Hello!
Detected as Trojan.FakeAlert
database version 7019
#1
Posted 04 July 2011 - 11:24 AM
#2
Posted 04 July 2011 - 01:35 PM
Please zip and attach your copy.
#3
Posted 04 July 2011 - 01:38 PM
I double checked both versions of putty currently available and neither is detected so we wont be able to progress further without the version you have.
#4
Posted 04 July 2011 - 02:29 PM
#5
Posted 04 July 2011 - 03:00 PM
I am unable to verify that this ever existed before today, is this a custom build or modified in some way?
#6
Posted 04 July 2011 - 03:21 PM
#7
Posted 04 July 2011 - 03:31 PM
The reason I ask is that there is decent evidence that this has only existed for about 6 hours. The MD5 has no hit as all on google and virustotal shows an initial scan earlier today. The other possibility is that for some reason putty was polymorphic back then and everyone got their own MD5 but I do not think that is likely.
The reason I was asking about default version VS. customized is that it would change how we process this.
Either way I am looking into this now.
The reason I was asking about default version VS. customized is that it would change how we process this.
Either way I am looking into this now.
#8
Posted 01 May 2012 - 06:28 AM
Hi,
I get a false(?) positive with the version directly from the PuTTY download page:
http://www.chiark.gr...y/download.html
The latest release version (beta 0.62). For Windows on Intel x86 PuTTY: putty.exe
Malwarebytes Anti-Malware 1.61.0.1400
www.malwarebytes.org
Database version: v2012.05.01.05
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
Omistaja :: OMISTAJA-PC [administrator]
01/05/2012 14:14:59
mbam-log-2012-05-01 (14-14-59).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 219798
Time elapsed: 20 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 1
C:\Users\Omistaja\Desktop\putty.exe (Trojan.Swrort) -> Quarantined and deleted successfully.
(end)
I get a false(?) positive with the version directly from the PuTTY download page:
http://www.chiark.gr...y/download.html
The latest release version (beta 0.62). For Windows on Intel x86 PuTTY: putty.exe
Malwarebytes Anti-Malware 1.61.0.1400
www.malwarebytes.org
Database version: v2012.05.01.05
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
Omistaja :: OMISTAJA-PC [administrator]
01/05/2012 14:14:59
mbam-log-2012-05-01 (14-14-59).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 219798
Time elapsed: 20 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 1
C:\Users\Omistaja\Desktop\putty.exe (Trojan.Swrort) -> Quarantined and deleted successfully.
(end)
Attached Files
#9
Posted 01 May 2012 - 07:58 AM
I also started receivng
I also started receiving warnings from Malwarebytes for the same version of PuTTY [0.62 beta] earlier today. Also tried downloading a fresh copy of PuTTY from the web and still the same Trojan.Swrort alert.
Malwarebytes Anti-Malware (PRO) 1.61.0.1400
www.malwarebytes.org
Database version: v2012.05.01.03
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
Regards,
Shane
rpa, on 01 May 2012 - 06:28 AM, said:
Hi,
I get a false(?) positive with the version directly from the PuTTY download page:
http://www.chiark.gr...y/download.html
The latest release version (beta 0.62). For Windows on Intel x86 PuTTY: putty.exe
Malwarebytes Anti-Malware 1.61.0.1400
www.malwarebytes.org
Database version: v2012.05.01.05
Windows 7 Service Pack 1 x64 NTFS
I get a false(?) positive with the version directly from the PuTTY download page:
http://www.chiark.gr...y/download.html
The latest release version (beta 0.62). For Windows on Intel x86 PuTTY: putty.exe
Malwarebytes Anti-Malware 1.61.0.1400
www.malwarebytes.org
Database version: v2012.05.01.05
Windows 7 Service Pack 1 x64 NTFS
I also started receiving warnings from Malwarebytes for the same version of PuTTY [0.62 beta] earlier today. Also tried downloading a fresh copy of PuTTY from the web and still the same Trojan.Swrort alert.
Malwarebytes Anti-Malware (PRO) 1.61.0.1400
www.malwarebytes.org
Database version: v2012.05.01.03
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
Regards,
Shane
#10
Posted 01 May 2012 - 09:15 AM
I too have begun to receive warnings from Malwarebytes for PuTTY 0.62 beta across our network. A fresh copy of PuTTY still gets flagged. Every time the alert is warning that PuTTY.exe is infected with Trojan.Swrort.
Malwarebytes Anti-Malware (PRO) 1.61.0.1400
Malwarebytes Anti-Malware (Corporate) 1.61.0.1400
Database version: v2012.05.01.05
Windows 7 SP1 x64 & x32
Malwarebytes Anti-Malware (PRO) 1.61.0.1400
Malwarebytes Anti-Malware (Corporate) 1.61.0.1400
Database version: v2012.05.01.05
Windows 7 SP1 x64 & x32
#11
Posted 01 May 2012 - 10:04 AM
Ok looking into this now folks.Thanks for the reports(s)
Edit/Update.
Confirmed that the recent detection is indeed a F/P.
This will be fixed on the next update cycle.
Edit/Update.
Confirmed that the recent detection is indeed a F/P.
This will be fixed on the next update cycle.
1 user(s) are reading this topic
0 members, 1 guests, 0 anonymous users

Sign In
Create Account

Back to top










