Jump to content

Malwarebytes

HELP... false/postive or ?


10 replies to this topic

#1
Denny_M

    New Member

  • Members
  • Pip
  • 34 posts
another fake ... false/postive ?

Infect Files:
C:\Documents and Settings\All Users\Documenti\DVD programmi\DVD copia\RipIt4Me_1.7.0.0_Installer.exe (Backdoor.Bot) -> No action taken.

C:\Documents and Settings\Proprietario\Desktop\PROGRAMMI\PC Utility\UTILITY-NEW\UTILITY\WinXP DOC\GIUGNO1\MIX\DVD copia\RipIt4Me_1.7.0.0_Installer.exe (Backdoor.Bot) -> No action taken.

C:\Programmi\Thoosje 2\Sidebar-v2-installer.exe (Backdoor.Bot) -> No action taken.

C:\Programmi\Samsung\Samsung PC Studio 3\util\SMSMoveD500.exe (Worm.Koobface) -> No action taken.
C:\Programmi\Samsung\Samsung PC Studio 3\util\SMSMoveX800.exe (Worm.Koobface) -> No action taken.
C:\Programmi\Samsung\Samsung PC Studio 3\util\SMSMoveZ510.exe (Worm.Koobface) -> No action taken.


Thoosje is the sidebar that i have for 2 year...

Samsung studio is the original program of samsung !

real infect this RipItMe4 ?


thanks

#2
miekiemoes

    Forum Deity

  • Administrators
  • PipPipPipPipPipPip
  • 7,127 posts
  • Gender:Female
  • Location:Belgium
Hi,

If I'm not mistaken, this has already been fixed...

Please post the full developers log... (header included)

1. Click the Start Menu.
2. Click Run.
3. Type in "mbam.exe /developer", without the quotes.
4. Run the same type of scan you did before and save the logfile and post it.
Mieke Verburgh
Assistant Director of Research

Posted Image

Follow us: Twitter, Become a fan: Facebook

#3
Denny_M

    New Member

  • Members
  • Pip
  • 34 posts
Malwarebytes' Anti-Malware 1.41
Versione del database: 3100
Windows 5.1.2600 Service Pack 2

04/11/2009 22.58.53
mbam-log-2009-11-04 (22-58-46).txt

Tipo di scansione: Scansione completa (C:\|)
Elementi scansionati: 198980
Tempo trascorso: 1 hour(s), 21 minute(s), 40 second(s)

Processi delle memoria infetti: 0
Moduli della memoria infetti: 0
Chiavi di registro infette: 0
Valori di registro infetti: 0
Elementi dato del registro infetti: 0
Cartelle infette: 0
File infetti: 6

Processi delle memoria infetti:
(Nessun elemento malevolo rilevato)

Moduli della memoria infetti:
(Nessun elemento malevolo rilevato)

Chiavi di registro infette:
(Nessun elemento malevolo rilevato)

Valori di registro infetti:
(Nessun elemento malevolo rilevato)

Elementi dato del registro infetti:
(Nessun elemento malevolo rilevato)

Cartelle infette:
(Nessun elemento malevolo rilevato)

File infetti:
C:\Documents and Settings\All Users\Documenti\DVD programmi\DVD copia\RipIt4Me_1.7.0.0_Installer.exe (Backdoor.Bot) -> No action taken.
C:\Documents and Settings\Proprietario\Desktop\PROGRAMMI\PC Utility\UTILITY-NEW\UTILITY\WinXP DOC\GIUGNO1\MIX\DVD copia\RipIt4Me_1.7.0.0_Installer.exe (Backdoor.Bot) -> No action taken.
C:\Programmi\Thoosje 2\Sidebar-v2-installer.exe (Backdoor.Bot) -> No action taken.
C:\Programmi\Samsung\Samsung PC Studio 3\util\SMSMoveD500.exe (Worm.Koobface) -> No action taken.
C:\Programmi\Samsung\Samsung PC Studio 3\util\SMSMoveX800.exe (Worm.Koobface) -> No action taken.
C:\Programmi\Samsung\Samsung PC Studio 3\util\SMSMoveZ510.exe (Worm.Koobface) -> No action taken.

#4
miekiemoes

    Forum Deity

  • Administrators
  • PipPipPipPipPipPip
  • 7,127 posts
  • Gender:Female
  • Location:Belgium
Hi,

Please reread my previous post, because above is not the developers log :)

Also, you are a couple of updates behind, so please update malwarebytes and then get me a developers log:

1. Click the Start Menu.
2. Click Run.
3. Type in "mbam.exe /developer", without the quotes.
4. Run the same type of scan you did before and save the logfile and post it.
Mieke Verburgh
Assistant Director of Research

Posted Image

Follow us: Twitter, Become a fan: Facebook

#5
Denny_M

    New Member

  • Members
  • Pip
  • 34 posts
note that the 3 voices appars from 1 week later ! :)

the samsung voices appars only yesterday.

thanks...i attend .

#6
Denny_M

    New Member

  • Members
  • Pip
  • 34 posts
ok..i attach here the log in a zip file... thanks

Attached Files



#7
B-boy/StyLe/

    Elite Member

  • Trusted Advisors
  • PipPipPipPipPip
  • 658 posts
  • Gender:Male
  • Location:Bulgaria
Hello all,

Samsung FPs were reported here:

http://www.malwareby...showtopic=29849

Thoosje Vista Sidebar was reported here:

http://www.malwareby...showtopic=29911

Regards,
B-boy :)
Posted Image

#8
miekiemoes

    Forum Deity

  • Administrators
  • PipPipPipPipPipPip
  • 7,127 posts
  • Gender:Female
  • Location:Belgium
Denny, please update malwarebytes and scan again, because your database version is outdated.
Get me the developers log please, because you have attached a normal log again.

Let me explain you step by step what to do...

1. Click the Start Menu.
2. Click Run.
3. Type in "mbam.exe /developer", without the quotes. <== important step to get the developer log afterwards!
4. Malwarebytes will open.
5. Click the updates tab
6. Click "Check for updates" in order to get the latest updates
7. Click the "scanner" tab
8. Check: "Perform Quick scan"
9. Click the scan button and allow malwarebytes to scan.
10. When the scan has finished, copy and paste the contents of the log in your next reply.
Mieke Verburgh
Assistant Director of Research

Posted Image

Follow us: Twitter, Become a fan: Facebook

#9
Denny_M

    New Member

  • Members
  • Pip
  • 34 posts
update now and scan.... database 3106 no infections found ! but BIG ERROR ....

for 3 times (in the samsung voices ) ,see:


Posted Image


what is this error. ....? :)

#10
Denny_M

    New Member

  • Members
  • Pip
  • 34 posts
error code 722 (0,9) what is ????

#11
miekiemoes

    Forum Deity

  • Administrators
  • PipPipPipPipPipPip
  • 7,127 posts
  • Gender:Female
  • Location:Belgium
Hi,

A next database update should fix this error... so please wait till the next update (should be soon).
No need for the logs anymore either, since the FP was fixed already. :)

Also, please zip and attach the following files to your next post:

C:\Programmi\Samsung\Samsung PC Studio 3\util\SMSMoveD500.exe
C:\Programmi\Samsung\Samsung PC Studio 3\util\SMSMoveX800.exe
C:\Programmi\Samsung\Samsung PC Studio 3\util\SMSMoveZ510.exe
Mieke Verburgh
Assistant Director of Research

Posted Image

Follow us: Twitter, Become a fan: Facebook





1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users

Follow Us