Avast WEBforum

Other => Viruses and worms => Topic started by: Lisandro on May 20, 2010, 07:20:37 PM

Title: Strange MBAM detections again...
Post by: Lisandro on May 20, 2010, 07:20:37 PM
I've run MBAM regularly. Nothing is found.
Today appeared a f.exe file in the root directory.
Of course it is fishy. Most probably infected.
The problem is that the file NEVER exists...

avast does not detect any rootkit also.
Title: Re: Strange MBAM detections again...
Post by: DavidR on May 20, 2010, 07:52:21 PM
Well the file might well be hidden from the normal windows explorer or APIs. So it might be worth running GMER anti-rootkit to check.

    (http://www.geekstogo.com/misc/guide_icons/gmer.png) GMER Rootkit Scanner - Download (http://www.gmer.net/gmer.zip) - Homepage (http://www.gmer.net/)
    • Download GMER
    • Extract the contents of the zipped file to desktop.
    • Double click GMER.exe.
    (http://img.photobucket.com/albums/v666/sUBs/gmer_zip.gif)
    • If it gives you a warning about rootkit activity and asks if you want to run a full scan...click on NO, then use the following settings for a more complete scan..
    • In the right panel, you will see several boxes that have been checked. Ensure the following are UNCHECKED ...
      • IAT/EAT
      • Drives/Partition other than Systemdrive (typically C:\)
      • Show All (don't miss this one)
      (http://www.geekstogo.com/misc/guide_icons/GMER_thumb.jpg) (http://www.geekstogo.com/misc/guide_icons/GMER_instructions.jpg)
      Click the image to enlarge it
    • Then click the Scan button & wait for it to finish.
    • Once done click on the [Save..] button, and in the File name area, type in "ark.txt" 
    • Save the log where you can easily find it, such as your desktop.
    **Caution**
    Rootkit scans often produce false positives. Do NOT take any action on any "<--- ROOKIT" entries

    Please copy and paste the report into your Post.
    Title: Re: Strange MBAM detections again...
    Post by: Lisandro on May 22, 2010, 03:50:09 AM
    Essexboy, can you check my log?
    http://www.mediafire.com/file/dtnn0mmwgqm/GMER.7z
    Title: Re: Strange MBAM detections again...
    Post by: Lisandro on May 22, 2010, 01:45:02 PM
    Uninstalled MBAM. Boot. Installed again.
    Problem is there...

    Code: [Select]
    Malwarebytes' Anti-Malware 1.46
    www.malwarebytes.org

    Versão da Base de Dados:  4127

    Windows 6.1.7600
    Internet Explorer 8.0.7600.16385

    22/05/2010 08:39:49
    mbam-log-2010-05-22 (08-39-49).txt

    Tipo de Verificação:  Verificação Rápida
    Objetos escaneados:  138823
    Tempo decorrido: 9 hora(s), 22 minuto(s), 11 segundo(s)

    Processos de Memória Infectados:  0
    Módulos de Memória Infectados:  0
    Chaves de Registro Infectadas: 0
    Valores de Registro Infectados: 0
    Itens de Dados no Registro Infectados:  0
    Pastas Infectadas:  0
    Arquivos Infectados: 1

    Processos de Memória Infectados:
    (Não foram detectados ítens maliciosos)

    Módulos de Memória Infectados:
    (Não foram detectados ítens maliciosos)

    Chaves de Registro Infectadas:
    (Não foram detectados ítens maliciosos)

    Valores de Registro Infectados:
    (Não foram detectados ítens maliciosos)

    Itens de Dados no Registro Infectados:
    (Não foram detectados ítens maliciosos)

    Pastas Infectadas:
    (Não foram detectados ítens maliciosos)

    Arquivos Infectados:
    C:\f.exe (Trojan.Agent) -> No action taken.

    I had this problem before and could not solve (I've formated/installed again everything so the problem disappeared in meanwhile...).
    http://forum.avast.com/index.php?topic=58921.msg496604#msg496604
    Title: Re: Strange MBAM detections again...
    Post by: DavidR on May 22, 2010, 02:51:02 PM
    Your MBAM log shows No action taken, what happens when you let it Remove it ?
    Presumably on reboot it is back again ?

    I'm not too familiar with the GMER logs and this is the largest GMER log I have seen, but I have had a quick look at it and I don't see anything obvious; GMER is usually quite distinct in highlighting anything that it considers suspect/a rootkit.

    So I think we will need essexboy to take a look at it.
    Title: Re: Strange MBAM detections again...
    Post by: Lisandro on May 22, 2010, 03:23:49 PM
    I run OTL (like posted here: http://forum.avast.com/index.php?topic=58921.msg496741#msg496741).
    The logs are here: http://www.mediafire.com/file/ijydtq4mzjj/OTL.7z

    Your MBAM log shows No action taken, what happens when you let it Remove it ?
    Allow to remove and boot three times... MBAM does nothing with it.
    Title: Re: Strange MBAM detections again...
    Post by: DavidR on May 22, 2010, 03:29:42 PM
    Yes it will take essexboy to root into the OTL log as I have no experience of that.
    Title: Re: Strange MBAM detections again...
    Post by: essexboy on May 22, 2010, 03:45:19 PM
    Hi Tech - GMER looks clean, as does OTL.  Note this part from the OTL scan
     < %SYSTEMDRIVE%\*.exe >


    < MD5 for: AGP440.SYS >
    The empty part under %systemdrive%\*.exe means that there are no exe files on your root drive - which is as should be

    MBAM is now at 4130 - could you update and see if it is still present
    Title: Re: Strange MBAM detections again...
    Post by: Lisandro on May 22, 2010, 04:03:18 PM
    OTM log:

    Code: [Select]
    ========== PROCESSES ==========
    Process explorer.exe killed successfully!
    ========== FILES ==========
    File/Folder C:\f.exe not found.
    ========== COMMANDS ==========
     
    OTM by OldTimer - Version 3.1.12.0 log created on 05222010_102611

    Essexboy, I'll update MBAM again.
    Title: Re: Strange MBAM detections again...
    Post by: Lisandro on May 22, 2010, 04:06:54 PM
    Essexboy, which will be good as a third opinion?
    SuperAntispyware?
    HitmanPro?
    Any on-line scanning?
    Title: Re: Strange MBAM detections again...
    Post by: Asyn on May 22, 2010, 04:13:30 PM
    Do you dare to try this...?? ;)
    http://www.emsisoft.com/en/software/antimalware/
    asyn
    Title: Re: Strange MBAM detections again...
    Post by: Lisandro on May 22, 2010, 05:25:08 PM
    Do you dare to try this...?? ;)
    http://www.emsisoft.com/en/software/antimalware/
    For what? More false positives? ???
    And look for a fourth opinion ;D
    Title: Re: Strange MBAM detections again...
    Post by: Lisandro on May 22, 2010, 05:25:32 PM
    Combofix log.
    Title: Re: Strange MBAM detections again...
    Post by: essexboy on May 22, 2010, 05:58:47 PM
    Well CF couldn't find it

    c:\users\Tech\AppData\Roaming\inst.exe This was taken out on the principle that exe files should not reside there

    I have just spent an hour getting Hitmanpro off of my system - so not happy with that one

    Title: Re: Strange MBAM detections again...
    Post by: Lisandro on May 22, 2010, 07:38:29 PM
    Well CF couldn't find it
    Any further thing to do?

    c:\users\Tech\AppData\Roaming\inst.exe This was taken out on the principle that exe files should not reside there
    Ok. Deleted.
    But it was a clean file: http://www.virustotal.com/analisis/c74d2fa6374b5f1e251e3205de0efe99ed026b8b7a0ad5ee549ee3700f8e63d7-1274549791

    I have just spent an hour getting Hitmanpro off of my system - so not happy with that one
    Thanks for sharing. Dropping it then. I don't like SuperAntispyware due to the things it needs to be running even on demand (drivers, services, etc.).
    Title: Re: Strange MBAM detections again...
    Post by: Lisandro on May 22, 2010, 07:51:29 PM
    I've registered and entered the information into MBAM forum.
    http://forums.malwarebytes.org/index.php?showtopic=51225
    Title: Re: Strange MBAM detections again...
    Post by: essexboy on May 22, 2010, 08:44:19 PM
    Methinks MBAM has decided to play games with you - by finding non-existant files
    Title: Re: Strange MBAM detections again...
    Post by: Lisandro on May 22, 2010, 08:45:56 PM
    Methinks MBAM has decided to play games with you - by finding non-existant files
    I can't believe ;D
    Am I alone? ???
    Title: Re: Strange MBAM detections again...
    Post by: essexboy on May 22, 2010, 08:56:40 PM
    But look on the bright side - it makes you special  ;D
    Title: Re: Strange MBAM detections again...
    Post by: Lisandro on May 22, 2010, 08:58:20 PM
    But look on the bright side - it makes you special  ;D
    No, it makes me unlucky ;D
    Title: Re: Strange MBAM detections again...
    Post by: Lisandro on May 23, 2010, 09:23:58 PM
    MBAM forum remains in silent...
    Is it normal? I mean, slow response time?
    Title: Re: Strange MBAM detections again...
    Post by: Wheresthelove on May 24, 2010, 08:31:22 AM
    MBAM forum remains in silent...
    Is it normal? I mean, slow response time?

    Nope, they usually reply within 24 hours. In order to make things move along more smoothly and quickly next time. You should follow these steps when posting a F/P in Malwarebytes' forum.
    1. Go to the Start Menu.
    2. Click Run
    3. Type in mbam.exe /developer
    4. Then run a quick or full scan, save the logfile and post it.

    Also, if you can attach the file with your post in ZIP or RAR format.
    Title: Re: Strange MBAM detections again...
    Post by: Lisandro on May 25, 2010, 05:26:13 PM
    Absolutely lack of support...
    http://forums.malwarebytes.org/index.php?showtopic=51225
    I hate this...
    Title: Re: Strange MBAM detections again...
    Post by: YoKenny on May 25, 2010, 07:32:25 PM
    You posted Yesterday, 08:50 PM (forum time) and expect a quick response. ???

    Do you have MBAM full?

    If you do then contact support(@)malwarebytes.org by email and they will help you.
    Title: Re: Strange MBAM detections again...
    Post by: Lisandro on May 25, 2010, 07:53:36 PM
    You posted Yesterday, 08:50 PM (forum time) and expect a quick response. ???
    Define "quick"... The problem was posted three days ago...

    Do you have MBAM full?
    No. But I suppose forum is for free support, isn't it?

    If you do then contact support(@)malwarebytes.org by email and they will help you.
    No need, seems the staff is following the thread, slowly, but it's there.
    Title: Re: Strange MBAM detections again...
    Post by: Lisandro on May 27, 2010, 10:43:55 PM
    Long lags into support...
    Seems the voice of Internet is correct: MBAM is a good program but the support is horrible or very weak.
    http://forums.malwarebytes.org/index.php?showtopic=51225
    Title: Re: Strange MBAM detections again...
    Post by: essexboy on May 27, 2010, 11:09:09 PM
    Looks like you found another bug there Tech, looking at your posts anyway 
    Title: Re: Strange MBAM detections again...
    Post by: Lisandro on May 27, 2010, 11:16:00 PM
    Looks like you found another bug there Tech, looking at your posts anyway 
    I can't believe I'm alone on this... What does my machine have so special? ???
    Title: Re: Strange MBAM detections again...
    Post by: Marc57 on May 28, 2010, 06:03:14 AM
    Tech, Does this help?  I found this by doing a search for F.exe.

    http://www.prevx.com/filenames/X8616758784404325-X1/F.EXE.html

    http://www.threatexpert.com/files/f.exe.html

    http://www.file.net/process/f.exe.html


    Here's someone else with a similar problem and maybe a fix.

    http://www.bleepingcomputer.com/forums/topic236537.html

    Title: Re: Strange MBAM detections again...
    Post by: Lisandro on May 28, 2010, 01:53:48 PM
    Thanks Marc. Let me comment:

    http://www.prevx.com/filenames/X8616758784404325-X1/F.EXE.html
    The hash of the file is fundamental (MD5). Different files have the same name and the opposite. So I don't think my f.exe file (that does not exist...) is the same as the Prevx one.
    http://www.threatexpert.com/files/f.exe.html
    The same.

    http://www.file.net/process/f.exe.html
    Can't find anything useful...

    http://www.bleepingcomputer.com/forums/topic236537.html
    Topic was closed. Not that much helpful. Besides I had send all the logs to Essexboy for analysis.
    No further help on the MBAM forum. I'm waiting.
    Title: Re: Strange MBAM detections again...
    Post by: Marc57 on May 29, 2010, 12:07:47 AM
    I was hoping that post # 3 might help you get rid of it.

    http://www.bleepingcomputer.com/forums/topic236537.html
    Title: Re: Strange MBAM detections again...
    Post by: Lisandro on May 29, 2010, 12:57:30 AM
    Marc, I've tested: the file does not exist (it should be c:\f.exe) and the prefetch folder does not have any f.exe file related.
    I'm running another MBAM scanning with an old partition backup restored and trying...
    Title: Re: Strange MBAM detections again...
    Post by: Lisandro on May 29, 2010, 01:03:23 AM
    Scanning finished. The file is found. Something is weird in my computer and MBAM.
    Title: Re: Strange MBAM detections again...
    Post by: Marc57 on May 29, 2010, 01:08:19 AM
    Sorry I couldn't help Tech.
    Title: Re: Strange MBAM detections again...
    Post by: DavidR on May 29, 2010, 01:15:40 AM
    What happens if you are able to access that drive outside windows, using a Linux live CD, etc. can that find anything ?

    Title: Re: Strange MBAM detections again...
    Post by: Lisandro on May 29, 2010, 02:57:28 AM
    What happens if you are able to access that drive outside windows, using a Linux live CD, etc. can that find anything ?
    Good shot. I'll try.
    Title: Re: Strange MBAM detections again...
    Post by: DavidR on May 29, 2010, 03:27:39 AM
    Hopefully that will work if it exists and is hidden when windows is running.