Jump to content

Malwarebytes

FP : riched20.dll


9 replies to this topic

#1
bobette marlow

    New Member

  • Members
  • Pip
  • 4 posts
Salut,

Malwarebytes' Anti-Malware 1.41
Database version: 3178
Windows 6.0.6001 Service Pack 1

16/11/2009 12:51:17
mbam-log-2009-11-16 (12-51-07).txt




Files Infected:
C:\Program Files\Windows Live\Messenger\riched20.dll (Adware.MyWebSearch) -> No action taken.

#2
nosirrah

    Forum Deity

  • Administrators
  • PipPipPipPipPipPip
  • 5,158 posts
  • Location:Northampton, MA USA
Please get us a developers log :

http://www.malwareby...?showtopic=3228

and if possible zip and attach a copy of riched20.dll to your next post .
Bruce Harrison
Vice President of Research

Posted Image

Follow us: Twitter, Become a fan: Facebook

#3
Gizmo

    New Member

  • Members
  • Pip
  • 6 posts

View Postnosirrah, on Nov 16 2009, 03:28 PM, said:

Please get us a developers log :

http://www.malwareby...?showtopic=3228

and if possible zip and attach a copy of riched20.dll to your next post .

Was anything done here... just updated to paid version and getting same issue plus another file all linked to Windows Live.

DETECTION C:\Program Files\Windows Live\Messenger\msimg32.dll Adware.MyWebSearch ALLOW
DETECTION C:\Program Files\Windows Live\Messenger\msimg32.dll Adware.MyWebSearch ALLOW
DETECTION C:\Program Files\Windows Live\Messenger\riched20.dll Adware.MyWebSearch ALLOW

Manual Scan of mentioned folder also reports adaware.

I ddi search google ... lol ... and these files are reported as true files

#4
AdvancedSetup

    Forum Deity

  • Administrators
  • PipPipPipPipPipPip
  • 22,574 posts
  • Gender:Male
  • Location:US
Hello Gizmo,

Please click on START - RUN and type in MBAM /DEVELOPER and then do a Quick Scan and post back the new log and we'll review.

Thank you.
Ron Lewis
Manager, Online Support

Posted Image

Follow us: Twitter, Become a fan: Facebook

If you've posted to the HJT forum and it has been over 5 days without a response please send a Private Message asking for assistance.

#5
Gizmo

    New Member

  • Members
  • Pip
  • 6 posts

View PostAdvancedSetup, on Dec 7 2009, 09:04 PM, said:

Hello Gizmo,

Please click on START - RUN and type in MBAM /DEVELOPER and then do a Quick Scan and post back the new log and we'll review.

Thank you.

Hopefully this helps

Attached Files



#6
miekiemoes

    Forum Deity

  • Administrators
  • PipPipPipPipPipPip
  • 7,127 posts
  • Gender:Female
  • Location:Belgium
Hi,

These are no False positives:

http://www.virustotal.com/analisis/36f6ecf...708a-1259709152
http://www.virustotal.com/analisis/76adc93...b7a3-1259604770
Mieke Verburgh
Assistant Director of Research

Posted Image

Follow us: Twitter, Become a fan: Facebook

#7
Gizmo

    New Member

  • Members
  • Pip
  • 6 posts

View Postmiekiemoes, on Dec 8 2009, 05:06 PM, said:



Hmmmm but my mcafee 5825 says no infections.... ???

Researching the web this file gets infected BUT when its in an MSN mesenger folder not Windows live.

Attached both files in zip if possible anyone can investigate.

Attached Files



#8
miekiemoes

    Forum Deity

  • Administrators
  • PipPipPipPipPipPip
  • 7,127 posts
  • Gender:Female
  • Location:Belgium
Hi,

Both files are 100% related with Mywebsearch/SmileyCentral adware.
If you rightclick them and choose properties > version, you'll see the "Smiley Central" in their version info
Mieke Verburgh
Assistant Director of Research

Posted Image

Follow us: Twitter, Become a fan: Facebook

#9
Gizmo

    New Member

  • Members
  • Pip
  • 6 posts

View Postmiekiemoes, on Dec 8 2009, 05:55 PM, said:

Hi,

Both files are 100% related with Mywebsearch/SmileyCentral adware.
If you rightclick them and choose properties > version, you'll see the "Smiley Central" in their version info


Hi Mieke, many thanks for your assistance ( rightclick, properties... good tip ) ... they have gone... now where is my son, installing stuff on my laptop...lol

Interesting that a later DAT file of mcafee reports no infection.

Keep up the good work all.....

#10
miekiemoes

    Forum Deity

  • Administrators
  • PipPipPipPipPipPip
  • 7,127 posts
  • Gender:Female
  • Location:Belgium
You're most welcome :(
Mieke Verburgh
Assistant Director of Research

Posted Image

Follow us: Twitter, Become a fan: Facebook





1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users

Follow Us