Jump to content

Malwarebytes

Malware.trace


1 reply to this topic

#1
Adam Brock

    Advanced Member

  • Honorary Members
  • PipPipPip
  • 174 posts
  • Gender:Male
  • Location:Waco, TX, USA
I found these files in the windows and system32 folders on a machine infected with rogue av. I don't believe they're malicious by themselves, but it'd be nice if they could get removed as trace files.

https://bearspace.baylor.edu/Adam_Brock/mal...91117-trace.zip

The password is "infected".

\\ACB

#2
Fatdcuk

    Malware BBQ'er

  • Moderators
  • PipPipPipPipPipPip
  • 16,155 posts
  • Gender:Male
  • Location:127.0.0.1
Hi Adam,

They are randomly created fallout files for the WiniClone family to make fake detections against.

You are correct that they are not malicious as they are non MZ and full of random garbage.

Because of the randomness of both the filenames and file contents i would have to create 701 signatures per each infection from this rogue family(they are averaging 3-4 new builds a week currently :))

So i guess you can see why we have'nt been removing thus far as would require much work and utilize valuable DB space for deleting non malicious files.
Ade Gill
Research Engineer

Posted Image

Follow us: Twitter, Become a fan: Facebook





1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users

Follow Us