Malwarebytes And Mfme3.2
Started by hornynick, Nov 14 2012 08:35 PM
18 replies to this topic
#1
Posted 14 November 2012 - 08:35 PM
About 2 weeks ago I ran a scan and Mb found a trojan caleed VBKrypt (or similar) on MFME 3.2. I just assumed that a virus had attached itself to the file and removed it. Over the weekend I finally got round to re-downloading 3.2 and today I did a scan and the virus is back.
I am now assuming its a false positive but did remove it to be on the safe side. Has anyone else done a scan with Mb recently and had the same? Also, if it isnt a false positive and there is something sinister lurking on my system (is that likely?) why is it only targeting 3.2?
I am now assuming its a false positive but did remove it to be on the safe side. Has anyone else done a scan with Mb recently and had the same? Also, if it isnt a false positive and there is something sinister lurking on my system (is that likely?) why is it only targeting 3.2?
#2 Guest_Tommy c_*
Posted 14 November 2012 - 08:40 PM
yeah would say a false positive as it's fine my end,providing you downloaded from here,the mecca or the repro.
#3
Posted 14 November 2012 - 08:53 PM
just checked mine though avg as i think i got mfme3.2 off a dodgy fleabay dvd originally before i found this/sites and mines all clear
The more I do today, The less I do tomorrow.
Fme is alive and screaming into the 21st century!
Enjoy FME and Happy Gaming!!!!
Fme is alive and screaming into the 21st century!
Enjoy FME and Happy Gaming!!!!
#4
Posted 14 November 2012 - 09:36 PM
As this was added in its current state on 3rd Nov 2006 with no problems.
I think we can confidently say it's your config of your AV.
I think we can confidently say it's your config of your AV.
#5
Posted 14 November 2012 - 10:00 PM
I know the file itself was ok when downloaded, im just asking others with up to date Malwarebytes if they get the same result. If not then I know I got bigger problems.
#6
Posted 14 November 2012 - 10:05 PM
It detects a trojan on my MFME 1.0, 2.0 and 3.2 too. Malwarebytes uses a fairly powerful heuristics and behaviour based analysis engine, that means in addition to just checking for actual malware and viruses from a database like most anti-virus programs it also scans for programs which may act like a virus or malware, this is so it can catch newer viruses that aren't yet detectable by most programs and viruses ones that actively try to evade anti-virus programs, the downside to this is that Malwarebytes is well known to show a lot of false positives. I've scanned all three .exe files with my AVG Internet Security 2011 and all 3 show no infection so I'd say it's just false positives, as it's the 3 older versions of MFME that trigger the alert while the newer 9.4, 9.9 and 10.1a show as clean I'd say that something is written into the older versions which Malwarebytes thinks resembles the behaviour of a trojan and flags it.
#7
Posted 14 November 2012 - 10:24 PM
Having said that, I did a malware thing (that someone posted on another thread) and then found that MFME 3.2 had gone...
I've re downloaded it using the 'All In One' version,
Not sure if thats something like you're on about??
I've re downloaded it using the 'All In One' version,
Not sure if thats something like you're on about??
#8
Posted 14 November 2012 - 10:28 PM
Could be. when the scan had finished did you have infections? If you did and clicked clean, it gets rid of 3.2 If thats the case I can breathe easy lol.
#9
Posted 14 November 2012 - 11:16 PM
It detects a trojan on my MFME 1.0, 2.0 and 3.2 too. Malwarebytes uses a fairly powerful heuristics and behaviour based analysis engine, that means in addition to just checking for actual malware and viruses from a database like most anti-virus programs it also scans for programs which may act like a virus or malware, this is so it can catch newer viruses that aren't yet detectable by most programs and viruses ones that actively try to evade anti-virus programs, the downside to this is that Malwarebytes is well known to show a lot of false positives. I've scanned all three .exe files with my AVG Internet Security 2011 and all 3 show no infection so I'd say it's just false positives, as it's the 3 older versions of MFME that trigger the alert while the newer 9.4, 9.9 and 10.1a show as clean I'd say that something is written into the older versions which Malwarebytes thinks resembles the behaviour of a trojan and flags it.
Id agree , i have scanned this 3 times (Avast , Trojan hunter and Malwarebytes) and the only one that flags this as a 'virus' is Malwarebytes.
With all AV programs , certain 'suspicious behaviour' can lead to programs flagging up viruses , but ive had these emulators on my system for years and never had it 'infect' my system.
Plus ive had just about every AV program going ... Kaspersky , AVG , Norton , ESET , Microsoft security Essentials , Bitdefender , none of them have ever found a problem with these files.
Mmmmmm...Sandy ive 'ad her ye know.
#10
Posted 14 November 2012 - 11:27 PM
Yep, the VBcrypt result from Malwarebytes is 100% false-positive, and only started a few revisions back, so you need to tell malwarebytes to exclude mfme from it's scans.
If you are ever unsure of any file, best uploading it to Virus Total, where they use several scan engines, which is a much more reliable bet than using just one or two scan engines alone
I would say if you get a detection rate of 30% or less, it's a pretty safe bet the file is fine
https://www.virustotal.com/
If you are ever unsure of any file, best uploading it to Virus Total, where they use several scan engines, which is a much more reliable bet than using just one or two scan engines alone
I would say if you get a detection rate of 30% or less, it's a pretty safe bet the file is fine
https://www.virustotal.com/
Edited by stanmarsh14, 14 November 2012 - 11:30 PM.
#11
Posted 14 November 2012 - 11:54 PM
just goes to show how good the malware bytes program is.
#12
Posted 15 November 2012 - 12:33 AM
Cheers guys, as someone said it only just started flagging it up so it did get me worried a bit.
#13
Posted 17 November 2012 - 10:02 AM
I had the same happen to me. I was going to post a thread up about it but don't need to now !
Last bet 11/06/09!!
#14
Posted 08 February 2013 - 10:42 PM
Anybody found a way to get 3.2 back up and working? with avg there doesn't seem a way to let it remain active. In the past you could declare things as false +ve's, but now all you can do is leave them but unusable.
Danasoft users are just annoying gits....
#15
Posted 09 February 2013 - 09:07 AM
Uninstall AVG, install security essentials instead and then re-download the mfme package. Worked for me on an old machine that still ran AVG.
#16
Posted 09 February 2013 - 11:43 AM
Anybody found a way to get 3.2 back up and working? with avg there doesn't seem a way to let it remain active. In the past you could declare things as false +ve's, but now all you can do is leave them but unusable.
Best to ditch AVG, and just go with MSE (Which also updates directly via windows update), and save yourself some grief.
It's just as good as AVG, and is something I have now started using on comps I repair for people.
http://www.microsoft...curity/mse.aspx
#17
Posted 09 February 2013 - 01:54 PM
I have Avg and when it scans computer for virus's it removes mfme3.2 and puts it into the virus vault all I do then is goto virus vault and restore the item everytime it does it I had malaware but that removed all the early mfme's
The more I do today, The less I do tomorrow.
Fme is alive and screaming into the 21st century!
Enjoy FME and Happy Gaming!!!!
Fme is alive and screaming into the 21st century!
Enjoy FME and Happy Gaming!!!!
#18
Posted 10 February 2013 - 02:32 PM
Best to ditch AVG, and just go with MSE (Which also updates directly via windows update), and save yourself some grief.
It's just as good as AVG, and is something I have now started using on comps I repair for people.
http://www.microsoft...curity/mse.aspx
I'd say it's actually a lot better than AVG. In fact MS Security Essentials just came top of the Which? review of PC security products.
As it's free, it's a bit of a no brainer tbh.
#19
Posted 10 February 2013 - 02:50 PM
MFME gives a false positives because it acts in a way similar to a key logger.
Its just a side effect of what the emulator is doing. i.e. sitting waiting for a key to be pressed so it can do the keyboard shortcuts.
Project Amber 2 - Coming Soon
1 user(s) are reading this topic
0 members, 1 guests, 0 anonymous users