MS Malicious Software Removal Tool

MS Malicious Software Removal Tool

Secure Home | Search | About
 Microsoft Antivirus Discussions    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
MS Malicious Software Removal Tool Keith Woolf 11-18-2006
Posted by Keith Woolf on November 18, 2006, 12:05 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Version 1.22 picks up C:\Program Files\Adobe\Adobe Help
Center\Browser\es262-32.dll as "a possible infection with
Backdoor:Win32/Hackdef.L".

The automatic Quick Scan from MS Update does not flag this file, only the
user initiated Enhanced Scan. Version 1.21 does not flag this file and two
independent virus scanners similarly do not flag it.

The file appears to be an unmodified 'genuine Adobe article'. Can anyone
confirm or deny that this is a False Positive?

Keith Woolf



Posted by David H. Lipman on November 18, 2006, 1:28 pm
If you were  Registered and logged in, you could reply and use other advanced thread options

| Version 1.22 picks up C:\Program Files\Adobe\Adobe Help
| Center\Browser\es262-32.dll as "a possible infection with
| Backdoor:Win32/Hackdef.L".
|
| The automatic Quick Scan from MS Update does not flag this file, only the
| user initiated Enhanced Scan. Version 1.21 does not flag this file and two
| independent virus scanners similarly do not flag it.
|
| The file appears to be an unmodified 'genuine Adobe article'. Can anyone
| confirm or deny that this is a False Positive?
|
| Keith Woolf
|

Please submit a sample of "es262-32.dll" to Virus Total --
http://www.virustotal.com/flash/index_en.html
The submission will then be tested against many different AV vendor's scanners.
That will give you an idea what it is and who recognizes it. In addition,
unless told
otherwise, Virus Total will provide the sample to all participating vendors.

You can also submit a suspect, one at a time, via the following email URL...
mailto:scan@virustotal.com?subject=SCAN

When you get the report, please post back the exact results.


--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm



Posted by Keith Woolf on November 19, 2006, 3:31 am
If you were  Registered and logged in, you could reply and use other advanced thread options

>
> | Version 1.22 picks up C:\Program Files\Adobe\Adobe Help
> | Center\Browser\es262-32.dll as "a possible infection with
> | Backdoor:Win32/Hackdef.L".
> |
> | The automatic Quick Scan from MS Update does not flag this file, only
> the
> | user initiated Enhanced Scan. Version 1.21 does not flag this file and
> two
> | independent virus scanners similarly do not flag it.
> |
> | The file appears to be an unmodified 'genuine Adobe article'. Can anyone
> | confirm or deny that this is a False Positive?
> |
> | Keith Woolf
> |
>
> Please submit a sample of "es262-32.dll" to Virus Total --
> http://www.virustotal.com/flash/index_en.html
> The submission will then be tested against many different AV vendor's
> scanners.
> That will give you an idea what it is and who recognizes it. In addition,
> unless told
> otherwise, Virus Total will provide the sample to all participating
> vendors.
>
> You can also submit a suspect, one at a time, via the following email
> URL...
> mailto:scan@virustotal.com?subject=SCAN
>
> When you get the report, please post back the exact results.
>
>
> --
> Dave
> http://www.claymania.com/removal-trojan-adware.html
> http://www.ik-cs.com/got-a-virus.htm
>
Report from 'virustotal' shows Fortinet 2.82.0.0 dated 11.19.06 giving
"suspicious"; all others giving "no virus found".
Incidentally I got an automatic update last night from MS downloading
Malicious Software Removal Tool v1.22. As I had already downloaded this
version both via Critcal Updates and manually, I assumed this was a 'new'
v1.22 but with the same number. I will now run the Extended Scan with this
'new?' version and see if anything has changed. Result later.

Thanks for your help.

Keith Woolf>



Posted by David H. Lipman on November 19, 2006, 8:27 am
If you were  Registered and logged in, you could reply and use other advanced thread options


| Report from 'virustotal' shows Fortinet 2.82.0.0 dated 11.19.06 giving
| "suspicious"; all others giving "no virus found".
| Incidentally I got an automatic update last night from MS downloading
| Malicious Software Removal Tool v1.22. As I had already downloaded this
| version both via Critcal Updates and manually, I assumed this was a 'new'
| v1.22 but with the same number. I will now run the Extended Scan with this
| 'new?' version and see if anything has changed. Result later.
|
| Thanks for your help.
|
| Keith Woolf>
|

YW.

For the moment, let's consider it "suspicious" as well.
Malware is known to replace legitimate file copies with Trojanized files.

In case you didn't know (but I think you do and it is more for those reading
this thread)...

The utility is...
%windir%\system32\MRT.exe

Command line switches...

/? or /HELP = displays the command line switches
/Q = quiet
/N = detect only
/F = force extended scan
/F:Y = force extended scan and automatically clean infected files

The following is the resultant log file...

%windir%\Debug\mrt.log


--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm



Posted by Keith Woolf on November 19, 2006, 8:58 am
If you were  Registered and logged in, you could reply and use other advanced thread options
>
> | Version 1.22 picks up C:\Program Files\Adobe\Adobe Help
> | Center\Browser\es262-32.dll as "a possible infection with
> | Backdoor:Win32/Hackdef.L".
> |
> | The automatic Quick Scan from MS Update does not flag this file, only
> the
> | user initiated Enhanced Scan. Version 1.21 does not flag this file and
> two
> | independent virus scanners similarly do not flag it.
> |
> | The file appears to be an unmodified 'genuine Adobe article'. Can anyone
> | confirm or deny that this is a False Positive?
> |
> | Keith Woolf
> |
>
> Please submit a sample of "es262-32.dll" to Virus Total --
> http://www.virustotal.com/flash/index_en.html
> The submission will then be tested against many different AV vendor's
> scanners.
> That will give you an idea what it is and who recognizes it. In addition,
> unless told
> otherwise, Virus Total will provide the sample to all participating
> vendors.
>
> You can also submit a suspect, one at a time, via the following email
> URL...
> mailto:scan@virustotal.com?subject=SCAN
>
> When you get the report, please post back the exact results.
>
>
> --
> Dave
> http://www.claymania.com/removal-trojan-adware.html
> http://www.ik-cs.com/got-a-virus.htm
>
Report Update

I have now run the full user initiated scan using the 'new?' version of 1.22
and it now reports 'nothing found'.

Incidentally the 'new' version 1.22 is 1.22.1632.0 with a modified date of
15 Nov 06 21.20.40 while the 'old' one was 1.22.1630 - I've 'lost' the
modified date because I deleted the file before thinking!

I did click the 'tell Microsoft' button when the 'suspicious' file was
flagged so I presume MS had a look and tweaked the MRT.

I am now feeling fairly confident that it was a False Positive. Am I living
in my usual 'fools paradise'?

Thanks for your help; I have bookmarked the VirusTotal site in case I have
more problems.

Cheers,

Keith Woolf



Similar ThreadsPosted
Uninstall/removal of MRT (Microsoft Malicious Software Removal Tool) November 13, 2006, 9:03 am
How to run "Malicious Software Removal Tool" ? July 19, 2005, 2:36 pm
Malicious Software Removal Tool September 22, 2005, 12:59 pm
Windows Malicious Software Removal Tool? December 4, 2005, 8:19 am
Where on earth is the (Malicious Software Removal) Tool? January 25, 2008, 4:34 am
Alerting - Malicious software removal tool November 25, 2008, 9:34 am
Malicious software removal tool - quiet mode September 19, 2005, 6:52 am
Microsoft Windows Malicious Software Removal Tool February 27, 2006, 5:24 am
When execute Malicious Software Removal Tool of Microsoft? August 13, 2008, 6:56 am
Guided Help widget available for MS Windows Malicious Software Removal Tool June 16, 2006, 12:30 am

The site map in XML format XML site map

Contact Us | Privacy Policy