Jump to content

Malwarebytes

Bakdoor.bot in sysprep.exe


4 replies to this topic

#1
Rocky

    New Member

  • Members
  • Pip
  • 29 posts
I've just updated my MBAM (free version) in my win XP sp3 when at the quick scan during euristic-extra scan I've found the backdoor.bot in sysprep.exe located in system32 folder.
I've quarantined the file but I'm wondering if it could be a false positive and the file should be therefore restored (I've known that sysprep.exe is a legitimate file of the system).
Thanks in advance for any suggestions.

#2
Rocky

    New Member

  • Members
  • Pip
  • 29 posts
Some additional info to help you in finding a solution to my problem:
1) a full scan before the quarantine confirmed the infection in sysprep.exe
2) if I'm not wrong the file sysprep.exe seems to have been added to my system with a recent installation of Visual c++ libraries
3) Superantispyware did not find anything; my Kaspersky internet security (my realtime protection) did not find anything either
4) with an on-line scan with VirusTotal 30 out of 31 products did not find anything; only the last one, webwasher guard (?) found something "suspicious"
Keep waiting for your suggestions
Cheers

#3
nosirrah

    Forum Deity

  • Administrators
  • PipPipPipPipPipPip
  • 5,158 posts
  • Location:Northampton, MA USA
Will be corrected this morning .
Bruce Harrison
Vice President of Research

Posted Image

Follow us: Twitter, Become a fan: Facebook

#4
nosirrah

    Forum Deity

  • Administrators
  • PipPipPipPipPipPip
  • 5,158 posts
  • Location:Northampton, MA USA
Please update and scan again , MBAM should now be able to tell the difference between the real and fake file .
Bruce Harrison
Vice President of Research

Posted Image

Follow us: Twitter, Become a fan: Facebook

#5
Rocky

    New Member

  • Members
  • Pip
  • 29 posts

View Postnosirrah, on Sep 13 2008, 03:40 PM, said:

Please update and scan again , MBAM should now be able to tell the difference between the real and fake file .

Great job Bruce,
just updated to version 1145 and the scan ended with success.
Let me thank you once again for your help.
Cheers





1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users

Follow Us