Wilders Security Forums  

Go Back   Wilders Security Forums > Official BrightFort Forum > SpywareBlaster & Other Forum
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old June 24th, 2010, 01:58 PM
_Kim_ _Kim_ is offline
Infrequent Poster
 
Join Date: Jun 2010
Posts: 4
Default SpywareBlaster Need Developer Help

Hello,
At this moment I'm getting help from a security expert on an issue I'm having with an alternate data stream. We are investigating the file 5C321E34.tmp that can be found in the /ProgramData/TEMP and Users/All Users/TEMP directories. I found a link when reseraching this file that states it is created by SpywareBlaster, can a developer confirm or deny this please, because I dont want to waste this guys time on a false positive.

Thank you. Kim.
  #2  
Old June 24th, 2010, 02:28 PM
Cudni's Avatar
Cudni Cudni is offline
Global Moderator
 
Join Date: May 2009
Location: Somethingshire
Posts: 6,944
Default Re: SpywareBlaster Need Developer Help

Looking at a thread here it seems OA is detecting it
http://support.tallemu.com/vbforum/s...142#post126142
and at linked comment
http://support.tallemu.com/vbforum/s...76&postcount=2

it sounds more like an FP. What other software did you use to scan the machine? What makes you think SB is creating the file?
__________________
once we only had ideals, today they are the only things we are missing
Microsoft MVP, 2006 - 2013/14
  #3  
Old June 24th, 2010, 02:39 PM
_Kim_ _Kim_ is offline
Infrequent Poster
 
Join Date: Jun 2010
Posts: 4
Default Re: SpywareBlaster Need Developer Help

The first link you posted was created by me and yes OA++ has detected it. OTL and ADSspy are both detecting it also, the reason I think it was created by SpywareBlaster is this thread http://www.wilderssecurity.com/showthread.php?t=218483 It makes alot of sense for it to be a FP but I just want it confirmed.
  #4  
Old June 24th, 2010, 02:53 PM
Cudni's Avatar
Cudni Cudni is offline
Global Moderator
 
Join Date: May 2009
Location: Somethingshire
Posts: 6,944
Default Re: SpywareBlaster Need Developer Help

Thanks for the link. I see it on Win7 as well. I have deleted the file and on SB restart the file comes back.
__________________
once we only had ideals, today they are the only things we are missing
Microsoft MVP, 2006 - 2013/14

Last edited by Cudni : June 24th, 2010 at 03:04 PM. Reason: further findings
  #5  
Old June 24th, 2010, 03:04 PM
_Kim_ _Kim_ is offline
Infrequent Poster
 
Join Date: Jun 2010
Posts: 4
Default Re: SpywareBlaster Need Developer Help

Interesting Cudni, can I ask if you used ADSspy to scan for it? Alternate data streams can not be seen by explorer even with "show hidden files and folders" "hide protected operating system files" selected/unselected. I'm using Vista myself, there could be some difference there too.
  #6  
Old June 24th, 2010, 03:06 PM
Cudni's Avatar
Cudni Cudni is offline
Global Moderator
 
Join Date: May 2009
Location: Somethingshire
Posts: 6,944
Default Re: SpywareBlaster Need Developer Help

No, I used AlternateStreamView from Nirsoft
__________________
once we only had ideals, today they are the only things we are missing
Microsoft MVP, 2006 - 2013/14
  #7  
Old June 24th, 2010, 03:36 PM
_Kim_ _Kim_ is offline
Infrequent Poster
 
Join Date: Jun 2010
Posts: 4
Default Re: SpywareBlaster Need Developer Help

Well after a bit more work it seems I have a result, I would like it confirmed by a member of the developement team just to be sure.

Without SpywareBlaster.
http://img155.imageshack.us/img155/293/proofmi.jpg

With SpywareBlaster.
http://img64.imageshack.us/img64/9219/proof2z.jpg
 

Wilders Security Forums > Official BrightFort Forum > SpywareBlaster & Other Forum « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 11:34 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums