Wilders Security Forums  

Go Back   Wilders Security Forums > Security Products > other anti-virus software
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old November 14th, 2006, 05:30 PM
CtlAltDelete CtlAltDelete is offline
Regular Poster
 
Join Date: Dec 2005
Posts: 64
Default Dr Web / MS Malicious Software Rmvl Tool Nov 14 2006

Anyone with Dr Web that also has spidermail installed.


See thread here:

http://www.dslreports.com/forum/remark,17275040
  #2  
Old November 14th, 2006, 06:51 PM
SSK SSK is offline
Frequent Poster
 
Join Date: Nov 2004
Location: Amsterdam
Posts: 976
Default Re: Dr Web / MS Malicious Software Rmvl Tool Nov 14 2006

Yep, I noticed...
  #3  
Old November 15th, 2006, 11:30 AM
sukarof's Avatar
sukarof sukarof is offline
Very Frequent Poster
 
Join Date: Jun 2004
Location: Stockholm Sweden
Posts: 1,605
Default Drweb´s spiderml.exe trojan according to Microsoft?!

Hi

I did a scan with microsoft malicious software removal tool that came with latest updates.
It claims that spiderml.exe is a trojan. (Spiderml.exe is a part of Drweb antivirus)

I did a scan at jottis and got this worrying message:

Quote:
spiderml.exe
Status:
MIGHT BE INFECTED/MALWARE (Sandbox emulation took a long time and/or runtime packers were found, this is suspicious. Normally programs aren't packed and don't force the sandbox into lengthy emulation. Do realize no scanner issued any warning, the file can very well be harmless. Caution is advised, however.) (Note: this file has been scanned before. Therefore, this file's scan results will not be stored in the database)

None of the AV´s at jottis did however find anything.

From microsoft:

Quote:
Malicious Software Encyclopedia: Backdoor:Win32/Hackdef.L
Published: September 19, 2006

Backdoor:Win32/Hackdef.L is a backdoor Trojan that is distributed in various ways to computers running certain versions of Microsoft Windows. This Trojan is a user-mode rootkit that creates, alters, and hides Windows system resources on an infected computer, and can hide proxy services and backdoor functionality. It can also conceal use of TCP and UDP ports for receiving commands from attackers.
Attached Images
 
__________________
OS: Windows 8 PRO 64bit
Imaging: Macrium Reflect Pro ver. 5. Image fo Windows. Virtualization: VMware Workstation .Passwordmanager: Lastpass Premium
AV/FW: Kaspersky Internet Security 2013 Currently testing: AX64 Time Machine.

Last edited by sukarof : November 15th, 2006 at 11:46 AM.
  #4  
Old November 15th, 2006, 12:31 PM
sukarof's Avatar
sukarof sukarof is offline
Very Frequent Poster
 
Join Date: Jun 2004
Location: Stockholm Sweden
Posts: 1,605
Default Re: Dr Web / MS Malicious Software Rmvl Tool Nov 14 2006

Thanks Bubba for moving my post here

And thanks CtrlAltDelete for the info. Seems I dont have to worry. I usually don't run the MS malicious removal tool. Now I know why I shouldn't

*edit*
Of course it was a false positive. Drweb was very quick to reply
Just a blooper from MS
__________________
OS: Windows 8 PRO 64bit
Imaging: Macrium Reflect Pro ver. 5. Image fo Windows. Virtualization: VMware Workstation .Passwordmanager: Lastpass Premium
AV/FW: Kaspersky Internet Security 2013 Currently testing: AX64 Time Machine.

Last edited by sukarof : November 15th, 2006 at 12:48 PM.
 

Wilders Security Forums > Security Products > other anti-virus software « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 05:58 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums