Jump to content

Malwarebytes

Warning FP in mbam downloader


44 replies to this topic

#1
dvk01

    Regular Member

  • Experts
  • PipPip
  • 71 posts
Heads up warning

There has been a FP in the regnow downloader for MBAM & most probably all regnow sold products via affiliate links

I have been in touch with the AV companies to get it fixed & expect a speedy resolution, but watch out for a few complaints for the next couple of hours

It isn't the actual MBAM file but in the system that regnow use where they download a download manager first and it is the download manager that is the problem



---[ www.virustotal.com ]---------------------------

File Download_mbam-setup.exe received on 03.14.2008 09:15:31 (CET)

Antivirus Version Last Update Result
AhnLab-V3 2008.3.14.0 2008.03.14 no virus found
AntiVir 7.6.0.73 2008.03.13 no virus found
Authentium 4.93.8 2008.03.13 no virus found
Avast 4.7.1098.0 2008.03.13 no virus found
AVG 7.5.0.516 2008.03.13 no virus found
BitDefender 7.2 2008.03.14 no virus found
CAT-QuickHeal 9.50 2008.03.13 Downloader.Keylogger.a (Not a Virus)
ClamAV 0.92.1 2008.03.14 no virus found
DrWeb 4.44.0.09170 2008.03.14 no virus found
eSafe 7.0.15.0 2008.03.09 no virus found
eTrust-Vet 31.3.5614 2008.03.14 no virus found
Ewido 4.0 2008.03.13 no virus found
FileAdvisor 1 2008.03.14 no virus found
Fortinet 3.14.0.0 2008.03.14 Download/Keylogger
F-Prot 4.4.2.54 2008.03.13 no virus found
F-Secure 6.70.13260.0 2008.03.14 no virus found
Ikarus T3.1.1.20 2008.03.14 no virus found
Kaspersky 7.0.0.125 2008.03.14 not-a-virus:Downloader.Win32.Keylogger.a
McAfee 5251 2008.03.13 no virus found
Microsoft 1.3301 2008.03.13 no virus found
NOD32v2 2946 2008.03.14 no virus found
Norman 5.80.02 2008.03.13 no virus found
Panda 9.0.0.4 2008.03.13 no virus found
Prevx1 V2 2008.03.14 no virus found
Rising 20.35.40.00 2008.03.14 no virus found
Sophos 4.27.0 2008.03.14 no virus found
Sunbelt 3.0.963.0 2008.03.14 no virus found
Symantec 10 2008.03.14 no virus found
TheHacker 6.2.92.245 2008.03.14 no virus found
VBA32 3.12.6.2 2008.03.13 Downloader.Win32.Keylogger.a
VirusBuster 4.3.26:9 2008.03.13 no virus found
Webwasher-Gateway 6.6.2 2008.03.13 no virus found

Additional information

File size: 128368 bytes
MD5: 4971a5730dc3fb83d66935578f0cd388
SHA1: 69c1143c716a2261dbb6fe5411d6f1b03ae61fee
PEiD: Armadillo v1.71
Derek Microsoft MVP/Windows - Security Thespykiller | Security & Privacy
I am helping you, please help me by donating to help keep the Hedgehog Rescue Centre running

#2
RubbeR DuckY

    Marcin

  • Root Admin
  • PipPipPipPipPipPip
  • 4,049 posts
  • Gender:Male
Derek, I will have to either contact each of these vendors, or RegNow to stop using silly packers.
Marcin Kleczynski
President and CEO

Posted Image

Follow me on Twitter or check out my Blog!

#3
dvk01

    Regular Member

  • Experts
  • PipPip
  • 71 posts
I have just heard back from KAV and after a bit of a s=discussion with one analyst I have bypassed & gone to a higher level who is getting it fixed
Derek Microsoft MVP/Windows - Security Thespykiller | Security & Privacy
I am helping you, please help me by donating to help keep the Hedgehog Rescue Centre running

#4
RubbeR DuckY

    Marcin

  • Root Admin
  • PipPipPipPipPipPip
  • 4,049 posts
  • Gender:Male
Good to hear .. unfortunately I believe it is unacceptable that RegNow is using these types of packers. I will have a talk with them tonight.
Marcin Kleczynski
President and CEO

Posted Image

Follow me on Twitter or check out my Blog!

#5
dvk01

    Regular Member

  • Experts
  • PipPip
  • 71 posts
it isn't the packer they are detecting or worried about this time but th actual downloader

Regnow don't put an actual download on the site BUT when you follow an affiliate link you get a small downloader which acts as a download manager and the downloader downloads the actual file

I can see why they do it as it makes it easier for them to track and for the developer to upload new versions more easily

The downloader contains the affiliate code which on contacting the main file injects the affiliate code into the actual program that is downloaded

I can see why the antivirus companies consider it a risk as it would not be difficult to alter the downloader to inject malicious code
Derek Microsoft MVP/Windows - Security Thespykiller | Security & Privacy
I am helping you, please help me by donating to help keep the Hedgehog Rescue Centre running

#6
RubbeR DuckY

    Marcin

  • Root Admin
  • PipPipPipPipPipPip
  • 4,049 posts
  • Gender:Male
Any ideas to get the file whitelisted?
Marcin Kleczynski
President and CEO

Posted Image

Follow me on Twitter or check out my Blog!

#7
dvk01

    Regular Member

  • Experts
  • PipPip
  • 71 posts
fixed in Kaspersky now

I haven't heard from the others who did detect it but as they all seem to follow or use KAV detections in some way they should hopefully soon fix it
Derek Microsoft MVP/Windows - Security Thespykiller | Security & Privacy
I am helping you, please help me by donating to help keep the Hedgehog Rescue Centre running

#8
RubbeR DuckY

    Marcin

  • Root Admin
  • PipPipPipPipPipPip
  • 4,049 posts
  • Gender:Male
Thanks :).
Marcin Kleczynski
President and CEO

Posted Image

Follow me on Twitter or check out my Blog!

#9
lordpake

    Advanced Member

  • Honorary Members
  • PipPipPip
  • 215 posts
  • Gender:Male
  • Location:Helsinki / European Union
  • Interests:Anime / Manga / Comp. security

View Postdvk01, on Mar 14 2008, 11:51 PM, said:

fixed in Kaspersky now

I haven't heard from the others who did detect it but as they all seem to follow or use KAV detections in some way they should hopefully soon fix it
Well someone fixed something alright ^^

This time it's NOT a keylogger detection from Kaspersky, but a Winfixer :P
http://www.virustotal.com/analisis/1a94c96...3a72756fe3fb6c1


I'm sure you can appreciate my surprise when, while doing some maintenance on my brother's laptop, I decided to check it with MBAM. Lo and behold, KAV jumps into action when I downloaded via MajorGeeks - 'Authors site' link.
Men make good pets.

~i~System info~i~

#10
RubbeR DuckY

    Marcin

  • Root Admin
  • PipPipPipPipPipPip
  • 4,049 posts
  • Gender:Male
Grr .. anybody have any ideas on how to whitelist this?
Marcin Kleczynski
President and CEO

Posted Image

Follow me on Twitter or check out my Blog!

#11
dvk01

    Regular Member

  • Experts
  • PipPip
  • 71 posts
I have emailed Kaspersky again today as it is still detecting it
detected: riskware not-a-virus:Downloader.Win32.WinFixer.fs File: C:\Documents and Settings\Derek Knight\Desktop\mbam\Download_mbam-setup.exe

If no response I will speak direct to someone high up who has the power to deal with

the problem seems to be with regnow using a stupid download system & not downloading the file itself but the detection is for the regnow downloader for the download
Derek Microsoft MVP/Windows - Security Thespykiller | Security & Privacy
I am helping you, please help me by donating to help keep the Hedgehog Rescue Centre running

#12
RubbeR DuckY

    Marcin

  • Root Admin
  • PipPipPipPipPipPip
  • 4,049 posts
  • Gender:Male
I am in talks with Regnow as of yesterday to help solve this issue.
Marcin Kleczynski
President and CEO

Posted Image

Follow me on Twitter or check out my Blog!

#13
Scotty

    New Member

  • Experts
  • Pip
  • 28 posts
  • Gender:Male
  • Location:Haggistown, Kiltland
I had one yesterday where Zone Alarm id'd MBAM as Winfixer too.

#14
lordpake

    Advanced Member

  • Honorary Members
  • PipPipPip
  • 215 posts
  • Gender:Male
  • Location:Helsinki / European Union
  • Interests:Anime / Manga / Comp. security

View PostScotty, on Apr 13 2008, 08:01 PM, said:

I had one yesterday where Zone Alarm id'd MBAM as Winfixer too.
If you have the AV version from ZoneLabs then this is the same Kaspersky detection. I recall they licensed the AV from Kaspersky.
Men make good pets.

~i~System info~i~

#15
RubbeR DuckY

    Marcin

  • Root Admin
  • PipPipPipPipPipPip
  • 4,049 posts
  • Gender:Male
This is becoming RIDICULOUS. I am personally contacting each of these companies right now. Let's see who is worthy enough to call themselves an Anti-Virus.

CAT-QuickHeal 9.50 2008.04.16 Downloader.Keylogger.a (Not a Virus)
DrWeb 4.44.0.09170 2008.04.16 Adware.Winfixer
Kaspersky 7.0.0.125 2008.04.16 not-a-virus:Downloader.Win32.WinFixer.fs
Norman 5.80.02 2008.04.16 W32/DLoader.GBVM
TheHacker 6.2.92.280 2008.04.16 Aplicacion/Keylogger.a
VirusBuster 4.3.26:9 2008.04.16 Adware.WinFixer.AH

Wish me luck.
Marcin Kleczynski
President and CEO

Posted Image

Follow me on Twitter or check out my Blog!

#16
RubbeR DuckY

    Marcin

  • Root Admin
  • PipPipPipPipPipPip
  • 4,049 posts
  • Gender:Male
All companies have been contacted. The e-mail to Kaspersky bounced back as undeliverable, great! :P. Now I contact RegNow and yell at them.
Marcin Kleczynski
President and CEO

Posted Image

Follow me on Twitter or check out my Blog!

#17
dvk01

    Regular Member

  • Experts
  • PipPip
  • 71 posts
I will sort Kaspersky tomorrow morning UK time
Derek Microsoft MVP/Windows - Security Thespykiller | Security & Privacy
I am helping you, please help me by donating to help keep the Hedgehog Rescue Centre running

#18
leofelix

    Advanced Member

  • Honorary Members
  • PipPipPip
  • 154 posts
  • Gender:Male
  • Location:Italy

View PostRubbeR DuckY, on Apr 16 2008, 10:19 PM, said:

All companies have been contacted. The e-mail to Kaspersky bounced back as undeliverable, great! :P. Now I contact RegNow and yell at them.


Hi Marcin,
I tried to send e-mail to Kaspersky Techincal Support with no response , Ithink the only way to get in touch with them consists in subscribing to their forum.

#19
lordpake

    Advanced Member

  • Honorary Members
  • PipPipPip
  • 215 posts
  • Gender:Male
  • Location:Helsinki / European Union
  • Interests:Anime / Manga / Comp. security

View Postleofelix, on Apr 17 2008, 08:10 PM, said:

Ithink the only way to get in touch with them consists in subscribing to their forum.
And from the little information I've managed to gather while lurking in their forums, I'd say you are wrong. Approaching support via email is the right path to take, it's just that they may be swamped under work load, and they probably, not surprisingly, prioritize their customers. The few times I've been in contact with them, I have no complaints.
Men make good pets.

~i~System info~i~

#20
dvk01

    Regular Member

  • Experts
  • PipPip
  • 71 posts
I am speaking to Kaspersky about it but my contact is away at the moment but he will deal when he comes back

he fixed it last time but another submission must have been done & a more junior one must have not seen it properly

I will see if he can do a permanent whitelisting for it
Derek Microsoft MVP/Windows - Security Thespykiller | Security & Privacy
I am helping you, please help me by donating to help keep the Hedgehog Rescue Centre running





1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users

Follow Us