Trojan sxe6672.exe located within MapleRoyals Program Files folder

Discussion in 'Closed' started by xballz, Nov 5, 2015.

  1. xballz
    Offline

    xballz Donator

    Joined:
    Nov 2, 2015
    Messages:
    20
    Likes Received:
    13
    Gender:
    Male
    Country Flag:
    IGN:
    HolyMacaroni
    Level:
    10
    After running a scan via HitMan Pro x64 within a completely fresh copy of Win 7 Ulti and a fresh download of MapleRoyals, HitMan Pro located a Trojan by the name of sxe6672.exe. I thought that you should be aware considering that whoever uploaded the file may have an instance of malware/viruses on their PC, or the database that the files are located on is corrupted in some way.
     
  2. John
    Offline

    John Donator

    Joined:
    Aug 5, 2013
    Messages:
    15,134
    Likes Received:
    8,187
    Gender:
    Male
    sxe6672.exe is not part of the MapleRoyals install package. That file may be a true trojan that has infected your computer, but it did not come from MapleRoyals.
     
    Aallas likes this.
  3. Matt
    Offline

    Matt Administrator

    Joined:
    May 8, 2013
    Messages:
    14,849
    Likes Received:
    18,782
    Gender:
    Male
    Location:
    United Kingdom
    Country Flag:
    IGN:
    Matt
    Level:
    N/A
    Guild:
    Staff
    I'd be interested to see the log/report from the virus scan please. And moving this to Technical help.
     
  4. xballz
    Offline

    xballz Donator

    Joined:
    Nov 2, 2015
    Messages:
    20
    Likes Received:
    13
    Gender:
    Male
    Country Flag:
    IGN:
    HolyMacaroni
    Level:
    10
    If the log is still available, i will post it.
     
  5. xballz
    Offline

    xballz Donator

    Joined:
    Nov 2, 2015
    Messages:
    20
    Likes Received:
    13
    Gender:
    Male
    Country Flag:
    IGN:
    HolyMacaroni
    Level:
    10
    I did a fresh install of windows during the same night that I installed a fresh copy of MSRoyals. It's preposterous to claim that a Trojan miraculously invaded a file that was newly installed. Using logic would dictate that the Trojan originated from the MSRoyals download considering that it was literally the only infected file on my computer. This is proven even more considering that the only other installations that took place were drivers from ASUS, google chrome, skype, nvidia geforce drivers, and CPU-Z. All of which came from trusted and accredited sites. The only culprit would be a custom MS server client downloaded from a google drive account, which can ultimately be altered by anyone who has access to it.
     

    Attached Files:

  6. xiknight
    Offline

    xiknight Donator

    Joined:
    Oct 19, 2015
    Messages:
    5
    Likes Received:
    1
    Gender:
    Male
    Country Flag:
    IGN:
    NostalgiaPlz
    Level:
    76
    Here is an excerpt from my own log showing the same; I have the rest if you're interested.

    D:\Program Files (x86)\MapleRoyals\sxeA41E.tmp
    Size . . . . . . . : 7,909,376 bytes
    Age . . . . . . . : 0.0 days (2015-11-05 18:54:12)
    Entropy . . . . . : 6.8
    SHA-256 . . . . . : D436159151D8D3096A249AD26B7182052752EAC9D191FC47328FA584C8182ECF
    Product . . . . . : Wizet MapleStory
    Publisher . . . . : Wizet
    Description . . . : MapleRoyals v62 MapleStory Private Server
    Version . . . . . : 1.0.0.1
    Desktop . . . . . : Default
    Parent Name . . . : D:\Program Files (x86)\MapleRoyals\MapleRoyals.exe
    LanguageID . . . . : 1042
    Running processes : 1276
    > Bitdefender . . . : Trojan.GenericKD.2292348
    Fuzzy . . . . . . : 104.0
     
  7. Andreas
    Offline

    Andreas Donator

    Joined:
    May 31, 2014
    Messages:
    14,272
    Likes Received:
    4,333
    Gender:
    Male
    IGN:
    Egonic
    Level:
    19x
    I ran Hitman myself and I did not have that on my computer, only thing it complained on was the MapleRoyals.exe like always.
    I also re downloaded the setup from the website, the google drive one and still nothing.
     
    Last edited: Nov 6, 2015
    xiknight likes this.
  8. Matt
    Offline

    Matt Administrator

    Joined:
    May 8, 2013
    Messages:
    14,849
    Likes Received:
    18,782
    Gender:
    Male
    Location:
    United Kingdom
    Country Flag:
    IGN:
    Matt
    Level:
    N/A
    Guild:
    Staff
    sxeA41E.tmp makes more sense. That is the unpacked client file that gets temporarily stored in the MapleRoyals folder when you open MapleRoyals.exe. So it is part of MapleRoyals and is a false positive.
     
    xiknight likes this.

Share This Page