Re:ReTrojan Horse Generic12.BGEI and infected msconfig

Discussion in 'Malware Help (A Specialist Will Reply)' started by mishkadar, Feb 19, 2009.

  1. mishkadar

    mishkadar Private E-2

    Hi ... I'm watching intensively for the original thread at the subject (#181644) initiated by MayBee. Unfortunately for some reason I'm blocked to contribute posts to it, even though I have some notes.
    First I'm getting the very same and completely identical MBAM log report content as MayBee. And here the thing: the locations that reported in MBAM log to host infected entries are not real rather than JUNCTION (I'm running VISTA).

    For example the following line from MBAM-log:
    C:\Users\Default\Cookies\MM2048.DAT (Trojan.Agent) -> No action taken.

    The "C:\Users\Default\Cookies\" is not accessible. Listing the content of "C:\Users\Default\" from command line prompt will result respectively to this /Cookies/ location the as follows:
    02/11/2006 08:02 AM <JUNCTION> Cookies [E:\Users\Default\AppData\Roaming\Microsoft\Windows\Cookies]

    So actually this so call "folders" are completely empty .... but here's the really weird thing (at least on my machine) ... the "E:/" on my toy is the DVD drive ... so I'm actually kinda shocked ... where & why the hell this junction is point to ...
    Any ideas?
    Thx.
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Re: ReTrojan Horse Generic12.BGEI and infected msconfig

    This is the first that we have seen of this and at this point do not know if it is a problem with an update in MBAM or what.
     
  3. mishkadar

    mishkadar Private E-2

    Re: ReTrojan Horse Generic12.BGEI and infected msconfig

    Hi again & thnx for a feedback.

    I'm not completely following U on this one ...
    I see that MayBee succeeded to delete those JUNCTIONS ... notice again these are not FOLDERS rather than JUNCTIONS, and are hidden by default as SYSTEM OWN entries ... its something alike Links in Linux.

    I'm not sure if deleting those JUNCTIONS is the key for solution especially when the actual containers they point at my machine are on DVD drive ... thus no wonder those entries can not be deleted by reboot.

    But while the last fact is quite explainable, it's really out of my sense how MBAM detects infection/maleware within those junctions which point to DVD drive which is EMPTY during the scan. Something weird here because we (me and MayBee) get/got 100% exactly the same MBAM-LOG content.
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Re: ReTrojan Horse Generic12.BGEI and infected msconfig

    What she ended up doing was to delete as much as she could under the users\default setting. Which seemed to work for her. Did you recheck that thread?
     
  5. mishkadar

    mishkadar Private E-2

    Re: ReTrojan Horse Generic12.BGEI and infected msconfig

    Hi...
    Sure... like I posted
    but I'm trying to ditch for the reason MBAM detecting infection at locations which is kinda not FEASIBLE if not exist ....so like I posted previously: it's really out of my sense how/why MBAM detects infection/maleware within those junctions which point to DVD drive which is EMPTY during the scan .
    So the JUNCTIONS are absolutely of 0 size by VISTA design and no DVD disk in drive during the scan.... wondering how MBAM detects/associates/accumulates infection list of 65 files which are obviously NOT THERE IN ANY CASE. Any ideas?
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Re: ReTrojan Horse Generic12.BGEI and infected msconfig

    Not a clue at this point.....but you could post at the MBAM forum and ask as they are good at responding to false positives. No one is still sure how some drivers respond in Vista.
     
  7. mishkadar

    mishkadar Private E-2

    Re: ReTrojan Horse Generic12.BGEI and infected msconfig

    Heh..
    Well they had pretty similar issue few month ago ... unfortunately hasn't been resolved....back there they promised to resolve it with upcoming version...3-4 version since ...

    BTW ... thx for attention & effort
     
  8. mishkadar

    mishkadar Private E-2

    Re: ReTrojan Horse Generic12.BGEI and infected msconfig

    Just updated DB version from 1778 to 1800 ... so I have
    v1.34 with DB 1800 and ... scan performed and ...
    Surprise - Surprise the issue has been vanished ... yeah just like that ... it's gone in vain .... the same way it's appeared....MBAM-log is clean.

    I check the content of /Default folder from command line console ... well those weirdo (pointing to E:// DVD drive) JUNCTIONS are there but ... at least MBAM this time aware that those are pointers to black hole ...

    Have I said the whole thing is WEIRD ;-)?
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Re: ReTrojan Horse Generic12.BGEI and infected msconfig

    Weird? I think you may have mentioned it. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds