Jump to content

Cheat Engine 6.2 (%install dir%\dbk64.sys == Rootkit.Necuts.GO)


Gloserous

Recommended Posts

Today MalwareBytes detected  the file dbk64.sys from a Cheat Engine 6.2 install as an Rootkit.Necuts.GO infection.

I can't upload the file due to not having permissions but here is the virus total of the file
https://www.virustotal.com/en/file/edc21b955b5697a42207879d87b7908728c0d2cf12a9e17ef3b4c6d8dccc0ed4/analysis/1394514743/

 

==========Here is a copy of the log==========

 

Malwarebytes Anti-Malware (PRO) 1.75.0.1300
www.malwarebytes.org

Database version: v2014.03.11.02

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 11.0.9600.16476
Gloserous :: IMASHARKSMD [limited]

Protection: Enabled

3/11/2014 1:20:53 AM
MBAM-log-2014-03-11 (01-20-59).txt

Scan type: Custom scan (C:\Program Files (x86)\Cheat Engine 6.2\dbk64.sys|)
Scan options enabled: File System | Heuristics/Shuriken | PUP | PUM | P2P
Scan options disabled: Memory | Startup | Registry | Heuristics/Extra
Objects scanned: 1
Time elapsed:

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 1
C:\Program Files (x86)\Cheat Engine 6.2\dbk64.sys (Rootkit.Necurs.GO) -> No action taken.

(end)
 

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.