Page 1 of 1

Slimjet web-setup exhumed by Malwarebytes.

Posted: Wed Feb 07, 2018 2:37 am
by saurabhdua
Hello!

My recent system scan with the latest version of Malwarebytes has left the web-installer of Slimjet >> entirely exhumed !

The web-installer were recognized as PUP & default action of MBAM - 'Quarantine' has made that disappear from my downloads folder.

Scan log is enclosed herewith...& Inputs in this regard will be sincerely appreciated. Thank you.

Malwarebytes
www.malwarebytes.com

-Log Details-
Scan Date: 2/7/18
Scan Time: 1:32 PM
Log File: 48d3e72f-0bdd-11e8-b880-10bf48779e96.json
Administrator: Yes

-Software Information-
Version: 3.3.1.2183
Components Version: 1.0.262
Update Package Version: 1.0.3887
License: Free

-System Information-
OS: Windows 7 Service Pack 1
CPU: x86
File System: NTFS
User: Mushkin-PC\Mushkin

-Scan Summary-
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 158778
Threats Detected: 1
Threats Quarantined: 1
Time Elapsed: 3 min, 47 sec

-Scan Options-
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Enabled
Heuristics: Enabled
PUP: Detect
PUM: Detect

-Scan Details-
Process: 0
(No malicious items detected)

Module: 0
(No malicious items detected)

Registry Key: 0
(No malicious items detected)

Registry Value: 0
(No malicious items detected)

Registry Data: 0
(No malicious items detected)

Data Stream: 0
(No malicious items detected)

Folder: 0
(No malicious items detected)

File: 1
PUP.Optional.InstallCore, C:\USERS\MUSHKIN\DOWNLOADS\SJTWEBSETUP_X86.EXE, Quarantined, [2], [424266],1.0.3887

Physical Sector: 0
(No malicious items detected)


(end)

Re: Slimjet web-setup exhumed by Malwarebytes.

Posted: Wed Feb 07, 2018 8:33 am
by oftentired
upload it to virustotal.com for a scan

Re: Slimjet web-setup exhumed by Malwarebytes.

Posted: Fri Mar 09, 2018 1:15 pm
by MikeJenkins

Re: Slimjet web-setup exhumed by Malwarebytes.

Posted: Fri Mar 09, 2018 7:23 pm
by oftentired
Where did you get the file?

When I click on the webinstaller and download it and check the SHA-256 signature it doesn't match the file size or SHA-256 signature of the one that you uploaded to virustotal.

Re: Slimjet web-setup exhumed by Malwarebytes.

Posted: Sat Mar 10, 2018 11:19 am
by sleeper10
oftentired,

I can't check on linux, but how does that file scan on virustotal, better or same as his? You might also scan it here:
https://www.hybrid-analysis.com/

Like you, I suspect a bad file source &/or false positives.