BleepingComputer.com: Rkill.com listed as infected by Trojan.BankerBot.Gen in mbam.log

Jump to content

Forum Rules

When posting your problem, do not run and post a ComboFix log. ComboFix is a tool that should only be run under the supervision of someone who has been trained in its use. Using it on your own can cause problems with your computer. Any posts containing CF Logs will be ignored.

To receive help, you should instead provide a detailed description of your problem, detailed word-for-word error messages that you are receiving, screenshots of strange behaviour, and your operating system. This information is much more useful to our helpers than a ComboFix log.


If you have not received help after three days, please post a link to your topic HERE.
Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

Rkill.com listed as infected by Trojan.BankerBot.Gen in mbam.log Trojan.BankerBot.Gen

#1 User is offline   Tim Salm 

  • New Member
  • Pip
  • Find Topics
  • Group: Members
  • Posts: 1
  • Joined: 26-May 11

Posted 26 May 2011 - 03:37 PM

I have a co-worker who ran rkill.com and Malwarebytes' Anti-Malware earlier today. The mbam.log file included the following information.

Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Database version: 6685

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

5/26/2011 11:16:56 AM
mbam-log-2011-05-26 (11-16-56).txt

Scan type: Full scan (C:\|)
Objects scanned: 242089
Time elapsed: 15 minute(s), 35 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 2

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
c:\documents and settings\xxxxxxx\Desktop\rkill.com (Trojan.BankerBot.Gen) -> Quarantined and deleted successfully.
c:\documents and settings\xxxxx\Desktop\rkill.com (Trojan.BankerBot.Gen) -> Quarantined and deleted successfully.

My co-worker believes that rkill.com was the source of the infection. I attempted to replicate the issue on my PC and it did not find any infected files (and, more importantly, any infected files associated with rkill.com). What, if anything, should I make of this? Any possible explanations?

#2 User is offline   mkbcomputerrepair 

  • New Member
  • Pip
  • Find Topics
  • Group: Members
  • Posts: 1
  • Joined: 28-May 11

Posted 28 May 2011 - 10:13 PM

I had the same problem just the other day. I have copies of Rkill and iexplore (same file different name) on my Dell laptop. I also have copies on a flash drive that I use to fix clients computers that have malware infections.

I ran MalwareBytes. The copies on my flash drive were infected with trojan.bankerbot.gen, but NOT the copies on my Dell computer. The copies on my flash drive are themselves copies of the the ones on my Dell computer. This tells me that the copies on my flash drive probably got infected themselves when I used the flash drive to remove malware from a clients computer.

#3 User is offline   Liuqin 

  • New Member
  • Pip
  • Find Topics
  • Group: Members
  • Posts: 1
  • Joined: 26-May 11

Posted 31 May 2011 - 06:58 PM

had same thing , detected by malbytes, downloaded newer version of rkill, isolated old one and scanned separate, this time nothing. Deleted it anyway. Rescanned with malbytes again, full scan and got this:


Malwarebytes' Anti-Malware 1.50
www.malwarebytes.org

Database version: 6682

Windows 5.1.2600 Service Pack 1 (Safe Mode)
Internet Explorer 6.0.2800.1106

31/05/2011 6:51:26 PM
mbam-log-2011-05-31 (18-51-26).txt

Scan type: Full scan (C:\|)
Objects scanned: 535962
Time elapsed: 3 hour(s), 4 minute(s), 53 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
c:\system volume information\_restore{987e0331-0f01-427c-a58a-7a2e4aabf84d}\RP280\A0053201.exe (Trojan.BankerBot.Gen) -> Quarantined and deleted successfully.

Share this topic:


Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users