Jump to content

everyone update


Recommended Posts

Updated from 141 to 148. Ran a quick scan:

Ok so I was testing the new rogue a few days ago. Ignore that. Well don't as it removed it.

Malwarebytes' Anti-Malware Version 0.68

Database version: 148

This logfile was saved before the removal process.

Scan type: Quick Scan

Objects scanned: 13562

Memory Processes Infected: 0

Memory Modules Infected: 0

Registry Keys Infected: 21

Registry Values Infected: 0

Registry Data Items Infected: 0

Folders Infected: 1

Files Infected: 4

Memory Processes Infected:

(No malicious items detected)

Memory Modules Infected:

(No malicious items detected)

Registry Keys Infected:

HKEY_CLASSES_ROOT\MSWinsock.Winsock (Backdoor.Bot) -> No action taken.

HKEY_CLASSES_ROOT\MSWinsock.Winsock.1 (Backdoor.Bot) -> No action taken.

HKEY_CLASSES_ROOT\CLSID\{248dd896-bb45-11cf-9abc-0080c7e7b78d} (Backdoor.Bot) -> No action taken.

HKEY_CLASSES_ROOT\Typelib\{af0c5cba-52e1-4b29-a2dc-58d91d599612} (Rogue.AntiVirGear) -> No action taken.

HKEY_CLASSES_ROOT\Interface\{418985ae-4fe4-448d-83ee-238c887d8fc2} (Rogue.AntiVirGear) -> No action taken.

HKEY_CLASSES_ROOT\Interface\{5f251303-f8c4-44c3-a7c2-9e8a93c59322} (Rogue.AntiVirGear) -> No action taken.

HKEY_CLASSES_ROOT\Interface\{61840430-c7cf-43a0-9d49-3b3ed563fed1} (Rogue.AntiVirGear) -> No action taken.

HKEY_CLASSES_ROOT\Interface\{64a8e3ca-ae17-4eb0-8c67-47d1103a5b6f} (Rogue.AntiVirGear) -> No action taken.

HKEY_CLASSES_ROOT\Interface\{765a8f7d-f57b-4601-a038-3f463a4d3193} (Rogue.AntiVirGear) -> No action taken.

HKEY_CLASSES_ROOT\Interface\{77e616d5-5db4-4b6a-8bda-2be4103a9921} (Rogue.AntiVirGear) -> No action taken.

HKEY_CLASSES_ROOT\Interface\{8742f319-c916-4930-b781-1c148134c05c} (Rogue.AntiVirGear) -> No action taken.

HKEY_CLASSES_ROOT\Interface\{897f5cb6-c1c1-494e-8f17-972784193442} (Rogue.AntiVirGear) -> No action taken.

HKEY_CLASSES_ROOT\Interface\{a2224c72-745e-4046-882f-1a48c9311d77} (Rogue.AntiVirGear) -> No action taken.

HKEY_CLASSES_ROOT\Interface\{aa500efc-3c92-44c9-b1d6-7a7033343a50} (Rogue.AntiVirGear) -> No action taken.

HKEY_CLASSES_ROOT\Interface\{ab5e9971-7086-4e6e-adfa-be9c685be68b} (Rogue.AntiVirGear) -> No action taken.

HKEY_CLASSES_ROOT\Interface\{ad7ca0bc-693a-4af9-b31a-60472248f761} (Rogue.AntiVirGear) -> No action taken.

HKEY_CLASSES_ROOT\Interface\{b2882cc2-0077-426b-916d-e0b9ea23a1b5} (Rogue.AntiVirGear) -> No action taken.

HKEY_CLASSES_ROOT\Interface\{ee241504-6f15-49e4-847f-b4d7da9ea8f9} (Rogue.AntiVirGear) -> No action taken.

HKEY_CLASSES_ROOT\Interface\{f1666e4e-45c8-462a-97ff-bfd5a103bffa} (Rogue.AntiVirGear) -> No action taken.

HKEY_CLASSES_ROOT\Interface\{fd9a05e8-4a1e-45e6-b3b6-37ce20140278} (Rogue.AntiVirGear) -> No action taken.

HKEY_CLASSES_ROOT\CLSID\{3bc3ac5b-3bbb-9dbe-8166-ec650e3b9b48} (Trojan.Zlob) -> No action taken.

Registry Values Infected:

(No malicious items detected)

Registry Data Items Infected:

(No malicious items detected)

Folders Infected:

C:\Program Files\AntiVirGear 3.7 (Rogue.AntiVirGear) -> No action taken.

Files Infected:

C:\WINDOWS\system32\MSWINSCK.ocx (Backdoor.Bot) -> No action taken.

C:\Program Files\AntiVirGear 3.7\AntiVirGear 3.7.exe (Rogue.AntiVirGear) -> No action taken.

C:\Program Files\AntiVirGear 3.7\ignored.lst (Rogue.AntiVirGear) -> No action taken.

C:\Program Files\AntiVirGear 3.7\vpp.ini (Rogue.AntiVirGear) -> No action taken.

Link to post
Share on other sites

I need a developers version log for all FPs . This will indicate where each detection comes from .

It looks like :

HKEY_CLASSES_ROOT\MSWinsock.Winsock

HKEY_CLASSES_ROOT\MSWinsock.Winsock.1

is listed as malware at multiple security sites but MSWINSCK.ocx is not .

I think it is just /developers from cmd line .

EDIT :

Also listed as legit at others . I hate it when they do that .

Get me a dev log and I will fix this .

Link to post
Share on other sites

Looking good running on XP Pro and scanning Vista.

Malwarebytes' Anti-Malware Version 0.68

Database version: 150

This logfile was saved before the removal process.

Scan type: Full Scan (C:\|D:\|)

Objects scanned: 114480

Memory Processes Infected: 0

Memory Modules Infected: 0

Registry Keys Infected: 0

Registry Values Infected: 0

Registry Data Items Infected: 0

Folders Infected: 0

Files Infected: 0

Memory Processes Infected:

(No malicious items detected)

Memory Modules Infected:

(No malicious items detected)

Registry Keys Infected:

(No malicious items detected)

Registry Values Infected:

(No malicious items detected)

Registry Data Items Infected:

(No malicious items detected)

Folders Infected:

(No malicious items detected)

Files Infected:

(No malicious items detected)

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.