Malwarebytes Anti-Rootkit BETA

Discussion in 'other anti-malware software' started by Cudni, Nov 10, 2012.

  1. Ranget

    Ranget Registered Member

    Joined:
    Mar 24, 2011
    Posts:
    846
    Location:
    Not Really Sure :/
    hello i don't have any malware experience

    but i tried this malware :
    RKdemo1.2 by EP_X0FF & MP_ART
    hxxp://www.kernelmode.info/forum/viewtopic.php?f=11&t=624

    MBAR didn't detect it nor MBAM
     
  2. jmonge

    jmonge Registered Member

    Joined:
    Mar 20, 2008
    Posts:
    13,550
    Location:
    Canada
    very bad
     
  3. nosirrah

    nosirrah Malware Fighter

    Joined:
    Aug 25, 2006
    Posts:
    561
    Location:
    Cummington MA USA
    All that proves is that a non-malicious rootkit from more than a year before MBAR existed was not detected.

    That has nothing to do with any malware that exists today.

    We can add detection for this demo but do not be fooled into thinking that this will protect you from anything today better than before.
     
  4. nosirrah

    nosirrah Malware Fighter

    Joined:
    Aug 25, 2006
    Posts:
    561
    Location:
    Cummington MA USA
    There is no test to determine if a change is made intentionally or by malware so we always opt to help the novice user assuming that the experienced user will understand and dismiss the detection.
     
  5. Victek

    Victek Registered Member

    Joined:
    Nov 30, 2007
    Posts:
    6,053
    Location:
    USA
    Yes, I don't understand the objection to this, other than the semantics of referring to the changes as malware instead of as possibly caused by malware. It is not sufficient for any security product to only remove malware. It is also necessary to reverse any changes to the system made by the malware. After cleaning a system I typically have to go through additional steps to manually fix things such as Windows Updates and the Security Center, so I appreciate that MBAR can do this directly.
     
  6. Mops21

    Mops21 Registered Member

    Joined:
    Oct 5, 2010
    Posts:
    2,268
    Location:
    Germany
  7. Tarnak

    Tarnak Registered Member

    Joined:
    Feb 5, 2007
    Posts:
    4,875
    Latest scan...

    ScreenShot_mbar14_04.gif

    P.S. I ran these earlier today, but they were not flagged by the new MBAM v2.0 beta that is still under restricted testing.

    I have posted about that experience in the beta testing sub-forum, earlier today.
     
  8. Tarnak

    Tarnak Registered Member

    Joined:
    Feb 5, 2007
    Posts:
    4,875
    Malwarebytes Anti-Rootkit BETA 1.07.0.1008
    www.malwarebytes.org

    Database version: v2013.12.25.03

    Windows XP Service Pack 3 x86 NTFS
    Internet Explorer 6.0.2900.5512
    <My Name> :: Removed identifying info [limited]

    25/12/2013 9:37:37 PM
    mbar-log-2013-12-25 (21-37-37).txt

    Scan type: Quick scan
    Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken
    Scan options disabled:
    Objects scanned: 231555
    Time elapsed: 1 hour(s), 8 minute(s), 3 second(s)

    Memory Processes Detected: 0
    (No malicious items detected)

    Memory Modules Detected: 0
    (No malicious items detected)

    Registry Keys Detected: 0
    (No malicious items detected)

    Registry Values Detected: 0
    (No malicious items detected)

    Registry Data Items Detected: 0
    (No malicious items detected)

    Folders Detected: 0
    (No malicious items detected)

    Files Detected: 10
    C:\Documents and Settings\<My Name>\Desktop\Spycar_tests\AlterHostsFile.exe (Simulation.Spycar) -> No action taken.
    C:\Documents and Settings\<My Name>\Desktop\Spycar_tests\HKCU_Run.exe (Simulation.Spycar) -> No action taken.
    C:\Documents and Settings\<My Name>\Desktop\Spycar_tests\HKCU_RunOnce.exe (Simulation.Spycar) -> No action taken.
    C:\Documents and Settings\<My Name>\Desktop\Spycar_tests\HKCU_RunOnceEx.exe (Simulation.Spycar) -> No action taken.
    C:\Documents and Settings\<My Name>\Desktop\Spycar_tests\HKLM_Run.exe (Simulation.Spycar) -> No action taken.
    C:\Documents and Settings\<My Name>\Desktop\Spycar_tests\HKLM_RunOnce.exe (Simulation.Spycar) -> No action taken.
    C:\Documents and Settings\<My Name>\Desktop\Spycar_tests\HKLM_RunOnceEx.exe (Simulation.Spycar) -> No action taken.
    C:\Documents and Settings\<My Name>\Desktop\Spycar_tests\IE-HomePageLock.exe (Simulation.Spycar) -> No action taken.
    C:\Documents and Settings\<My Name>\Desktop\Spycar_tests\IE-KillAdvancedTab.exe (Simulation.Spycar) -> No action taken.
    C:\Documents and Settings\<My Name>\Desktop\Spycar_tests\IE-KillConnectionsTab.exe (Simulation.Spycar) -> No action taken.

    Physical Sectors Detected: 0
    (No malicious items detected)

    (end)
     
  9. controler

    controler Guest

    does the 2.00 have the same option to not show pup's?

    also none of thode spycar tests are signed so ie will give opyion to not run them. they need a fake sig too?
     
  10. Mops21

    Mops21 Registered Member

    Joined:
    Oct 5, 2010
    Posts:
    2,268
    Location:
    Germany
  11. BoerenkoolMetWorst

    BoerenkoolMetWorst Registered Member

    Joined:
    Dec 22, 2009
    Posts:
    4,442
    Location:
    Outer space

    Version 1.07.0.1009 of MBAR BETA is now available for download.

    Highlights of this release:

    Error code 20026 is no longer displayed after removing certain rootkits
    Eliminated BSODs under certain scenarios when using MBAR
    Fixed issue where MBAR did not unload its drivers properly when done running under certain scenarios
    Fixed false positives under certain scenarios when system files were compressed on the drive being scanned


    https://forums.malwarebytes.org/index.php?showtopic=140916
     
  12. MrBrian

    MrBrian Registered Member

    Joined:
    Feb 24, 2008
    Posts:
    6,032
    Location:
    USA
    1.7.0.1012 Beta is available.
     
  13. Tarnak

    Tarnak Registered Member

    Joined:
    Feb 5, 2007
    Posts:
    4,875
    I am still running MBAM v1.75 here, even though I have updated my other snapshot to v2.00.

    Also, one can tell I haven't run an MBAM scan in this snapshot in quite awhile.

    ScreenShot_Mbar16_v1.7.0.1012_08.gif .... ScreenShot_Mbar16_v1.7.0.1012_09.gif
     
  14. Tarnak

    Tarnak Registered Member

    Joined:
    Feb 5, 2007
    Posts:
    4,875
    Database updated successfully, but ends up being different. Maybe it is the anti-rootkit DB that is showing, now? This wouldn't be updated, so often.

    ScreenShot_Mbar16_v1.7.0.1012_10.gif
     
  15. Tarnak

    Tarnak Registered Member

    Joined:
    Feb 5, 2007
    Posts:
    4,875
    Scanning has been underway for half an hour...

    ScreenShot_Mbar16_v1.7.0.1012_14.gif
     
  16. Tarnak

    Tarnak Registered Member

    Joined:
    Feb 5, 2007
    Posts:
    4,875
    Getting close to the end of the scan....I think. ;)

    ScreenShot_Mbar16_v1.7.0.1012_16.gif
     
  17. Tarnak

    Tarnak Registered Member

    Joined:
    Feb 5, 2007
    Posts:
    4,875
    I was right! :)

    ScreenShot_Mbar16_v1.7.0.1012_17.gif
     
  18. controler

    controler Guest

    Get these to alerts, One from Voodoshirld and one from my WIm 81. system while trying to run this new beta.
     

    Attached Files:

  19. controler

    controler Guest

    ---------------------------
    Probable rootkit activity detected
    ---------------------------
    Registry value "AppInit_Dlls" has been found, which may be caused by rootkit activity.
    Note: Press "No" button if you're not sure. If the tool crashes or terminates unexpectedly during a system scan, restart the tool and press "Yes" should this message appear again.
    Do you want to remove this value and restart the tool?
    ---------------------------
    Yes No
    ---------------------------
     
  20. TairikuOkami

    TairikuOkami Registered Member

    Joined:
    Oct 10, 2005
    Posts:
    3,112
    Location:
    Slovakia
    Good thing, that I have tried it out, it gave some false positive, most likely a leftover from IoBit software, but it saved me 343 MB. :thumb:
     

    Attached Files:

  21. trott3r

    trott3r Registered Member

    Joined:
    Jan 21, 2010
    Posts:
    1,259
    Location:
    UK

    I got this when running XP as well.
    I Didnt remove it.

    What did you do?
     
  22. Mops21

    Mops21 Registered Member

    Joined:
    Oct 5, 2010
    Posts:
    2,268
    Location:
    Germany
  23. Tarnak

    Tarnak Registered Member

    Joined:
    Feb 5, 2007
    Posts:
    4,875
    Just tried the latest beta earlier today, and got a BSOD on XP

    ScreenShot_MBar_1.08.3.1004_bsod_01.gif
     
  24. Mops21

    Mops21 Registered Member

    Joined:
    Oct 5, 2010
    Posts:
    2,268
    Location:
    Germany
  25. Tarnak

    Tarnak Registered Member

    Joined:
    Feb 5, 2007
    Posts:
    4,875
    Running now...

    ScreenShot_mbar_1.09.1.1004 beta_06.gif ScreenShot_mbar_1.09.1.1004 beta_09.gif ScreenShot_mbar_1.09.1.1004 beta_10.gif ScreenShot_mbar_1.09.1.1004 beta_11.gif ScreenShot_mbar_1.09.1.1004 beta_14.gif
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.