ilanzak Posted July 13, 2010 ID:283522 Share Posted July 13, 2010 Hi,The Malwarebytes software identifies Oberon GamesBar as an Adware. This is a false positive.The GamesBar is a legitiamte browser add on (toolbar) which is distributed with Oberon's game downloads which users explicitly select to install from the biggest game sites on the network that Oberon Media operates like MSN zone, Pogo, AT&T etc...Check the games on http://download-games.pogo.com/ or http://www.iplay.com/index.aspx.Thanks,Ilanmbam_log_2010_07_13__16_46_44_.txt Link to post Share on other sites More sharing options...
Staff TeMerc Posted July 13, 2010 Staff ID:283593 Share Posted July 13, 2010 Hello, please update your database, you're way behind, current database is 4309. Then run another developers log Link to post Share on other sites More sharing options...
ilanzak Posted July 14, 2010 Author ID:284085 Share Posted July 14, 2010 Hello, please update your database, you're way behind, current database is 4309. Then run another developers logPlease see attached an updated log after I updated my database to 4312. Link to post Share on other sites More sharing options...
ilanzak Posted July 14, 2010 Author ID:284086 Share Posted July 14, 2010 Failed to attache. Re-trying.mbam_log_2010_07_14__13_32_06_.txt Link to post Share on other sites More sharing options...
nosirrah Posted July 14, 2010 ID:284088 Share Posted July 14, 2010 It would expedite things if you could also zip and attach an actual copy of the dll. Link to post Share on other sites More sharing options...
ilanzak Posted July 14, 2010 Author ID:284101 Share Posted July 14, 2010 Attached another developer log.mbam_log_2010_07_14__14_03_16_.txt Link to post Share on other sites More sharing options...
nosirrah Posted July 14, 2010 ID:284118 Share Posted July 14, 2010 oberontb.dll <- zip and attach this file, I do not need another scan log. Link to post Share on other sites More sharing options...
nosirrah Posted July 14, 2010 ID:284121 Share Posted July 14, 2010 There is something odd in your scan log as well. The reason this dll is detected has either been edited out or many objects have been set to ignore. Here is what you should be seeing:Memory Modules Infected:C:\Program Files\GamesBar\oberontb.dll (Adware.Gamesbar) -> Delete on reboot.Registry Keys Infected:HKEY_CLASSES_ROOT\oberontb.band (Adware.Gamesbar) -> Quarantined and deleted successfully.HKEY_CLASSES_ROOT\TypeLib\{ad76633e-e50d-4844-9e7f-4dfbc7c18467} (Adware.Gamesbar) -> Quarantined and deleted successfully.HKEY_CLASSES_ROOT\Interface\{daa37aad-f156-4c2c-ac48-3c22ef92ae2f} (Adware.Gamesbar) -> Quarantined and deleted successfully.HKEY_CLASSES_ROOT\Interface\{ec1a2105-5621-440f-987d-27ef428131d9} (Adware.Gamesbar) -> Quarantined and deleted successfully.HKEY_CLASSES_ROOT\CLSID\{6f282b65-56bf-4bd1-a8b2-a4449a05863d} (Adware.Gamesbar) -> Quarantined and deleted successfully.HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{6f282b65-56bf-4bd1-a8b2-a4449a05863d} (Adware.Gamesbar) -> Quarantined and deleted successfully.HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{6f282b65-56bf-4bd1-a8b2-a4449a05863d} (Adware.Gamesbar) -> Quarantined and deleted successfully.HKEY_CLASSES_ROOT\CLSID\{cb0d163c-e9f4-4236-9496-0597e24b23a5} (Adware.Gamesbar) -> Quarantined and deleted successfully.HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{cb0d163c-e9f4-4236-9496-0597e24b23a5} (Adware.Gamesbar) -> Quarantined and deleted successfully.HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{cb0d163c-e9f4-4236-9496-0597e24b23a5} (Adware.Gamesbar) -> Quarantined and deleted successfully.HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{cb0d163c-e9f4-4236-9496-0597e24b23a5} (Adware.Gamesbar) -> Quarantined and deleted successfully.HKEY_CLASSES_ROOT\oberontb.band.1 (Adware.Gamesbar) -> Quarantined and deleted successfully.HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1a93c934-025b-4c3a-b38e-9654a7003239} (Adware.Gamesbar) -> Quarantined and deleted successfully.Registry Values Infected:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{6f282b65-56bf-4bd1-a8b2-a4449a05863d} (Adware.Gamesbar) -> Quarantined and deleted successfully.Registry Data Items Infected:(No malicious items detected)Folders Infected:(No malicious items detected)Files Infected:C:\Program Files\GamesBar\oberontb.dll (Adware.Gamesbar) -> Delete on reboot.HKEY_CLASSES_ROOT\CLSID\{6f282b65-56bf-4bd1-a8b2-a4449a05863d} <- this is the actual detection here according to your own developers log (once decoded) yet that line does not exist in the actual log. Link to post Share on other sites More sharing options...
ilanzak Posted July 14, 2010 Author ID:284340 Share Posted July 14, 2010 There is something odd in your scan log as well. The reason this dll is detected has either been edited out or many objects have been set to ignore. Here is what you should be seeing:Memory Modules Infected:C:\Program Files\GamesBar\oberontb.dll (Adware.Gamesbar) -> Delete on reboot.Registry Keys Infected:HKEY_CLASSES_ROOT\oberontb.band (Adware.Gamesbar) -> Quarantined and deleted successfully.HKEY_CLASSES_ROOT\TypeLib\{ad76633e-e50d-4844-9e7f-4dfbc7c18467} (Adware.Gamesbar) -> Quarantined and deleted successfully.HKEY_CLASSES_ROOT\Interface\{daa37aad-f156-4c2c-ac48-3c22ef92ae2f} (Adware.Gamesbar) -> Quarantined and deleted successfully.HKEY_CLASSES_ROOT\Interface\{ec1a2105-5621-440f-987d-27ef428131d9} (Adware.Gamesbar) -> Quarantined and deleted successfully.HKEY_CLASSES_ROOT\CLSID\{6f282b65-56bf-4bd1-a8b2-a4449a05863d} (Adware.Gamesbar) -> Quarantined and deleted successfully.HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{6f282b65-56bf-4bd1-a8b2-a4449a05863d} (Adware.Gamesbar) -> Quarantined and deleted successfully.HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{6f282b65-56bf-4bd1-a8b2-a4449a05863d} (Adware.Gamesbar) -> Quarantined and deleted successfully.HKEY_CLASSES_ROOT\CLSID\{cb0d163c-e9f4-4236-9496-0597e24b23a5} (Adware.Gamesbar) -> Quarantined and deleted successfully.HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{cb0d163c-e9f4-4236-9496-0597e24b23a5} (Adware.Gamesbar) -> Quarantined and deleted successfully.HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{cb0d163c-e9f4-4236-9496-0597e24b23a5} (Adware.Gamesbar) -> Quarantined and deleted successfully.HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{cb0d163c-e9f4-4236-9496-0597e24b23a5} (Adware.Gamesbar) -> Quarantined and deleted successfully.HKEY_CLASSES_ROOT\oberontb.band.1 (Adware.Gamesbar) -> Quarantined and deleted successfully.HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1a93c934-025b-4c3a-b38e-9654a7003239} (Adware.Gamesbar) -> Quarantined and deleted successfully.Registry Values Infected:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{6f282b65-56bf-4bd1-a8b2-a4449a05863d} (Adware.Gamesbar) -> Quarantined and deleted successfully.Registry Data Items Infected:(No malicious items detected)Folders Infected:(No malicious items detected)Files Infected:C:\Program Files\GamesBar\oberontb.dll (Adware.Gamesbar) -> Delete on reboot.HKEY_CLASSES_ROOT\CLSID\{6f282b65-56bf-4bd1-a8b2-a4449a05863d} <- this is the actual detection here according to your own developers log (once decoded) yet that line does not exist in the actual log.DLL file attached.I used the scanner with default settings and performed a quick scan so I'm not sure why the log is different than expected. I sent the log file as is, and didn't edit out anything.oberontb.zip Link to post Share on other sites More sharing options...
Fatdcuk Posted July 14, 2010 ID:284358 Share Posted July 14, 2010 Hi,I have just registered the attached .dll and ran a quickscan.This is my output log from the quick test Malwarebytes' Anti-Malware 1.46www.malwarebytes.orgDatabase version: 4314Windows 5.1.2600 Service Pack 3Internet Explorer 6.0.2900.551214/07/2010 21:36:09mbam-log-2010-07-14 (21-36-09).txtScan type: Quick scanObjects scanned: 114455Time elapsed: 1 minute(s), 8 second(s)Memory Processes Infected: 0Memory Modules Infected: 0Registry Keys Infected: 10Registry Values Infected: 1Registry Data Items Infected: 0Folders Infected: 0Files Infected: 1Memory Processes Infected:(No malicious items detected)Memory Modules Infected:(No malicious items detected)Registry Keys Infected:HKEY_CLASSES_ROOT\oberontb.band (Adware.Gamesbar) -> Quarantined and deleted successfully.HKEY_CLASSES_ROOT\TypeLib\{ad76633e-e50d-4844-9e7f-4dfbc7c18467} (Adware.Gamesbar) -> Quarantined and deleted successfully.HKEY_CLASSES_ROOT\Interface\{73129582-1d7a-4c50-a0d5-587ed7755199} (Adware.Gamesbar) -> Quarantined and deleted successfully.HKEY_CLASSES_ROOT\Interface\{daa37aad-f156-4c2c-ac48-3c22ef92ae2f} (Adware.Gamesbar) -> Quarantined and deleted successfully.HKEY_CLASSES_ROOT\CLSID\{6f282b65-56bf-4bd1-a8b2-a4449a05863d} (Adware.Gamesbar) -> Quarantined and deleted successfully.HKEY_CLASSES_ROOT\CLSID\{85790a84-d74d-49b3-b3f5-0b1ff7b11f9c} (Adware.Gamesbar) -> Quarantined and deleted successfully.HKEY_CLASSES_ROOT\CLSID\{cb0d163c-e9f4-4236-9496-0597e24b23a5} (Adware.Gamesbar) -> Quarantined and deleted successfully.HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{cb0d163c-e9f4-4236-9496-0597e24b23a5} (Adware.Gamesbar) -> Quarantined and deleted successfully.HKEY_CLASSES_ROOT\oberontb.band.1 (Adware.Gamesbar) -> Quarantined and deleted successfully.HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{1a93c934-025b-4c3a-b38e-9654a7003239} (Adware.Gamesbar) -> Quarantined and deleted successfully.Registry Values Infected:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{6f282b65-56bf-4bd1-a8b2-a4449a05863d} (Adware.Gamesbar) -> Quarantined and deleted successfully.Registry Data Items Infected:(No malicious items detected)Folders Infected:(No malicious items detected)Files Infected:C:\Documents and Settings\User\My Documents\Malware Samples\oberontb.dll (Adware.Gamesbar) -> Quarantined and deleted successfully. Link to post Share on other sites More sharing options...
ilanzak Posted July 14, 2010 Author ID:284365 Share Posted July 14, 2010 Hi,I have just registered the attached .dll and ran a quickscan.This is my output log from the quick test Malwarebytes' Anti-Malware 1.46www.malwarebytes.orgDatabase version: 4314Windows 5.1.2600 Service Pack 3Internet Explorer 6.0.2900.551214/07/2010 21:36:09mbam-log-2010-07-14 (21-36-09).txtScan type: Quick scanObjects scanned: 114455Time elapsed: 1 minute(s), 8 second(s)Memory Processes Infected: 0Memory Modules Infected: 0Registry Keys Infected: 10Registry Values Infected: 1Registry Data Items Infected: 0Folders Infected: 0Files Infected: 1Memory Processes Infected:(No malicious items detected)Memory Modules Infected:(No malicious items detected)Registry Keys Infected:HKEY_CLASSES_ROOT\oberontb.band (Adware.Gamesbar) -> Quarantined and deleted successfully.HKEY_CLASSES_ROOT\TypeLib\{ad76633e-e50d-4844-9e7f-4dfbc7c18467} (Adware.Gamesbar) -> Quarantined and deleted successfully.HKEY_CLASSES_ROOT\Interface\{73129582-1d7a-4c50-a0d5-587ed7755199} (Adware.Gamesbar) -> Quarantined and deleted successfully.HKEY_CLASSES_ROOT\Interface\{daa37aad-f156-4c2c-ac48-3c22ef92ae2f} (Adware.Gamesbar) -> Quarantined and deleted successfully.HKEY_CLASSES_ROOT\CLSID\{6f282b65-56bf-4bd1-a8b2-a4449a05863d} (Adware.Gamesbar) -> Quarantined and deleted successfully.HKEY_CLASSES_ROOT\CLSID\{85790a84-d74d-49b3-b3f5-0b1ff7b11f9c} (Adware.Gamesbar) -> Quarantined and deleted successfully.HKEY_CLASSES_ROOT\CLSID\{cb0d163c-e9f4-4236-9496-0597e24b23a5} (Adware.Gamesbar) -> Quarantined and deleted successfully.HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{cb0d163c-e9f4-4236-9496-0597e24b23a5} (Adware.Gamesbar) -> Quarantined and deleted successfully.HKEY_CLASSES_ROOT\oberontb.band.1 (Adware.Gamesbar) -> Quarantined and deleted successfully.HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{1a93c934-025b-4c3a-b38e-9654a7003239} (Adware.Gamesbar) -> Quarantined and deleted successfully.Registry Values Infected:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{6f282b65-56bf-4bd1-a8b2-a4449a05863d} (Adware.Gamesbar) -> Quarantined and deleted successfully.Registry Data Items Infected:(No malicious items detected)Folders Infected:(No malicious items detected)Files Infected:C:\Documents and Settings\User\My Documents\Malware Samples\oberontb.dll (Adware.Gamesbar) -> Quarantined and deleted successfully.The question still remains - why does the software identifies this dll as adware and what are the next steps to resolution? Link to post Share on other sites More sharing options...
nosirrah Posted July 14, 2010 ID:284391 Share Posted July 14, 2010 It does not identify the attached file as adware though. The detection is far more involved and unrelated to the file alone. Until we resolve why only the file is being detected on your system (and the developers log shows that more was detected yet is missing) we cant proceed.Are you 100% sure that you did not set much of this detection to ignore? That is the only thing that explains this aside from the log being modified. Link to post Share on other sites More sharing options...
ilanzak Posted July 15, 2010 Author ID:284634 Share Posted July 15, 2010 I run the scanner on another machine and now there are many more Adware.Gamesbar infections. Hope this helps to resovle the issue.mbam_log_2010_07_15__14_02_11_.txt Link to post Share on other sites More sharing options...
ilanzak Posted July 18, 2010 Author ID:286007 Share Posted July 18, 2010 Hi,Did you have the chance to review the latest log I sent?Ilan Link to post Share on other sites More sharing options...
nosirrah Posted July 18, 2010 ID:286385 Share Posted July 18, 2010 After the next update let me know if this is still detected. Link to post Share on other sites More sharing options...
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now