Two Plus Two Publishing LLC Two Plus Two Publishing LLC
 

Go Back   Two Plus Two Poker Forums > Other Topics > Computer Technical Help

Notices

Computer Technical Help Post your questions about computer hardware and software and configuring same here.

Reply
 
Thread Tools Display Modes
Old 02-02-2012, 01:09 PM   #1
grinder
 
Eclipse86's Avatar
 
Join Date: Dec 2006
Posts: 458
Trojans found in Absolute Poker Software (with MBAM)

I scan my computer with MBAM every 3 days. Today it started picking up this from the Absolute Poker install directory. The last scan I did prior to today was on Jan 30, 2012 in which everything was clean.


Malwarebytes Anti-Malware 1.60.0.1800
www.malwarebytes.org

Database version: v2012.02.02.04

Windows Vista Service Pack 1 x64 NTFS
Internet Explorer 7.0.6001.18000
User :: USER-PC [administrator]

2/2/2012 10:58:35 AM
mbam-log-2012-02-02 (12-54-35).txt

Scan type: Full scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 514184
Time elapsed: 1 hour(s), 2 minute(s), 45 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 1
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Uni nstall\Absolute Poker (Trojan.Agent) -> No action taken.

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 2
C:\Poker Application\Absolute Poker\CasinoUninstall.exe (Trojan.Agent) -> No action taken.
C:\Poker Application\_uninstallation_info\Absolute Poker\CasinoUninstall.exe (Trojan.Agent) -> No action taken.

(end)


Is anyone else picking this up with their MBAM?
Eclipse86 is offline   Reply With Quote
Old 02-02-2012, 04:23 PM   #2
Malware Jedi
 
Gabethebabe's Avatar
 
Join Date: Oct 2007
Location: In front of my monitor
Posts: 9,068
Re: Trojans found in Absolute Poker Software (with MBAM)

This looks like a standard false positive

or

MBAM thinks that peeking holecards is a characteristic of a trojan

Donīt worry about it.
Gabethebabe is offline   Reply With Quote
Old 02-02-2012, 05:07 PM   #3
journeyman
 
Join Date: Feb 2007
Posts: 321
Re: Trojans found in Absolute Poker Software (with MBAM)

I ran a full scan and it found nothing.
dealace1 is offline   Reply With Quote
Old 02-03-2012, 12:42 AM   #4
grinder
 
Eclipse86's Avatar
 
Join Date: Dec 2006
Posts: 458
Re: Trojans found in Absolute Poker Software (with MBAM)

Quote:
Originally Posted by Gabethebabe View Post
This looks like a standard false positive

or

MBAM thinks that peeking holecards is a characteristic of a trojan

Donīt worry about it.
Should I be worried about MBAM picking up the AP Registry Key as being malicious? Never encountered a FP before with a registry key, so not really sure what to make of it.
Eclipse86 is offline   Reply With Quote
Old 02-03-2012, 12:43 AM   #5
grinder
 
Eclipse86's Avatar
 
Join Date: Dec 2006
Posts: 458
Re: Trojans found in Absolute Poker Software (with MBAM)

Quote:
Originally Posted by dealace1 View Post
I ran a full scan and it found nothing.
Are you using the latest MBAM database update?
Could you scan just the AP install folder and post the log here?
Eclipse86 is offline   Reply With Quote
Old 02-03-2012, 06:55 AM   #6
stranger
 
SystEmsuX's Avatar
 
Join Date: Jul 2008
Location: Zapatista territory
Posts: 6
Re: Trojans found in Absolute Poker Software (with MBAM)

I got 2 Cereus detections, too, this morning from MBAM:

C:\Application\UltimateBet\CasinoUninstall.exe
C:\Poker Application\Absolute Poker\CasinoUninstall.exe

This hasn't happened before, but it has been a while since I've updated the software from all the sites where I (used to) play. If I'm not even accessing poker clients, can they still be a security threat?

Lately Avira has also been showing some Cake skins on my computer as being infected, FWIW. I don't know for sure whether any of these problems are just false positives, though. (I keep Secunia PSI's score at 100% religiously, so I'm especially surprised to suddenly see several detections seemingly from out of nowhere.)
SystEmsuX is offline   Reply With Quote
Old 02-03-2012, 08:16 AM   #7
grinder
 
Eclipse86's Avatar
 
Join Date: Dec 2006
Posts: 458
Re: Trojans found in Absolute Poker Software (with MBAM)

I posted this over to the MBAM false positive forum as well.

http://forums.malwarebytes.org/index...owtopic=105681
Eclipse86 is offline   Reply With Quote
Old 02-03-2012, 08:21 AM   #8
grinder
 
Eclipse86's Avatar
 
Join Date: Dec 2006
Posts: 458
Re: Trojans found in Absolute Poker Software (with MBAM)

Quote:
Originally Posted by SystEmsuX View Post
I got 2 Cereus detections, too, this morning from MBAM:

C:\Application\UltimateBet\CasinoUninstall.exe
C:\Poker Application\Absolute Poker\CasinoUninstall.exe

This hasn't happened before, but it has been a while since I've updated the software from all the sites where I (used to) play. If I'm not even accessing poker clients, can they still be a security threat?
Can you post the MBAM log here?
Eclipse86 is offline   Reply With Quote
Old 02-03-2012, 04:03 PM   #9
stranger
 
SystEmsuX's Avatar
 
Join Date: Jul 2008
Location: Zapatista territory
Posts: 6
Re: Trojans found in Absolute Poker Software (with MBAM)

Database version: v2012.02.03.04

Windows Vista Service Pack 2 x64 NTFS
Internet Explorer 9.0.8112.16421
Brice :: BRICE-PC [administrator]

2/3/2012 2:31:18 AM
mbam-log-2012-02-03 (02-31-18).txt

Scan type: Full scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 425710
Time elapsed: 2 hour(s), 26 minute(s), 28 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 2
C:\Application\UltimateBet\CasinoUninstall.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Poker Application\Absolute Poker\CasinoUninstall.exe (Trojan.Agent) -> Quarantined and deleted successfully.

(end)
SystEmsuX is offline   Reply With Quote
Old 02-04-2012, 12:00 AM   #10
grinder
 
Eclipse86's Avatar
 
Join Date: Dec 2006
Posts: 458
Re: Trojans found in Absolute Poker Software (with MBAM)

Update:

Just updated MBAM again today and scanned again (with Database version: v2012.02.03.11) and MBAM is no longer detecting those 3 things.
Eclipse86 is offline   Reply With Quote

Reply
      

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off



All times are GMT -4. The time now is 03:45 PM.


Powered by vBulletin®
Copyright ©2000 - 2012, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.6.0 ©2011, Crawlability, Inc.
Copyright Đ 2008-2010, Two Plus Two Interactive