PDA

View Full Version : MBAM strangeness


Firebytes
December 16th, 2008, 02:24 PM
I had an odd thing happen with MBAM late last night. I downloaded a malware file to tinker with while under the protection of Returnil. I uploaded the file to VirusTotal and it was detected by about 60% of the scanners as a trojan. I then scanned the file with MBAM to see if MBAM would detect it and it did. Then due to the fact that my wife was going to bed I moved to another computer in another room and downloaded the same malware file onto it. I started where I left off and scanned it with MBAM but this time MBAM did not detect it! I had the same version of MBAM on both systems and both were updated with the latest definitions. Also, FYI the trojan file was downloaded onto both computers but was never ran. Any ideas what the difference could have been?

lordpake
December 16th, 2008, 03:03 PM
Are you certain you got the same malware sample, down to the last bit? Checksums matching?

If you got it from the Web, it's possible you were served another variant.

Firebytes
December 16th, 2008, 03:16 PM
Yeah, I just downloaded it again from the same link (maybe thirty minutes later) and didn't even think about verifying it by checksum. I bet you are right. Thanks.