MSFN Forum: MSFN has viruses? - MSFN Forum

Jump to content


Think before posting!

If your post is even remotely technical in nature, it probably doesn't belong here. Take another look at the forums and try to find the *right* location before posting a technical question here.
Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

MSFN has viruses? Update - likely incorrect, more analysis needed

#1 User is offline   Glen Saunders 

  • Newbie
  • Group: Members
  • Posts: 13
  • Joined: 12-January 10

  Posted 12 January 2010 - 11:45 AM

MSFN has tracking cookies, they where placed here by the owners of the site.

General Info
Web Site Location United States of America

Norton Safe Web has analyzed msfn.org for safety and security problems. Below is a sample of the threats that were found.

msfn.org

Threat Report

Total threats found: 1



Threats found: 1

Here is a complete list:
Threat Name: Infostealer
Location: http://unattended.ms...ed/bbucolor.exe <--- (Read the url)


#2 User is offline   DigeratiPrime 

  • MSFN Junkie
  • Group: Patrons
  • Posts: 3,490
  • Joined: 18-August 04
  • OS:Windows 7 x64
  • Country: Country Flag

Posted 12 January 2010 - 12:11 PM

Nice find MSE detects it as PWS:Win32/Inido!rts

We'll fix it...

Quote

Category: Password Stealer

Description: This program is dangerous and captures user passwords.

Recommendation: Permit this detected item only if you trust the program or the software publisher.

Microsoft Security Essentials detected programs that may compromise your privacy or damage your computer. You can still access the files that these programs use without removing them (not recommended). To access these files, select the 'Allow' action and click 'Apply actions'. If this option is not available, log on as administrator or ask the local administrator for help.

Items:
containerfile:E:\bbucolor.exe
file:E:\bbucolor.exe->(7zSfx)->BBU Color Changer.exe
filelocalcopy:C:\ProgramData\Microsoft\Microsoft Antimalware\LocalCopy\{346E1D8D-837B-45EF-B2CC-99DE30DA0DF4}-bbucolor.exe
webfile:C:\ProgramData\Microsoft\Microsoft Antimalware\LocalCopy\{346E1D8D-837B-45EF-B2CC-99DE30DA0DF4}-bbucolor.exe|http://unattended.msfn.org/files/advanced/bbucolor.exe
webfile:E:\bbucolor.exe|http://unattended.msfn.org/files/advanced/bbucolor.exe

Get more information about this item online.


#3 User is offline   Kelsenellenelvian 

  • WPI Guru
  • Group: Developers
  • Posts: 8,322
  • Joined: 18-September 03
  • OS:Windows 7 x64
  • Country: Country Flag

Posted 12 January 2010 - 12:15 PM

What?

All this time and I have had that on my drive?

Nod never detected it either.

I am very sorry to the OP. I never suspected that file as it came from a trusted source.

Edit: Nod detects it now as I try to move or delete it. I am glad I haven't used it for ages.

This post has been edited by Kelsenellenelvian: 12 January 2010 - 12:17 PM


#4 User is offline   Glen Saunders 

  • Newbie
  • Group: Members
  • Posts: 13
  • Joined: 12-January 10

Posted 12 January 2010 - 12:31 PM

I'm just glad I could warn you!

Glen

#5 User is offline   submix8c 

  • Inconceivable!
  • Group: Patrons
  • Posts: 3,236
  • Joined: 14-September 05
  • OS:none specified
  • Country: Country Flag

Posted 12 January 2010 - 12:39 PM

From here... (google) Appears that it still wouldn't fix your Colors anyway without modifying the checksum. Appears that no source code available.

Wups!

Alternative here (Kel's link)

This post has been edited by submix8c: 12 January 2010 - 12:42 PM


#6 User is offline   Sp0iLedBrAt 

  • MSFN Addict
  • Group: Supreme Sponsor
  • Posts: 1,710
  • Joined: 19-March 09
  • OS:XP Pro x86
  • Country: Country Flag

Posted 12 January 2010 - 01:03 PM

Ye ye ye..CabTool 1.8 is also recognized as a virus by NOD32, but it doesn't mean it is. I even reported it HERE. After you install it, with Antivirus OFF, it works just fine.

#7 User is offline   Tarun 

  • Area 5 Investigator
  • Group: Super Moderator
  • Posts: 3,080
  • Joined: 27-January 04
  • OS:Windows 7 x64
  • Country: Country Flag

Posted 12 January 2010 - 01:23 PM

24/41 - worry not, we'll get this fixed.

#8 User is offline   cluberti 

  • Gustatus similis pullus
  • Group: Supervisor
  • Posts: 11,208
  • Joined: 09-September 01
  • OS:Windows RT
  • Country: Country Flag

Posted 14 January 2010 - 06:52 PM

Note that the .exe in question was provided to AVG for analysis by a fellow moderator, and their response was that this was a false positive, for what it's worth, and detection of this would be fixed in the next signature update. I have updated the thread title to reflect this, and suggest anyone with antivirus software detecting this as a virus submit it to that A/V provider as well for deeper analysis.

#9 User is offline   xper 

  • Insane Clown
  • Group: Administrator
  • Posts: 15,633
  • Joined: 16-August 01
  • OS:Windows 7 x64
  • Country: Country Flag

Posted 25 February 2010 - 12:41 PM

I removed this file from server 3 weeks ago and yes symantec say it is on server. I love symantec ****.

Share this topic:


Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

2 User(s) are reading this topic
0 members, 2 guests, 0 anonymous users



All trademarks mentioned on this page are the property of their respective owners
Copyright © 2001 - 2013 msfn.org
Privacy Policy