Author Topic: Win32:FakeAlert-ABB [Trj] Steam.exe FP?  (Read 3126 times)

0 Members and 1 Guest are viewing this topic.

T961

  • Guest
Win32:FakeAlert-ABB [Trj] Steam.exe FP?
« on: May 30, 2011, 11:09:23 AM »
Avast is picking up a virus in:

Process 1784 [steam.exe], memory block 0x000000000400000, block size 1269160 (Steam.exe)
Threat: Win32:FakeAlert-AAB[Trj]

Program version: 6.0.1125
Virus definitions: 110530-0

I'm guessing this is another FP like the one's we have seen before?

SafeSurf

  • Guest
Re: Win32:FakeAlert-ABB [Trj] Steam.exe FP?
« Reply #1 on: May 30, 2011, 11:14:26 AM »
Do you have MBAM (Malwarebytes) on your machine?  If so, update first and run a scan.  If you do not have it:

Check your computer for malware with Malwarebytes’ Anti-Malware (MBAM).
·   Download free http://www.malwarebytes.org/ (the blue button) for an on-demand scanner.
·   Double Click mbam-setup.exe to install the application.
·   After install, click update so you have latest database before scanning.
·   Under Settings:
o   General: Automatically Save File After Scan Completes is checked off
o   Scanner SettingsCheck all boxes
o   Updater: Download and install update if available is checked off
·   Once the program has loaded, select "Perform Quick Scan", then click Scan.
·   The scan may take some time to finish, so please be patient.
·   When the disinfection scan is complete, a log will appear in Notepad and you may be prompted to Restart. (See Extra Note).
·   Click the “remove selected” button to quarantine anything found.  You will find the infection details under the Quarantine tab.
·   The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
·   Copy & Paste the entire report in your next reply.

If the virus is in your Avast Chest, you can also upload it to Avast.

T961

  • Guest
Re: Win32:FakeAlert-ABB [Trj] Steam.exe FP?
« Reply #2 on: May 30, 2011, 12:00:10 PM »
Avast won't allow me to place the "virus" in the chest.

MBAM log:

Quote
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Database version: 6722

Windows 6.1.7600
Internet Explorer 9.0.8112.16421

30/05/2011 10:49:29
mbam-log-2011-05-30 (10-49-29).txt

Scan type: Full scan (C:\|D:\|)
Objects scanned: 418765
Time elapsed: 25 minute(s), 9 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)


T961

  • Guest
Re: Win32:FakeAlert-ABB [Trj] Steam.exe FP?
« Reply #3 on: May 30, 2011, 02:57:37 PM »
Checked my backup computer which doesn't have steam on it and isn't attached to the same network, Avast says it's clean.

I installed steam via the install from the official website as soon as it's installed and I do a fresh scan Avast picks up a virus.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37699
Re: Win32:FakeAlert-ABB [Trj] Steam.exe FP?
« Reply #4 on: May 30, 2011, 03:01:02 PM »
Quote
.......and I do a fresh scan Avast picks up a virus......
Quote
Process 1784 [steam.exe], memory block 0x000000000400000, block size 1269160 (Steam.exe)
what type of scan is this....is it a custom scan where you have selected "Scan memory"



if you search the forum for  "steam.exe"  you will find more
here is one  http://forum.avast.com/index.php?topic=49186.0
« Last Edit: May 30, 2011, 03:16:31 PM by Pondus »

T961

  • Guest
Re: Win32:FakeAlert-ABB [Trj] Steam.exe FP?
« Reply #5 on: May 30, 2011, 03:29:22 PM »
Quote
Process 1784 [steam.exe], memory block 0x000000000400000, block size 1269160 (Steam.exe)
what type of scan is this....is it a custom scan where you have selected "Scan memory"

Yes it's a custom scan of the memory

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37699
Re: Win32:FakeAlert-ABB [Trj] Steam.exe FP?
« Reply #6 on: May 30, 2011, 03:33:53 PM »
That setting often give some mysterious results, usually it is malware signaturs from other security programs installed that is detected
so why it detect this i do not know

If you run the normal quick/full scan with default settings, any detection then?


have you tested the steam.exe file at   www.virustotal.com
« Last Edit: May 30, 2011, 03:38:08 PM by Pondus »

T961

  • Guest
Re: Win32:FakeAlert-ABB [Trj] Steam.exe FP?
« Reply #7 on: May 30, 2011, 04:03:17 PM »
Quick scan and Full Scan doesn't detect anything and VirusTotal scan on the Steam.exe also doesn't find anything.

Online DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89680
  • No support PMs thanks
Re: Win32:FakeAlert-ABB [Trj] Steam.exe FP?
« Reply #8 on: May 30, 2011, 04:17:20 PM »
That is because the memory scan incorporated into the Quick and Full scans doesn't go into the same depth/sensitivity.

Personally I haven't seen a reason to run a custom scan when the Quick and Full pre-defined scans should be adequate. But if doing a custom scan I wouldn't select the memory scan.

- With a resident on-access antivirus like avast, the need for frequent on-demand scans is much depreciated. For the most part the on-demand scan is going to be scanning files that would be otherwise be dormant or inert. If they were active files then the on-access file system shield would be scanning them before being created, modified, opened or executed.

I have avast set to do a scheduled weekly Quick scan, set at a time and day that I know the computer will be on.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD - 27" external monitor 1440p 2560x1440 resolution - avast! free  24.9.6130 (build 24.9.9452.762) UI 1.0.818/ Firefox, uBlock Origin Lite, uMatrix/ MailWasher Pro/ Avast! Mobile Security