Jump to content

Malwarebytes

False positive winlogon.exe


20 replies to this topic

#1
gen-hackman

    New Member

  • Members
  • Pip
  • 22 posts
  • Gender:Male
  • Location:Marseille , France
hello

i find a funny thing about Malwarebytes

take the installer of any program ( for example VLC installer ) copy it in your desktop , rename it winlogon.exe.

make a scan with malwarebytes and he finds that's a Reserved.world.exploit ^^

isn't it funny ?

i see that everyday with my tool Pre_Scan renamed winlogon to kill the rogues when i make use MBAM at the end of the disinfection :)

http://forums-fec.be...an/Pre_Scan.exe

Regards

#2
shadowwar

    Forum Deity

  • Moderators
  • PipPipPipPipPipPip
  • 2,690 posts
That is detected like it should be. Reserved word exploit means that nothing should be named winlogon.exe outside of system directory. If you are doing this to get it to run it can be added to the Malwarebytes ignore list.
Malware does this a lot but also power users can do this sometimes to get tools to run outside of a malware blacklist. We have no way of knowing if this is malware or on purpose that is why its detected like this.

How often is your file updated? It may be possible to whitelist it.
Rich Matteo
Research Engineer

Posted Image

Follow us: Twitter, Become a fan: Facebook

#3
gen-hackman

    New Member

  • Members
  • Pip
  • 22 posts
  • Gender:Male
  • Location:Marseille , France
How often is your file updated?

it depends... the more often i updated my tool .... 6 times on a day ( seeing that , you can't use the MD5 to whitelist it)

if it can serve to you :

Version = 2.6.1.9 (changes very often , 6 = month , 19 = day)
LegalCopyright = g3n-h@ckm@n
FileDescription = g3n-h@ckm@n
DefaultLangCodepage = 040C04B0

i don't which repair you can take ....

it's generaly in downloads folder or desktop at the begginning , and after it's on the desktop cause the program makes a copy of himself here at the end on the scan/kill to be scripted at the launch back without having to search it...try it and you'll see

in fact it has 3 names :

Pre_Scan.exe
Winlogon.exe (you understand why ^^)
Pre_Scan.pif (i think you understand why too :D )

regards

#4
shadowwar

    Forum Deity

  • Moderators
  • PipPipPipPipPipPip
  • 2,690 posts
Do you have a few previous versions you can attach here maybe?
Thanks.
Rich Matteo
Research Engineer

Posted Image

Follow us: Twitter, Become a fan: Facebook

#5
gen-hackman

    New Member

  • Members
  • Pip
  • 22 posts
  • Gender:Male
  • Location:Marseille , France
can we attach 6/7 Mo here ?

#6
shadowwar

    Forum Deity

  • Moderators
  • PipPipPipPipPipPip
  • 2,690 posts
yes or pm me a link or the files. Thanks
Rich Matteo
Research Engineer

Posted Image

Follow us: Twitter, Become a fan: Facebook

#7
gen-hackman

    New Member

  • Members
  • Pip
  • 22 posts
  • Gender:Male
  • Location:Marseille , France
ok i've another idea

here is a zip containing 3 samples of the last versions


regards

#8
gen-hackman

    New Member

  • Members
  • Pip
  • 22 posts
  • Gender:Male
  • Location:Marseille , France
oups....

#9
shadowwar

    Forum Deity

  • Moderators
  • PipPipPipPipPipPip
  • 2,690 posts
Got em and deleted links.
Will look at this by tomorrow.
Rich Matteo
Research Engineer

Posted Image

Follow us: Twitter, Become a fan: Facebook

#10
shadowwar

    Forum Deity

  • Moderators
  • PipPipPipPipPipPip
  • 2,690 posts
All these are the same md5.
Rich Matteo
Research Engineer

Posted Image

Follow us: Twitter, Become a fan: Facebook

#11
gen-hackman

    New Member

  • Members
  • Pip
  • 22 posts
  • Gender:Male
  • Location:Marseille , France
ok there's still one link in my 1st post ( not important for me if it rests )

read you later , thx

#12
gen-hackman

    New Member

  • Members
  • Pip
  • 22 posts
  • Gender:Male
  • Location:Marseille , France
yes but when i update the md5 changes obligatory

#13
gen-hackman

    New Member

  • Members
  • Pip
  • 22 posts
  • Gender:Male
  • Location:Marseille , France
I've just updated now for an hour

here's the analysys from virus-total

https://www.virustot...sis/1340150491/

permanent links to download :

http://gen-hackman.f...-speech-pre_san

i know the Md5 is the same for them three , only the name changes

#14
shadowwar

    Forum Deity

  • Moderators
  • PipPipPipPipPipPip
  • 2,690 posts
Ok can white this for now. Was trying to see past versions so i can make a stronger white for them.
Rich Matteo
Research Engineer

Posted Image

Follow us: Twitter, Become a fan: Facebook

#15
gen-hackman

    New Member

  • Members
  • Pip
  • 22 posts
  • Gender:Male
  • Location:Marseille , France
ok thank you very much :D

Regards

PS : in fact it's not so important but if i need to make use it again after Malwarebytes scan and deletion, the user will have to download it again and it makes manipulations for nothing :)
scripting my tool , there's a lot of possibility of switches (a little bit like Combofix ) and you can do every what you want in the PC.

thx again

#16
shadowwar

    Forum Deity

  • Moderators
  • PipPipPipPipPipPip
  • 2,690 posts
This should be fixed in next database update.
Rich Matteo
Research Engineer

Posted Image

Follow us: Twitter, Become a fan: Facebook

#17
gen-hackman

    New Member

  • Members
  • Pip
  • 22 posts
  • Gender:Male
  • Location:Marseille , France
thank you very much !

like we say in French : "Au plaisir"

the expression does mean : pleasure to see you again in the near Future :)

bye

#18
gen-hackman

    New Member

  • Members
  • Pip
  • 22 posts
  • Gender:Male
  • Location:Marseille , France
hello just to say it's still detected like before :)

Regards

#19
shadowwar

    Forum Deity

  • Moderators
  • PipPipPipPipPipPip
  • 2,690 posts
I just checked here and on desktop its not detected?
Rich Matteo
Research Engineer

Posted Image

Follow us: Twitter, Become a fan: Facebook

#20
gen-hackman

    New Member

  • Members
  • Pip
  • 22 posts
  • Gender:Male
  • Location:Marseille , France
ok sorry mbam was not updated

thanks





1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users

Follow Us