False positive or Avast infected ? [ C:\Windows\System32\actskin4.ocx ]

Hi. 8)

I am using Avast uptodate and MalwareByte’s Antimalware (free edition, scanning only) on XP SP3.

So…

Today, I’ve checked with MalwareByte’s Antimalware my computer (I do that nearly every day), it has found 19 references (most of them in Registry) and one interesting in:

C:\Windows\System32\actskin4.ocx

My first reaction was not to use the cleaning possibility of AntiMalware, but to come back to a restore point I knew “safe”.

So… I dit it.

Reboot, restore to a point 2 days before, re scan… and same thing: re scan with MalwareByte’s Antimalware… 19 references still there.

This time I used the cleaning possibility of that software, reboot, rescan. Ok, everything has disappeared.
Just to be sure, I used Spybot, nothing (just cookies).

So… I tried an update (software update) of Avast, something was available (because of my XP restore point ?), with an asked reboot.

Reboot… Ok.

But, I do not know why, I’ve checked again with MalwareByte’s Antimalware … and those 19 references of infestation (Trojan) were here again !
It occured after that Avast updating (and Reboot).

So: is Avast infected ? Is it a false positive from MalwareByte’s Antimalware ?

What I can say is that I am always using uptodate software.

This is the list of what MalwareByte’s had cleared at first attempt:

Register Keys infected: HKEY_CLASSES_ROOT\CLSID\{0944d16c-d0f4-4389-982a-a085595a9eb3} (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{3831331e-0d11-4716-871d-68f3b11d23c9} (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{3dcd2bc5-8489-48ae-891f-90c8b2f19f56} (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{52c01a76-19e2-4a50-ae8a-38ffbccf9182} (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{5954ea75-9bfa-461a-bd34-cea3a861ff19} (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{762ec429-1a5d-4ab8-844a-9a552e1241da} (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{a506ef88-9efc-4522-bfe1-a8e886a64d80} (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{a5704c37-40da-49ef-904b-97e5f5f9b1c5} (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{b87799af-2ce9-4daa-93cf-65f002035369} (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{bbc73c94-337c-43cc-b52c-31eb9fa34013} (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{c406f816-318d-4f7d-81cb-ba93ca7b70d5} (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{d502d4a3-03e6-4eae-a14e-69606ca63430} (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{ec22770d-3343-4c56-8a8d-3e560475f655} (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{4921908c-7090-4d37-a6b3-fc447f08378a} (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{750fc67c-0311-4391-9864-a2efed49bd28} (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{f3fc950c-7583-4377-bad8-efbeaa33273c} (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\TypeLib\{90f3d7b3-92e7-44ba-b444-6a8e2a3bc375} (Trojan.Agent) -> Quarantined and deleted successfully.

Infected Register value:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs\C:\WINDOWS\system32\actskin4.ocx (Trojan.Agent) → Quarantined and deleted successfully

Infected File:
C:\WINDOWS\system32\actskin4.ocx (Trojan.Agent) → Quarantined and deleted successfully.

Could you tell me if those references are relevant with Avast ?
What do you think: False positive or real threat ?

Thanks. :slight_smile:

Hello Fbzn ,

no need to restore using system restore. instead you can restore the delete files from malware bytes antimalware quarantine. restore all the 19 items and reboot. avast should work even without rebooting.

more info :

http://forum.avast.com/index.php?topic=49100.0

Thanks for your link nmb.

I can see I’m not alone. ;D

Yes there are many. and there are multiple topics seen on this fp in mbam forums.

I have problem with MBAM 1.41 WITH FALSE POSITIVE.It,s false positive this report MBAM after scanning my system???

10/1/2009 12:14:01 PM
mbam-log-2009-10-01 (12-14-01).txt

Tipul scanarii: Scanare totala (C:|D:|)
Obiecte scanate: 74657
Timp trecut: 27 minute(s), 51 second(s)

Procese din memorie afectate: 0
Module de memorie afectate: 0
Chei de registri infectate: 17
Valori din registri afectate: 1
Elemente din registri infectate: 0
Foldere infectate: 0
Fisiere infectate: 1

Procese din memorie afectate:
(Nici un element periculos nu a fost detectat)

Module de memorie afectate:
(Nici un element periculos nu a fost detectat)

Chei de registri infectate:
HKEY_CLASSES_ROOT\CLSID{3831331e-0d11-4716-871d-68f3b11d23c9} (Trojan.Agent) → Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib{90f3d7b3-92e7-44ba-b444-6a8e2a3bc375} (Trojan.Agent) → Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface{4921908c-7090-4d37-a6b3-fc447f08378a} (Trojan.Agent) → Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface{750fc67c-0311-4391-9864-a2efed49bd28} (Trojan.Agent) → Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface{f3fc950c-7583-4377-bad8-efbeaa33273c} (Trojan.Agent) → Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID{0944d16c-d0f4-4389-982a-a085595a9eb3} (Trojan.Agent) → Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID{3dcd2bc5-8489-48ae-891f-90c8b2f19f56} (Trojan.Agent) → Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID{52c01a76-19e2-4a50-ae8a-38ffbccf9182} (Trojan.Agent) → Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID{5954ea75-9bfa-461a-bd34-cea3a861ff19} (Trojan.Agent) → Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID{762ec429-1a5d-4ab8-844a-9a552e1241da} (Trojan.Agent) → Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID{a506ef88-9efc-4522-bfe1-a8e886a64d80} (Trojan.Agent) → Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID{a5704c37-40da-49ef-904b-97e5f5f9b1c5} (Trojan.Agent) → Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID{b87799af-2ce9-4daa-93cf-65f002035369} (Trojan.Agent) → Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID{bbc73c94-337c-43cc-b52c-31eb9fa34013} (Trojan.Agent) → Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID{c406f816-318d-4f7d-81cb-ba93ca7b70d5} (Trojan.Agent) → Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID{d502d4a3-03e6-4eae-a14e-69606ca63430} (Trojan.Agent) → Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID{ec22770d-3343-4c56-8a8d-3e560475f655} (Trojan.Agent) → Quarantined and deleted successfully.

Valori din registri afectate:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs\C:\WINDOWS\system32\actskin4.ocx (Trojan.Agent) → Quarantined and deleted successfully.

Elemente din registri infectate:
(Nici un element periculos nu a fost detectat)

Foldere infectate:
(Nici un element periculos nu a fost detectat)

Fisiere infectate:
C:\WINDOWS\system32\actskin4.ocx (Trojan.Agent) → Quarantined and deleted successfully.

What happened???/Is problem with Avast??? or MBAM transform in bullshit antimalware???program

I use Avast to more 3 years and I considered the best in the world.I hope is real the best this antivirus.I want think this.

http://forum.avast.com/index.php?topic=49100.0