Jump to content


Photo
- - - - -

Malwarebytes And Mfme3.2


  • Please log in to reply
18 replies to this topic

#1 hornynick

hornynick

    Member

  • Regulars
  • 259 posts

Posted 14 November 2012 - 08:35 PM

About 2 weeks ago I ran a scan and Mb found a trojan caleed VBKrypt (or similar) on MFME 3.2. I just assumed that a virus had attached itself to the file and removed it. Over the weekend I finally got round to re-downloading 3.2 and today I did a scan and the virus is back.

I am now assuming its a false positive but did remove it to be on the safe side. Has anyone else done a scan with Mb recently and had the same? Also, if it isnt a false positive and there is something sinister lurking on my system (is that likely?) why is it only targeting 3.2?

#2 Guest_Tommy c_*

Guest_Tommy c_*
  • Guests

Posted 14 November 2012 - 08:40 PM

yeah would say a false positive as it's fine my end,providing you downloaded from here,the mecca or the repro.

#3 vectra666

vectra666

    No1. Lurker

  • Layout Creator
  • PipPipPipPipPip
  • 9041 posts

Donator

Posted 14 November 2012 - 08:53 PM

just checked mine though avg as i think i got mfme3.2 off a dodgy fleabay dvd originally before i found this/sites and mines all clear
The more I do today, The less I do tomorrow.
Fme is alive and screaming into the 21st century!
Enjoy FME and Happy Gaming!!!!

#4 ady

ady

    The furniture

  • Moderators
  • 14204 posts

Posted 14 November 2012 - 09:36 PM

As this was added in its current state on 3rd Nov 2006 with no problems.

I think we can confidently say it's your config of your AV.

#5 hornynick

hornynick

    Member

  • Regulars
  • 259 posts

Posted 14 November 2012 - 10:00 PM

I know the file itself was ok when downloaded, im just asking others with up to date Malwarebytes if they get the same result. If not then I know I got bigger problems.

#6 Stephen22

Stephen22

    Newbie

  • New Members
  • 2 posts

Posted 14 November 2012 - 10:05 PM

It detects a trojan on my MFME 1.0, 2.0 and 3.2 too. Malwarebytes uses a fairly powerful heuristics and behaviour based analysis engine, that means in addition to just checking for actual malware and viruses from a database like most anti-virus programs it also scans for programs which may act like a virus or malware, this is so it can catch newer viruses that aren't yet detectable by most programs and viruses ones that actively try to evade anti-virus programs, the downside to this is that Malwarebytes is well known to show a lot of false positives. I've scanned all three .exe files with my AVG Internet Security 2011 and all 3 show no infection so I'd say it's just false positives, as it's the 3 older versions of MFME that trigger the alert while the newer 9.4, 9.9 and 10.1a show as clean I'd say that something is written into the older versions which Malwarebytes thinks resembles the behaviour of a trojan and flags it.

#7 Taylor525

Taylor525

    Owner and Parts Seller

  • Regulars
  • 508 posts

Posted 14 November 2012 - 10:24 PM

Having said that, I did a malware thing (that someone posted on another thread) and then found that MFME 3.2 had gone...

I've re downloaded it using the 'All In One' version,

Not sure if thats something like you're on about??

#8 hornynick

hornynick

    Member

  • Regulars
  • 259 posts

Posted 14 November 2012 - 10:28 PM

Could be. when the scan had finished did you have infections? If you did and clicked clean, it gets rid of 3.2 If thats the case I can breathe easy lol.

#9 todd1970

todd1970

    The furniture

  • Regulars
  • 6818 posts

Posted 14 November 2012 - 11:16 PM

It detects a trojan on my MFME 1.0, 2.0 and 3.2 too. Malwarebytes uses a fairly powerful heuristics and behaviour based analysis engine, that means in addition to just checking for actual malware and viruses from a database like most anti-virus programs it also scans for programs which may act like a virus or malware, this is so it can catch newer viruses that aren't yet detectable by most programs and viruses ones that actively try to evade anti-virus programs, the downside to this is that Malwarebytes is well known to show a lot of false positives. I've scanned all three .exe files with my AVG Internet Security 2011 and all 3 show no infection so I'd say it's just false positives, as it's the 3 older versions of MFME that trigger the alert while the newer 9.4, 9.9 and 10.1a show as clean I'd say that something is written into the older versions which Malwarebytes thinks resembles the behaviour of a trojan and flags it.


Id agree , i have scanned this 3 times (Avast , Trojan hunter and Malwarebytes) and the only one that flags this as a 'virus' is Malwarebytes.

With all AV programs , certain 'suspicious behaviour' can lead to programs flagging up viruses , but ive had these emulators on my system for years and never had it 'infect' my system.

Plus ive had just about every AV program going ... Kaspersky , AVG , Norton , ESET , Microsoft security Essentials , Bitdefender , none of them have ever found a problem with these files.
Mmmmmm...Sandy ive 'ad her ye know. :)

#10 stanmarsh14

stanmarsh14

    Sado-masochist

  • Gold Supporters
  • 3120 posts

Posted 14 November 2012 - 11:27 PM

Yep, the VBcrypt result from Malwarebytes is 100% false-positive, and only started a few revisions back, so you need to tell malwarebytes to exclude mfme from it's scans.

If you are ever unsure of any file, best uploading it to Virus Total, where they use several scan engines, which is a much more reliable bet than using just one or two scan engines alone

I would say if you get a detection rate of 30% or less, it's a pretty safe bet the file is fine

https://www.virustotal.com/

Edited by stanmarsh14, 14 November 2012 - 11:30 PM.


#11 nails

nails

    The furniture

  • Regulars
  • 4578 posts

Posted 14 November 2012 - 11:54 PM

just goes to show how good the malware bytes program is.

#12 hornynick

hornynick

    Member

  • Regulars
  • 259 posts

Posted 15 November 2012 - 12:33 AM

Cheers guys, as someone said it only just started flagging it up so it did get me worried a bit.

#13 lufc26

lufc26

    Newbie

  • Regulars
  • 110 posts

Posted 17 November 2012 - 10:02 AM

I had the same happen to me. I was going to post a thread up about it but don't need to now :spinny: !

Last bet 11/06/09!!


#14 TurboZed

TurboZed

    Just an old Member LOL!

  • New Members
  • 64 posts

Posted 08 February 2013 - 10:42 PM

Anybody found a way to get 3.2 back up and working? with avg there doesn't seem a way to let it remain active. In the past you could declare things as false +ve's, but now all you can do is leave them but unusable.


Danasoft users are just annoying gits....

#15 Magz

Magz

    Senior Member

  • Regulars
  • 887 posts

Posted 09 February 2013 - 09:07 AM

Uninstall AVG, install security essentials instead and then re-download the mfme package. Worked for me on an old machine that still ran AVG.



#16 stanmarsh14

stanmarsh14

    Sado-masochist

  • Gold Supporters
  • 3120 posts

Posted 09 February 2013 - 11:43 AM

Anybody found a way to get 3.2 back up and working? with avg there doesn't seem a way to let it remain active. In the past you could declare things as false +ve's, but now all you can do is leave them but unusable.

 

Best to ditch AVG, and just go with MSE (Which also updates directly via windows update), and save yourself some grief.

It's just as good as AVG, and is something I have now started using on comps I repair for people.

http://www.microsoft...curity/mse.aspx



#17 vectra666

vectra666

    No1. Lurker

  • Layout Creator
  • PipPipPipPipPip
  • 9041 posts

Donator

Posted 09 February 2013 - 01:54 PM

I have Avg and when it scans computer for virus's it removes mfme3.2 and puts it into the virus vault all I do then is goto virus vault and restore the item everytime it does it I had malaware but that removed all the early mfme's
The more I do today, The less I do tomorrow.
Fme is alive and screaming into the 21st century!
Enjoy FME and Happy Gaming!!!!

#18 Magz

Magz

    Senior Member

  • Regulars
  • 887 posts

Posted 10 February 2013 - 02:32 PM

Best to ditch AVG, and just go with MSE (Which also updates directly via windows update), and save yourself some grief.

It's just as good as AVG, and is something I have now started using on comps I repair for people.

http://www.microsoft...curity/mse.aspx

 

I'd say it's actually a lot better than AVG. In fact MS Security Essentials just came top of the Which? review of PC security products.

 

As it's free, it's a bit of a no brainer tbh.



#19 Guitar

Guitar

    Project Amber Developer

  • Layout Creator
  • PipPipPipPipPip
  • 2989 posts

Posted 10 February 2013 - 02:50 PM

MFME gives a false positives because it acts in a way similar to a key logger.

 

Its just a side effect of what the emulator is doing. i.e. sitting waiting for a key to be pressed so it can do the keyboard shortcuts.


Project Amber 2 - Coming Soon





1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users