Jump to content


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.

Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.


Malwarebytes - I dont understand this!?

  • Please log in to reply
No replies to this topic

#1 wish2learn


  • Members
  • 72 posts
  • Local time:06:33 AM

Posted 03 July 2010 - 11:57 AM


I have a query regarding Malwarebytes; when an installer (exe) is found by Malwarebytes to be infected and yet the installed Program itself is not??

I have Windows XP and sometime around November 2009 I downloaded and installed a small freeware sound program that looked interesting.

I update Malwarebytes regularly but only today it found a dangerous virus Trojan.Dropper located in an exe installation file - which it has many times before previously scanned but never before identified.
Here is the info regarding the Trojan from the Malwarebytes site:
Date spotted:
First seen on 2008-01-21.
Last seen on 2010-07-03.

Detection statistics:
This object is 1.09% of all objects detected.
40,012,406 instances detected worldwide.

Another puzzlement is that although the Trojan has been located in the installer (exe) file, when I go to scan the Program itself (located in Program Files) and installed from an apparently infected installer file - it comes up clean! I have deleted the installer file but it doesn't make sense that the installer is infected and yet the program itself is deemed clean.

Here is the log:

Malwarebytes' Anti-Malware 1.46

Database version: 4269

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

7/3/2010 6:36:06 PM
mbam-log-2010-07-03 (18-36-06).txt

Scan type: Quick scan
Objects scanned: 1
Time elapsed: 4 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
F:\My Health\NanoVoice\nanoVoiceBetaSetup2.0.exe (Trojan.Dropper) -> No action taken.

Please advise?


Edited by Orange Blossom, 03 July 2010 - 03:15 PM.
Move to AII as no logs posted and prep. guide not followed. ~ OB

BC AdBot (Login to Remove)


0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users