Solved Legit Folder Or Malware?

Pebble

New member
Local time
12:03 AM
Messages
24
Going through my system today I came across a folder named Key-Base, Inside was a folder named 27b48b2c.054, Inside were 2 files:


CODE.PK_
CODE.PKD


The path is C:/ProgramData/Key-Base/27b48b2c.054


Both folders and the 2 files are hidden.


Any help appreciated.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom build
OS
Windows 7 64-bit
CPU
i7 2600k
Motherboard
Asus p8p67
Memory
8 Gb @ 1600
Graphics Card(s)
Radeon HD 5870
Antivirus
Kaspersky Internet Security 2015
Browser
IE 10, Firefox 36.0, TOR Brower 31
Program data is a hidden folder

Right-click the folder and scan with your AV & malwarebytes

Same with the files

Upload the folder and files to Virus Total which scans with many avs

Googling for Key-Base and C:\ProgramData\Key-Base I found this

How to remove Trojan.agent.cn? Please help! - Resolved ...

forums.malwarebytes.com › topic › 120366-how-to-re...
Jan 2, 2013 - C:\Program Files (x86)\Norton PC Checkup 3.0\PCCU.exe. C:\Program Files ... If you wish to scan all of them, select the 'Force scan all domains' option. ... 2013-01-01 02:31:37 -------- d-sha-r- C:\ProgramData\Key-Base.
Snick
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
HP Desktop & Compaq Laptop
OS
Win 10 x64, Linux Lite, Win 7 x64, BlackArch, & Kali
Hard Drives
Samsung 850 Pro 256Gb,
Hitachi HDD 1Tb,
Crucial MX SSD 250Gb
Segate 3Tb USB 3.0 Ext. Backup HDD
Internet Speed
150Mbps dn, 20Mbps up
Antivirus
Avast Free, Malwarebytes Anti-Exploit & Anti-Ransomware
Browser
Firefox, Chrome, Opera, & VPN
If this is malware, it proves my point that anti-virus is crap for polymorphic malware and they serve to be nothing but overbloated code bloat. I say this because I see you're running the GRU Kaspersky Internet Security 2015.

GRU (G.U - Wikipedia.)

Kaspersky Internet Security - Wikipedia

Bloomberg - Are you a robot?

Homeland Security Bans Feds From Using Kaspersky Software | Fortune

Trump signs into law U.S. government ban on Kaspersky Lab software - Reuters

Bet you or many readers here never knew this.
 

My Computer

Computer type
PC/Desktop
OS
Windows 7 Ultimate x64
And use Tor with a non-five eyes jurisdiction VPN like Proton VPN or VPN.AC. I pay for my VPN with Monero. Bitcoin is flawed. Research Monero if you want to know about it. If so, you can turn Bitcoin into Monero and send it to your 'My Monero' wallet from here. Easy Crypto Exchange of Bitcoin & 10+ coins – Evonax

I have used that site twice and can vouch for it. At first I processed a few dollars to check its legitimacy. Then latter on I sent some $55 worth of Bitcoin through it and I got Monero in my 'My Monero' wallet. From there I paid for my VPN.

Anyway, I saw you run Tor and had to chime in on that. It's useless without a good, reputable, non-five eyes jurisdiction VPN.

You may be interested in my posts here and here.
 

My Computer

Computer type
PC/Desktop
OS
Windows 7 Ultimate x64
Updated Kaspersky Total Security and a full scan before cleanup & defrag. Nothing found.
I appreciate that Kaspersky may be 'spying' but if it found Statnet and is able to block it... Cool! I don't mind an 'enemy state' spying on me, But I do resent my own country or ally spying on me.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom build
OS
Windows 7 64-bit
CPU
i7 2600k
Motherboard
Asus p8p67
Memory
8 Gb @ 1600
Graphics Card(s)
Radeon HD 5870
Antivirus
Kaspersky Internet Security 2015
Browser
IE 10, Firefox 36.0, TOR Brower 31
Did you scan that file at Virus Total?

Can I has your phone number, bank account number, etc? You don't mind the spying, right? LOL :D

What kind of HDD do you have? You never defrag an SSD.
 

My Computer

Computer type
PC/Desktop
OS
Windows 7 Ultimate x64
Going through my system today I came across a folder named Key-Base, Inside was a folder named 27b48b2c.054, Inside were 2 files:

CODE.PK_
CODE.PKD

The path is C:/ProgramData/Key-Base/27b48b2c.054

PKD stands for Public Key Directory (or Data). C:\ProgramData\Key-Base\<number-string>\CODE.PKD is typically the registration data for software that uses a licence protection system.



An example (in the original German) here: Hinweis Giveaway of the Day - kostenlose Programme - Seite 458

Google Translate version:

This creates the registration data in:
C: \ ProgramData \ Key-Base \ 27b48b2c.052 \ CODE.PK_ + CODE.PKD (files are hidden, so not visible) Save them!
Google Translate


Another example:
...can you (when program is registered with keygen) backup license folder "Key-Base" or only keyfile "CODE.PKD" and "CODE.PK_", delete license folder/file, restore from backup and start SpeedCommander as registered?
SpeedCommander Pro 17.50.9100 - Software Updates - nsane.forums
 
Last edited:

My Computers

System One System Two

  • Computer type
    Laptop
    Computer Manufacturer/Model Number
    Toshiba satellite C650D
    OS
    Windows 7 Home Premium x64
    CPU
    AMD V120
    Memory
    4GB
    Internet Speed
    150 Mbps
    Antivirus
    MSE
    Browser
    IE11, Edge, Firefox
    Other Info
    I also have W7 Pro on my System Two, and several W7 Hyper-V VMs. My other machines run Windows 10/11. Their specs are in my Ten Forums & Eleven Forum profiles.
  • Computer type
    Laptop
    System Manufacturer/Model Number
    Lenovo Thinkpad T430
    OS
    Windows 7 Pro x64
    CPU
    Intel i5-3320M
    Memory
    8 GB
    Hard Drives
    250GB Samsung SSD 860 EVO
    Antivirus
    MSE
Further research

Keybase
keybase.io
Keybase is for keeping everyone's chats and files safe, from families to communities to companies. MacOS, Windows, Linux, iPhone, and Android.

Keybase is a key directory that maps social media identities to encryption keys in a publicly auditable manner. Additionally it offers an end-to-end encrypted chat and cloud storage system, called Keybase Chat and the Keybase Filesystem respectively.

May or may not be part of a Trojan
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
HP Desktop & Compaq Laptop
OS
Win 10 x64, Linux Lite, Win 7 x64, BlackArch, & Kali
Hard Drives
Samsung 850 Pro 256Gb,
Hitachi HDD 1Tb,
Crucial MX SSD 250Gb
Segate 3Tb USB 3.0 Ext. Backup HDD
Internet Speed
150Mbps dn, 20Mbps up
Antivirus
Avast Free, Malwarebytes Anti-Exploit & Anti-Ransomware
Browser
Firefox, Chrome, Opera, & VPN
Thank's Snick, I could find load's on KeyBase folder but nothing on Key-Base. The 'random' sub-folder name made me think I was infected. Done a full scan and nothing was detected, So I'm going to leave the folder as it is.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom build
OS
Windows 7 64-bit
CPU
i7 2600k
Motherboard
Asus p8p67
Memory
8 Gb @ 1600
Graphics Card(s)
Radeon HD 5870
Antivirus
Kaspersky Internet Security 2015
Browser
IE 10, Firefox 36.0, TOR Brower 31
Back
Top