Author Topic: Real malware or just a false positive..  (Read 2085 times)

0 Members and 1 Guest are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34063
  • malware fighter
Real malware or just a false positive..
« on: June 20, 2011, 08:08:39 PM »
Have this file for ages (since June of 2006) and now on Vista. Did a scan with the latest version of DrWeb CureIt and that scanner found this executable to be ewido_micro.exe infected with Trojan.DownLoad2.8659.....
Uploaded the file to Anubis, see results here: http://anubis.iseclab.org/?action=result&task_id=167596889528f9484bd706ce54cf5b989&format=html
Submitted already to VT MD5:   e82b923d6d2ac34b611d2f410b159a7d
Date first seen:   2009-02-20 05:58:38 (UTC)
Date last seen:   2011-06-05 14:42:28 (UTC)
Detection ratio:   25/43
Re-analyzed at VT: http://www.virustotal.com/file-scan/report.html?id=921a5e8b7c4a53ad9e8d97295cdf9e7e3266abfe212edd825bc415128f0b4f57-1308591206
and at jotti's: http://virusscan.jotti.org/nl/scanresult/f567e85514c90b2531b65c389acc17bdc7c6c0c4
&
http://2.virscan.org/report/8ad53f5492f79bfab994e1393fa99ce1.html
&
http://www.filterbit.com/results.cgi?uid=uou2ypfz2ufeqpwmccf9mxyen1lml0g6

Is avast right by not detecting it or is this really malware/spyware?
MBAM and SAS find the file to be secure,
Here I get two flags: http://www.garyshood.com/virus/results.php?r=e82b923d6d2ac34b611d2f410b159a7d
F-prot finds a security risk and AntiVir
ALERT: [TR/Dldr.Genome.ooc] ewido_micro.exe
 Is the Trojan horse TR/Dldr.Genome.ooc

polonus
« Last Edit: June 20, 2011, 08:31:42 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37699
Re: Real malware or just a false positive..
« Reply #1 on: June 20, 2011, 10:09:40 PM »
Quote
MBAM and SAS find the file to be secure,
The reason for why Malwarebytes does not detect is probably....they want fresh samples, not older then 3 months

and the VT scan here say: First seen: 2009-02-20 05:58:38

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34063
  • malware fighter
Re: Real malware or just a false positive..
« Reply #2 on: June 20, 2011, 10:15:07 PM »
Hi Pondus,

I think I will remove the executable. Also have set my zonemap setting stricter via MicroSoft FixIt Center. e.g. improve performance, safety and security with IE-fix. As this was affected here, so the fix had prevention of data export restored,

polonus
« Last Edit: June 21, 2011, 12:01:21 AM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37699
Re: Real malware or just a false positive..
« Reply #3 on: June 21, 2011, 09:59:17 AM »
NORMAN lab

Quote
Yes this file is a malware and we are detecting it as 'W32/Suspicious_Gen2.MXNIU'.

Offline Milos

  • Avast team
  • Super Poster
  • *
  • Posts: 2295
Re: Real malware or just a false positive..
« Reply #4 on: June 21, 2011, 01:40:27 PM »
Hello,
it looks, that it is some old digitally signed file from "ewido networks GmbH & Co. KG" which belongs to "ewido anti-malware", the certificate has expired in 03/07/2007. I think it's clean.

Milos

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34063
  • malware fighter
Re: Real malware or just a false positive..
« Reply #5 on: June 21, 2011, 03:43:41 PM »
Hi Milos,

Thanks, reason also at a re-scan the apparent virusnames vary all the time, see:
http://virscan.org/report/da20654126e8d63850b2b84b1e548109.html

I attached the authenticode data I got with Filealyzer

polonus
« Last Edit: June 21, 2011, 06:52:14 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34063
  • malware fighter
Re: Real malware or just a false positive..
« Reply #6 on: June 23, 2011, 10:19:26 PM »
But with this file a we should be careful as this was pointed out to me by our forum friend, Pondus, who had that particular file analyzed at Norman's and got these specifics, I quote:
Quote
At 2011-6-23 9:18:53, len wrote:
Greetings,

We have sandbox detection of this file as suspicious(downloading activity). Although  it seems to be  a part of Ewido antimalware(Now acquired by avg)  but it has expired certificate and can be easily modified for malicious purpose. Also, this file has characteristic to download some file form ewido website. Generally security software have websites name in encrypted form but this file has in plain text that can be modified easily to download some other files.
Note: I have added this file to my track list.

Regards  

Additionally I add this specific scan with the same MD5 hash, but a complete different file name re:
File Name :     430D5A2E.E7F
File Size :     134496 byte
File Type :     PE32 executable for MS Windows (GUI) Intel 80386 32-bit
MD5 :     e82b923d6d2ac34b611d2f410b159a7d
SHA1 :     dd50332945c62e8f0cd9bc610446be27329c795f

Could that be the malicious counterpart of the original ewido executable?

polonus
« Last Edit: June 23, 2011, 10:21:20 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!