"GOOD" MALware in MBAM??

Discussion in 'Malware Help (A Specialist Will Reply)' started by grc123, Aug 26, 2010.

  1. grc123

    grc123 MajorGeek

    MBAM marked this as "Good" ? (Please see attached)...

    When someone has a moment, would it be possible to explain this for me, please?

    Thanks in advance,
    g...
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    • This is a common hijack point for a common infection.
    • There is no way for MBAM to determine if the user has done this or malware is at fault
    • Please have MBAM ignore these to prevent them from showing up in your scans again.

    If you wish to check further for any possible malware on your system then complete the rest of the scans and attach the requested logs. :)
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Read your log again! It did not mark them as "Good"! It said it quarantined and deleted them. However these are typically not problems as most people change these settings from defaults and MBAM is marking any change from default to be bad.
     
  4. grc123

    grc123 MajorGeek

    Thank you ma'am.

    Am I to assume then that's it's "possible" that something was left on my hard drive after I "wiped" it?

    Otherwise I'm not understanding how something could have entered this machine in such a short period of time, and with such carefulness on my part ... of the three days that had passed since the reinstall, 95% of my time was spent downloading security progs from here (MG's) ... and heck, it took MS two days to reapply all of their updates.

    Though I did visit some other sites in that time, they were "ALL" well known, reputable sites (virtually all of them security software vendors), and again, I have not opened any strange email nor clicked-on any links within email.

    Either Chaslang knows something that he didn't share with me in his response, or I'm "seeing" things in my log ... while he is correct in that MBAM "quarantined and deleted them", this too, is clearly written into the log (copy/paste):

    "HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_ShowSearch (Hijack.StartMenu) -> Bad: (0) Good: (1)

    ??

    Thanks again...
     
    Last edited: Aug 26, 2010
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You had a registry value that was set to 0 when the default value is normally 1. Thus MBAM was telling you 0 = bad and 1 = Good. And that is what it changed it to when it said Quarantined and Deleted. If the value had already been set to one, you would not have seen anything in the MBAM report.

    The fact remains that many of these types of registry key detections by MBAM are not necessarily valid malware detections. If you change a setting to how you want it to be and it is not the normal Microsoft default value, MBAM will tell you that it is bad when it may just be what you want it to be set to. MBAM cannot tell the difference between something you knowingly changed and something changed by malware. Thus MBAM attempts to just set things to defaults which is not necessarily a good thing since it could be changing values that a person decided to make on their own.. Kestrel13! mentioned this to you.

    These kinds of detections are similar to the issues that Spybot caused years ago when it started reporting changes to Windows Security Center defaults and everyone kept assuming they were problems/malware when in 99% of cases they were settings that the end user chose to do or that their security software made automatically.
     
    Last edited: Aug 26, 2010
  6. grc123

    grc123 MajorGeek

    Thank you for the breakdown, though I often don't fully understand this stuff, I always appreciate the opportunity to.

    So, would this line (*below), which was listed just above the first one that we have addressed (in the same log), mean just the opposite for this particular value, please?


    Registry Data Items Infected:
    * HKEY_CURRENT_USER\SOFTWARE\Policies\Microsoft\Internet Explorer\Control Panel\Homepage (Hijack.Homepage) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
    "HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_ShowSearch (Hijack.StartMenu) -> Bad: (0) Good: (1)
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes it means 1 is not the default value expected.

    Let me give you an example that you may find interesting/helpful. You will need Spybot installed to try this example.

    • Run Spybot
    • Click Mode and select Advanced Mode
    • On the left side select the Tools menu and click + to expand it.
    • Click on IE Tweaks and lock the IE start page. Double click the below snapshot to see what this looks like
    sbot1.jpg

    • Now do not exit Spybot ( so that you will be able to quickly undo this later ).
    • Now run MBAM and do a quick scan and save a log without fixing. Notice you will see the below lines
    • A 1 in this value of the registry key means the Homepage is locked but being locked is not the default.
    • Obviously this is a setting that you just made. It could have also been a setting made by other protection software options you chose. It is not malware, nor is it bad in this case because you chose it to be this way. MBAM is defaulting to deciding that this is always bad which is not really a good idea. It would have been a better option to show it as a Warning/Advisorory with a suggestion to only fix if you did not set it this way.
    • Now undo what you did with Spybot
    Get the idea? ;)
     
  8. grc123

    grc123 MajorGeek

    Thank you again - I get it - and am now realizing, this is all probably due to me having set it that way in SpywareBlaster ... (correct?)

    This way (attached):

    PS ~ and I just happened to have downloaded/installed Spybot last night based-on your recommendation in "How to Protect Yourself...", here at MG's.
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds