Wilders Security Forums  

Go Back   Wilders Security Forums > Software, Hardware and General Services > backup, imaging & disk mgmt
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old August 10th, 2012, 04:08 AM
JoeBlack40's Avatar
JoeBlack40 JoeBlack40 is offline
Very Frequent Poster
 
Join Date: Apr 2009
Location: Romania
Posts: 1,284
Default CTM 2.9 bootkit MBR FP?

Few days ago i bought a new laptop and i installed on it CTM as it is part of my security.On my other laptop,CTM 2.8 version works flawlessly for over 2 years now.But on the new one,the 2.8 version doesn't work,it won't install,it gave that "couldn't find the operating system" error.Searched a little on their forum and decided to install the 2.9 beta version.This one installed fine,but...when i scanned yesterday with Hitman pro,a bootkit MBR warning was detected.After that,i scanned with:
Kaspersky TDSS killer-clean (3 suspicious drivers from CTM,but these 3 are flagged in the 2.8 version too,no big deal)
BitDefender Antibootkit Tool-clean
Eset Online Scanner-clean
MBAM-clean
SAS-clean
Emsisoft Toolkit-suspicious MBR rootkit
GMER-possible MBR rootkit.
I want to mention the fact that on the laptop with CTM 2.8 version,these detections doesn't exist.So my question is...anyone using the 2.9 beta version and facing these detections?I suppose they're FP...or not...?
Thanks guys for your replies.
__________________
Avira free-Privatefirewall-Sandboxie-WinPatrol Plus-Wondershare TimeFreeze
  #2  
Old August 10th, 2012, 11:46 AM
andyman35 andyman35 is offline
Very Frequent Poster
 
Join Date: Nov 2007
Posts: 2,270
Default Re: CTM 2.9 bootkit MBR FP?

It's a FP,no cause for concern.Anything that modifies the MBR is always likely to trigger a FP unless specifically whitelisted.
  #3  
Old August 10th, 2012, 12:19 PM
Jim1cor13 Jim1cor13 is offline
Frequent Poster
 
Join Date: Aug 2012
Location: US
Posts: 295
Default Re: CTM 2.9 bootkit MBR FP?

Thank you andy, I was thinking the same thing. Generally this is common with anything that lodges itself within the MBR such as a program like CTM, and it may handle that differently than say RollbackRX, etc., but they all still embed within the MBR.

It is good though that Joe mentioned this, but I am sure it is a FP.
  #4  
Old August 10th, 2012, 07:23 PM
ratchet ratchet is offline
Very Frequent Poster
 
Join Date: Feb 2006
Posts: 1,294
Default Re: CTM 2.9 bootkit MBR FP?

Quote:
Originally Posted by JoeBlack40
Few days ago i bought a new laptop and i installed on it CTM as it is part of my security.On my other laptop,CTM 2.8 version works flawlessly for over 2 years now.But on the new one,the 2.8 version doesn't work,it won't install,it gave that "couldn't find the operating system" error.Searched a little on their forum and decided to install the 2.9 beta version.This one installed fine,but...when i scanned yesterday with Hitman pro,a bootkit MBR warning was detected.After that,i scanned with:
Kaspersky TDSS killer-clean (3 suspicious drivers from CTM,but these 3 are flagged in the 2.8 version too,no big deal)
BitDefender Antibootkit Tool-clean
Eset Online Scanner-clean
MBAM-clean
SAS-clean
Emsisoft Toolkit-suspicious MBR rootkit
GMER-possible MBR rootkit.
I want to mention the fact that on the laptop with CTM 2.8 version,these detections doesn't exist.So my question is...anyone using the 2.9 beta version and facing these detections?I suppose they're FP...or not...?
Thanks guys for your replies.
What operating system? Just curious as you stated new. I love CTM but as far as I know can't use on 64 bit W7.
__________________
Linksys WRT54GS (Tomato) Firewall
Norton AntiVirus 2012
Sandboxie (license)
CTM
  #5  
Old August 10th, 2012, 07:34 PM
JoeBlack40's Avatar
JoeBlack40 JoeBlack40 is offline
Very Frequent Poster
 
Join Date: Apr 2009
Location: Romania
Posts: 1,284
Default Re: CTM 2.9 bootkit MBR FP?

Thank you guys,yes,we could say that it's a FP.Just wondering why with the 2.8 version this doesn't happen...
Quote:
Originally Posted by ratchet
What operating system? Just curious as you stated new. I love CTM but as far as I know can't use on 64 bit W7.
Windows 7 Ultimate x32.
__________________
Avira free-Privatefirewall-Sandboxie-WinPatrol Plus-Wondershare TimeFreeze
  #6  
Old August 11th, 2012, 11:17 AM
taleblou taleblou is offline
Frequent Poster
 
Join Date: Jan 2010
Posts: 302
Default Re: CTM 2.9 bootkit MBR FP?

Quote:
Originally Posted by ratchet
What operating system? Just curious as you stated new. I love CTM but as far as I know can't use on 64 bit W7.

WHAT Yes you can use it on win-7 64bit. I am using it for a long time. Also yes the 2.8 gives some failed windows message but 2.9 beta works fine and installs well. You can use it on 64bit fine as I have it now.

Also the false positive is true with both CTM and rollback rx. They give FP in hitman and kaspersky and also emsisoft antimalware. SO white list them.
  #7  
Old August 11th, 2012, 01:22 PM
DarkPhoenix DarkPhoenix is offline
Regular Poster
 
Join Date: Dec 2010
Posts: 86
Default Re: CTM 2.9 bootkit MBR FP?

I suspect the reason why all those programs didn't detect the False Positive is because their definitions were updated to include the known 2.8 versions software - the 2.9 versions definitions were probably not updated yet.

Glad to hear someone used CTM for 2 years without problems.. it always crashed my system hard after a week or so with no chance at recovery but a windows reinstall. I'm looking forward to the new 3.0 if it ever gets finished to try it again. BTW, RollBack RX crashed my system in the same exact way CTM did, and they are really dragging their feet on a new version.
  #8  
Old August 11th, 2012, 07:00 PM
JoeBlack40's Avatar
JoeBlack40 JoeBlack40 is offline
Very Frequent Poster
 
Join Date: Apr 2009
Location: Romania
Posts: 1,284
Default Re: CTM 2.9 bootkit MBR FP?

Ok,now the proof that it's a FP.Uninstalled CTM for disk defrag and Hitman pro doesn't detect the bootkit anymore.
__________________
Avira free-Privatefirewall-Sandboxie-WinPatrol Plus-Wondershare TimeFreeze
 

Wilders Security Forums > Software, Hardware and General Services > backup, imaging & disk mgmt « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 02:30 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums