Jump to content

Malwarebytes

[Backdoor.Celofot] Possible F.P


71 replies to this topic

#1
leofelix

    Advanced Member

  • Honorary Members
  • PipPipPip
  • 158 posts
  • Gender:Male
Hi All.

I've just scanned 3 computers of mine (Laptop with Windows 7 home premim x64 - Desktop PC with Windows 7 Ultimate x86 - Virtual PC with XP SP3) with MBAM database version 3896

Backdoor.Celofot has been detected in all my computers and only as a registry entry.
Log is attached in rar format.

I believe it is a false positive, since my computers are fully up to date, I practice a safe surfing and my default browser is sanboxed and I never download from untrusted sources.

Windows 7 64 bit security software installed:
ESET NOD 32 v 4
PC Tools Firewall Plus 6
SpywareBlaster 4.2
WinPatrol 2010
on demand a-squared free and HitMan Pro 3.5
sandboxie3.44

Windows 7 Ultimate 32 bit
GData antivirus 2010
PC Tools Firewal Plus 6.
PREVX Safe OnLine 3.0.5
WinPatrol 2010
on demand a-squared free and HitMan Pro 3.5
sandboxie3.44

Virtual PC with XP SP 3
avira free 9.0
spywareblaster 4.2
a-squared free
WinPatrol 2010
sandboxie 3.44

I also just perfomed a full scan with SAS online scanner which found no malware on my Windows 7 x64.

I'm under a router

Thank you

Attached Files



#2
Tarnak

    Advanced Member

  • Honorary Members
  • PipPipPip
  • 141 posts
Can confirm...Looks like an FP :huh:

Malwarebytes' Anti-Malware 1.44
Database version: 3896
Windows 5.1.2600 Service Pack 2
Internet Explorer 6.0.2900.2180

22/03/2010 9:30:00 AM
mbam-log-2010-03-22 (09-29-52).txt

Scan type: Quick Scan
Objects scanned: 121540
Time elapsed: 5 minute(s), 15 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\protect_ie (Backdoor.Celofot) -> No action taken. [01ADCD28415F739C15682220B794E819]

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)


P.S This is a separate snapshot to the one that I presently beta testing 1.45

#3
JohnBurns

    New Member

  • Members
  • Pip
  • 24 posts
  • Gender:Male
  • Location:Oklahoma City, OK
I have the same item on my Windows 7 pc and on my XP pc - both of which are fully up to date, and have Microsoft Security Essentials, SuperAntiSpyware and HitmanPro, none of which show any problems. I also am behind a router. Very similar to you, leofelix. I am just holding until I find out whether it is a false positive.

#4
Tarnak

    Advanced Member

  • Honorary Members
  • PipPipPip
  • 141 posts
I bet my bottom dollar it is a FP. :huh:

#5
pulsar68

    New Member

  • Members
  • Pip
  • 4 posts
Hi guys. The same for me. Made update and then a fast scan and backdoor.celofot appear. Sure is a False Positive?

#6
Hurin

    New Member

  • Members
  • Pip
  • 2 posts
Glad to find this thread! I was about to enter "panic mode" since I occasionally use the laptop showing this apparent false positive for some secure stuff at work.

Same exact issue as described above. Use Firefox with noscript, MSSE as antivirus, and computer comes up otherwise completely clean. The only possible vector I would consider at all likely is that my wife sometimes uses this laptop. :huh:

Here's something else odd. . . when I went to go find the registry entry it was describing (prior to having MBAM delete it), it wasn't even actually there (unless it's somehow hidden or transient). So, it appears MBAM is possibly seeing a phantom registry value?

Best,

H

#7
jurtti

    New Member

  • Members
  • Pip
  • 1 posts
Hello!

Same problem here. Win 7 64 bit

#8
Tarnak

    Advanced Member

  • Honorary Members
  • PipPipPip
  • 141 posts
Looks like the verdict is in...FP! ...but i ain't no Guru! > http://en.wikipedia....hod,_No_Teacher

:huh:

#9
pulsar68

    New Member

  • Members
  • Pip
  • 4 posts

View PostHurin, on Mar 22 2010, 12:52 AM, said:

Glad to find this thread! I was about to enter "panic mode" since I occasionally use the laptop showing this apparent false positive for some secure stuff at work.

Same exact issue as described above. Use Firefox with noscript, MSSE as antivirus, and computer comes up otherwise completely clean. The only possible vector I would consider at all likely is that my wife sometimes uses this laptop. :huh:

Here's something else odd. . . when I went to go find the registry entry it was describing (prior to having MBAM delete it), it wasn't even actually there (unless it's somehow hidden or transient). So, it appears MBAM is possibly seeing a phantom registry value?

Best,

H

What does she do with your laptop? :lol:

#10
chimpy

    Elite Member

  • Honorary Members
  • PipPipPipPipPip
  • 786 posts
  • Gender:Female
  • Location:North of England
Just got the same result here too!
Vista HB 32 bit,WoT,ABP,Sandboxie free,MBAM,Ccleaner,NoScript,AVG 2011 free,Hostsman

#11
Hurin

    New Member

  • Members
  • Pip
  • 2 posts

View Postpulsar68, on Mar 21 2010, 05:08 PM, said:

What does she do with your laptop? :unsure:
Hehe. . . nothing that should cause trouble. But you never know!

#12
Guest_SFdude_*

  • Guests

View PostTarnak, on Mar 21 2010, 11:59 PM, said:

Looks like the verdict is in...FP! ...but i ain't no Guru! > http://en.wikipedia....hod,_No_Teacher

:unsure:
@Tarnak:

My MBAM also just detected
"backdoor.celofot" as a bad registry entry.
(Have XP SP2 fully patched,
MBAM, NoScript
and Firefox 3.5.8 running INSIDE Sandboxie).


My Question to you...
You have 3 posts so far (in this thread),
affirming that:
"...it's an FP".

Your 3d post absolutely declares about "backdoor.celofot":
"looks like the verdict is in...FP!".

Can you illuminate the rest of us mortals why you say that?
What, who and/or where does it state that it's an FP?

Thanks...

#13
pulsar68

    New Member

  • Members
  • Pip
  • 4 posts

View PostHurin, on Mar 22 2010, 01:12 AM, said:

Hehe. . . nothing that should cause trouble. But you never know!

That's right... we never know! :unsure:

#14
nosirrah

    Forum Deity

  • Administrators
  • PipPipPipPipPipPip
  • 5,399 posts
  • Location:Northampton, MA USA
This will be fixed in just a sec guys .
Bruce Harrison
Vice President of Research

Posted Image

Follow us: Twitter, Become a fan: Facebook

#15
virus_monkey

    New Member

  • Members
  • Pip
  • 1 posts
Can anyone from malware bytes confirm this being a FP? I have seen this on everything from XP (sp0, sp1, sp2 and sp3), Vista (sp0, sp1 and sp2) and Windows 7...also all flavors 32 and 64bit

#16
chimpy

    Elite Member

  • Honorary Members
  • PipPipPipPipPip
  • 786 posts
  • Gender:Female
  • Location:North of England
I have it in my results so if it is confirmed as a FP what do I do to restore it? do I "ignore" it or untick it? or something else?
Vista HB 32 bit,WoT,ABP,Sandboxie free,MBAM,Ccleaner,NoScript,AVG 2011 free,Hostsman

#17
Tarnak

    Advanced Member

  • Honorary Members
  • PipPipPip
  • 141 posts

View PostSFdude, on Mar 22 2010, 10:18 AM, said:

Can you illuminate the rest of us mortals why you say that?
What, who and/or where does it state that it's an FP?

Thanks...


all care no responsibility http://craigdavis.tumblr.com/page/2 :unsure:

#18
Guest_SFdude_*

  • Guests

View Postnosirrah, on Mar 22 2010, 12:22 AM, said:

This will be fixed in just a sec guys .

Thanks for you quick intervention, Nosirrah!

That's why MBAM and its community are tops! :unsure:

#19
Jetstar

    New Member

  • Members
  • Pip
  • 3 posts
Well, I think this might have messed me up a bit...

Ironically, a few hours ago a malicious file made it's way onto my desktop. Of course, I use Malwarebytes as a first resort and it picks up the F.P. everyone is getting in this thread. I removed it.

What kind of damage have I done now?

#20
A8AWD

    New Member

  • Members
  • Pip
  • 3 posts

View Postnosirrah, on Mar 21 2010, 08:22 PM, said:

This will be fixed in just a sec guys .

Have you determined if this is a FP? Thanks?





1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users

Follow Us