to be similarly categorized, especially given some of their features.

And if you're still worried, run the demo sandboxed.
 
Back
Top