Jump to content

Is this a false positve?


Recommended Posts

Below is a log of the scan I ran a few minutes ago. Is this a false positive?

I looked up this file in my system 32 directory and the file is dated 8/9/04.

Malwarebytes' Anti-Malware 1.41

Database version: 2912

Windows 5.1.2600 Service Pack 3

10/5/2009 5:04:45 PM

mbam-log-2009-10-05 (17-04-41).txt

Scan type: Quick Scan

Objects scanned: 111480

Time elapsed: 12 minute(s), 2 second(s)

Memory Processes Infected: 0

Memory Modules Infected: 0

Registry Keys Infected: 0

Registry Values Infected: 0

Registry Data Items Infected: 0

Folders Infected: 0

Files Infected: 1

Memory Processes Infected:

(No malicious items detected)

Memory Modules Infected:

(No malicious items detected)

Registry Keys Infected:

(No malicious items detected)

Registry Values Infected:

(No malicious items detected)

Registry Data Items Infected:

(No malicious items detected)

Folders Infected:

(No malicious items detected)

Files Infected:

C:\WINDOWS\system32\ufat.dll (Spyware.Zbot) -> No action taken.

Thank you,

Blue 452

XP, SP3

IE 8

NIS 2009

Link to post
Share on other sites

Hello,

1) Yes, MBAM stated that my PC is infected with Spyware.Zbot. This morning, I scanned and it was clean, but now infected after update. :)

Window XP

Norton 360 V3, Firewall

Keyscrambler (Free)

SAS on demand (Free)

MBAM on demand (Free)

Spywareblaster (Free)

CCleaner (Free)

2) However, my Vista PC is clean. In addition, I scan both PC twice a day and sometimes more. :)

Vista

Norton 360 V3, Firewall

SAS on demand (Free)

MBAM on demand (Free)

Spywareblaster (Free)

CCleaner (Free)

Sanboxie (Free)

Window Defender

Link to post
Share on other sites

Hi Team

Same also this morning WA Australia time ... file ufat.dll triggered no response from Spybot SD, Norton 360 or Windows Malicious Software Removal Tool (Sept 2009).

Please clarify ... it seems to be a legit Microsft file looking at its properties.

Perth 2008

Link to post
Share on other sites

Malwarebytes' Anti-Malware 1.41

Database version: 2912

Windows 5.1.2600 Service Pack 3

10/5/2009 11:36:58 PM

mbam-log-2009-10-05 (23-36-47).txt

Scan type: Quick Scan

Objects scanned: 96300

Time elapsed: 2 minute(s), 13 second(s)

Memory Processes Infected: 0

Memory Modules Infected: 0

Registry Keys Infected: 0

Registry Values Infected: 0

Registry Data Items Infected: 0

Folders Infected: 0

Files Infected: 1

Memory Processes Infected:

(No malicious items detected)

Memory Modules Infected:

(No malicious items detected)

Registry Keys Infected:

(No malicious items detected)

Registry Values Infected:

(No malicious items detected)

Registry Data Items Infected:

(No malicious items detected)

Folders Infected:

(No malicious items detected)

Files Infected:

C:\WINDOWS\system32\ufat.dll (Spyware.Zbot) -> No action taken. [4948455830528190886683701559678085010707015538515242484730393445523801070701525

35142474052302425231823130121371717232617172320171724191717233917172420171723391

7

17232317172421171719171717212017172339171724191717241717172339171724191717231817

1

72421171723261717233917172338]

Link to post
Share on other sites

Same here: these three infections showed up both on my Dell Inspiron and the HP Mini after updating to database version 2912.

Malwarebytes' Anti-Malware 1.41

Database version: 2912

Windows 5.1.2600 Service Pack 3

6/10/2009 5:36:14

mbam-log-2009-10-06 (05-36-09).txt

Scan type: Quick Scan

Objects scanned: 113090

Time elapsed: 7 minute(s), 3 second(s)

Memory Processes Infected: 0

Memory Modules Infected: 0

Registry Keys Infected: 1

Registry Values Infected: 0

Registry Data Items Infected: 0

Folders Infected: 0

Files Infected: 2

Memory Processes Infected:

(No malicious items detected)

Memory Modules Infected:

(No malicious items detected)

Registry Keys Infected:

HKEY_CLASSES_ROOT\CLSID\{d2923b86-15f1-46ff-a19a-de825f919576} (Spyware.Zbot) -> No action taken. [4948455830528190886683701559678085010707015538515242484730393445523801070701525

35142474052302425231823130121371717232617172320171724191717233917172420171723391

7

17232317172421171719171717212017172339171724191717241717172339171724191717231817

1

72421171723261717233917172338]

Registry Values Infected:

(No malicious items detected)

Registry Data Items Infected:

(No malicious items detected)

Folders Infected:

(No malicious items detected)

Files Infected:

C:\WINDOWS\system32\fsusd.dll (Spyware.Zbot) -> No action taken. [4948455830528190886683701559678085010707015538515242484730393445523801070701525

35142474052302425231823130121371717232617172320171724191717233917172420171723391

7

17232317172421171719171717212017172339171724191717241717172339171724191717231817

1

72421171723261717233917172338]

C:\WINDOWS\system32\ufat.dll (Spyware.Zbot) -> No action taken. [4948455830528190886683701559678085010707015538515242484730393445523801070701525

35142474052302425231823130121371717232617172320171724191717233917172420171723391

7

17232317172421171719171717212017172339171724191717241717172339171724191717231817

1

72421171723261717233917172338]

Thank you very much for looking into this.

Link to post
Share on other sites

Nosirrah,

All clear, thanks. :)

Malwarebytes' Anti-Malware 1.41

Database version: 2914

Windows 5.1.2600 Service Pack 3

10/5/2009 9:04:05 PM

mbam-log-2009-10-05 (21-04-05).txt

Scan type: Quick Scan

Objects scanned: 113747

Time elapsed: 7 minute(s), 5 second(s)

Memory Processes Infected: 0

Memory Modules Infected: 0

Registry Keys Infected: 0

Registry Values Infected: 0

Registry Data Items Infected: 0

Folders Infected: 0

Files Infected: 0

Memory Processes Infected:

(No malicious items detected)

Memory Modules Infected:

(No malicious items detected)

Registry Keys Infected:

(No malicious items detected)

Registry Values Infected:

(No malicious items detected)

Registry Data Items Infected:

(No malicious items detected)

Folders Infected:

(No malicious items detected)

Files Infected:

(No malicious items detected)

Link to post
Share on other sites

I scanned yesterday and got the follwing positive result. IS any of this false?

Files Infected:

C:\Program Files\MSN Gaming Zone\Windows\bckg.dll (Spyware.Zbot) -> Quarantined and deleted successfully.

C:\System Volume Information\_restore{509E7F66-165C-4C09-9193-02CFFDF8C048}\RP17\A0002906.dll (Spyware.Zbot) -> Quarantined and deleted successfully

C:\WINDOWS\system32\ufat.dll (Spyware.Zbot) -> Quarantined and deleted successfully.

C:\WINDOWS\system32\dllcache\bckg.dll (Spyware.Zbot) -> Quarantined and deleted successfully.

C:\WINDOWS\system32\dllcache\voicesub.dll (Spyware.Zbot) -> Quarantined and deleted successfully.

C:\WINDOWS\system32\dllcache\ufat.dll (Spyware.Zbot) -> Quarantined and deleted successfully.

C:\WINDOWS\ServicePackFiles\i386\lang\voicesub.dll (Spyware.Zbot) -> Quarantined and deleted successfully.

C:\WINDOWS\$NtServicePackUninstall$\voicesub.dll (Spyware.Zbot) -> Quarantined and deleted successfully.

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    No registered users viewing this page.

Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.