Trojan in Malwarebytes Free

I was just rreading a 2014 forum thread re Malwarebytes ans trojans

I just downloaded the 'free' Malwarebytes after being prompted to update.I only use the free version and only scan monthly for malware.

Instead of getting the usual free version it kept installing a free trial version. Norton warned this was very new and only 4 Norton users had downloaded it, I thought as Malwarebytes it will be OK (direct from their site).

After the third installation, I ran a scan. It found a trojan, situated in the new Malwarebytes program!

I have uninstalled Malwarebytes now as it has made me nervous and I'm waiting for their response to my email about this.

I just wondered if anyone else has expereienced this problem.

Thanks to all of you!

R Palmer:

[..], I was able to get rid of the Trial version , must say it is certainly more complicated than the old Free Version download, I'm sure most users will never know that process.

Yeah, I missed Deactivate Premium Trial until Imacri pointed to the support article How-To: Deactivate Trial version in Malwarebytes 3.  

R Palmer:

Thanks! Looking for that log. I found a Malwarebytes folder, couldn't open any logs, but one file was setup. I was surprised as when I uninstalled the program, I didn't think any of Malwarebytes remained!

They may be difficult to read / open. If you zip the log files you found you should be able to upload them here.

Anyway, I ran setup, then using Imacri's instructions above, I was able to get rid of the Trial version , must say it is certainly more complicated than the old Free Version download, I'm sure most users will never know that process.

I ran a scan, no Trojan, zero problems, so all is well. Thank you all for your help.

Hi imacri, 

Here is the reply I sent to Password-password below: Thanks for that de-activate tip, pity the thousands of MWB users who will never get that!

+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Thanks! Looking for that log. I found a Malwarebytes folder, couldn't open any logs, but one file was setup. I was surprised as when I uninstalled the program, I didn't think any of Malwarebytes remained!

Anyway, I ran setup, then using imacri's instructions above, I was able to get rid of the Trial version , must say it is certainly more complicated than the old Free Version download, I'm sure most users will never know that process.

I ran a scan, no Trojan, zero problems, so all is well. Thank you all for your help.

Copy of my message to Password-password below!

Thanks! Looking for that log. I found a Malwarebytes folder, couldn't open any logs, but one file was setup. I was surprised as when I uninstalled the program, I didn't think any of Malwarebytes remained!

Anyway, I ran setup, then using Norton Fighter's instructions above, I was able to get rid of the Trial version , must say it is certainly more complicated than the old Free Version download, I'm sure most users will never know that process.

I ran a scan, no Trojan, zero problems, so all is well. Thank you all for your help.

Thanks! Looking for that log. I found a Malwarebytes folder, couldn't open any logs, but one file was setup. I was surprised as when I uninstalled the program, I didn't think any of Malwarebytes remained!

Anyway, I ran setup, then using Imacri's instructions above, I was able to get rid of the Trial version , must say it is certainly more complicated than the old Free Version download, I'm sure most users will never know that process.

I ran a scan, no Trojan, zero problems, so all is well. Thank you all for your help.

R Palmer:

[...]

The Trojan would've shown in Malwarebytes, but I uninstalled the program just in case, so no record.

[...]

We are saying the log may be left behind. Go to:

%PROGRAMDATA%\Malwarebytes\MBAMService\ScanResults\

You can zip and upload if you want, or you can examine the file yourself (it may be hard to read).

ohhh, so old, that is interesting to compare 

Thanks for this imacri, I can't find any reference to it in Norton, maybe because it only flagged the download as needing attention.

The Trojan would've shown in Malwarebytes, but I uninstalled the program just in case, so no record.

I'll just have to see what Malwarebytes support says....if they ever reply!

lmacri:

MB v3.x scan logs are now stored in the %PROGRAMDATA%\Malwarebytes\MBAMService\ScanResults folder as .json (i.e., not formatted .txt or .log) files.....

Hi R Palmer:

Without more information, my best guess is that a problem occurred during the download of your mb3-setup-consumer-3.2.2.2029.exe installer that caused the download to abort and corrupt the installer. That could have triggered MB to flag the installer as a suspected Trojan when it scanned the file.

If your Malwarebytes .json scan logs were deleted when you uninstalled MB v3.2.2, the only other suggestion I have is that you open your Norton File Insight report for the "problem" mb3-setup-consumer-3.2.2.2029.exe installer at Security | History  | Show | Download Insight [the log entry will likely have a severity of Low (yellow), Medium (orange) or High (red) instead of Info (blue)], click the Copy to Clipboard link, and then paste the contents of that report into your next post.  That might give us some information about whether there was a partial download (e.g., the filename ended with .exe.part instead of .exe) or the SHA-256 hash (digital signature) of the installer was altered.

Here's a partial extract of my own detailed log for the "safe" mb3-setup-consumer-3.2.2.2029.exe installer:

____________________________

Many Users:  Tens of thousands of users in the Norton Community have used this file.
New:               This file was released 13 days ago.
Good:             Norton has given this file a good rating.
___________________________

https:// data-cdn.mbamupdates.com/web/mb3-setup-consumer/mb3-setup-consumer-3.2.2.2029.exe
____________________________

File Thumbprint - SHA:
d02b91b47647a7545e7bb021711bbaf4cb7045d2088a39cce5b6e3c8ceb3eda0
File Thumbprint - MD5:
bb8435aea68e5bcb2fc93d68c10c6de0

------------
32-bit Vista Home Premium SP2 * Firefox ESR v52.3.0 * NS Premium v22.10.1.10 * MB Premium v3.2.2

R Palmer:

I actually tried both these sites and each time Norton flagged as 'need attention' said there was not enough information to give it a clear. I went ahead after the third installation try and did the scan using my new Premium Trial Malwarebytes, that's when it quarantined a Trojan contained in its own newly installed program!

Hi R Palmer:

The File Insight report for the mb3-setup-consumer-3.2.2.2029.exe installer I downloaded today (Security | History  | Show | Download Insight) says "Tens of thousands of users" and "released 12 days ago".  If you click the Check for New Rating link in your File Insight report as shown below it should check again for the latest trust ratings for the installer and might give the file a Good trust rating this time.

Just an FYI, though.  I have MB Premium v3 and find that the real-time Web Protection sometimes interferes with connections to the Symantec's backend Insight servers - see my comments <here> in the Malwarebytes forum about how this sometimes causes Norton Download Insight to throw one of these "no available reputation information" warnings on my 32-bit machine. I currently have Web Protection disabled in MB Premium v3.2.2 to prevent these connection problems but once you switch from the 14-day trial version of MB Premium (with real-time protection enabled) to MB Free (no real-time protection) you shouldn't have to worry about possible conflicts with Norton.

password_password:

Your log may still exist saved somewhere. I don't know exactly where the log is saved, someone else my add additional info.

MB v3.x scan logs are now stored in the %PROGRAMDATA%\Malwarebytes\MBAMService\ScanResults folder as .json (i.e., not formatted .txt or .log) files - see exile360's post in the Malwarebytes thread Where are the log files stored in version 3.1x.  I don't know if your scan logs were deleted when you uninstalled MB v3, but if they are still stored on your hard drive you might be able to find some useful information about the Trojan detection by right-clicking on the .json file and choosing to open with a text editor like Notepad (although the formatting will be a bit messy).

------------
32-bit Vista Home Premium SP2 * Firefox ESR v52.3.0 * NS Premium v22.10.1.10 * MB Premium v3.2.2

R Palmer:

Unfortunately as soon as I saw that, I uninstalled the program, thought they had been hacked or something, so I can't even remember what the Trojan's full name was!

Your log may still exist saved somewhere. I don't know exactly where the log is saved, someone else my add additional info.

Unfortunately as soon as I saw that, I uninstalled the program, thought they had been hacked or something, so I can't even remember what the Trojan's full name was!

Sorry I didn't reply to this part:

>>>>>>>>>>>>>>>>>>>>>>

When you downloaded MB v3 from the official site did you download from the main website at https://www.malwarebytes.com/free/ or the direct download link at https://downloads.malwarebytes.com/file/mb3?  Both links are currently downloading a 66,806 KB installer named mb3-setup-consumer-3.2.2.2029.exe.  I just submitted that installer for a SHA-256 hash analysis to VirusTotal.com and the report at https://www.virustotal.com/#/file/d02b91b47647a7545e7bb021711bbaf4cb7045... shows that over 80 scan engines report the installer is safe.

>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>

I actually tried both these sites and each time Norton flagged as 'need attention' said there was not enough information to give it a clear. I went ahead after the third installation try and did the scan using my new Premium Trial Malwarebytes, that's when it quarantined a Trojan contained in its own newly installed program!

R Palmer:

It wasn't a Norton scan, it was a Malwarebytes scan that found the Trojan in its own program!

I tried the scan after the third go at installation, after it found a Trojan in its own program, I uninstalled it and emailed Malwarebytes.

I will post their reply when it comes

Oh.. ok. Missed that. Post that log then, for reference.

It wasn't a Norton scan, it was a Malwarebytes scan that found the Trojan in its own program!

I tried the scan after the third go at installation, after it found a Trojan in its own program, I uninstalled it and emailed Malwarebytes.

I will post their reply when it comes

Thanks for that info, it is strange they have to complicate things like this!

Yes it was a Malwarebytes scan that found the Trojan in its own program!

R Palmer:

[...]

After the third installation, I ran a scan. It found a trojan, situated in the new Malwarebytes program!

[..]

Can you post details from your Norton log about the detection?