Submit Your Article Forum Rules FAQ About Us
Search the forums:

Tech Support Team


Hello and Welcome to Tech Support Team! Before you can start posting and answering questions, you'll have to register. Registration is fast, simple and absolutely free! Feel free to browse through existing questions by choosing the forum you want to visit below.



Reply
  #1 (permalink)   Top
Old 11th March 2009, 01:40 AM
danjmilos's Avatar
TST Member
 
Join Date: Feb 2009, 81 posts.
Location: Steeler Nation Capital
Reputation: danjmilos is on a distinguished road
fake.drive

I ran my normal daily quick scan with MBAM and found 'fake.drive' MBAM removed it on a restart. Did a full scan after found nothing else. Anyone heard of fake.drive?
Reply With Quote
  #2 (permalink)   Top
Old 11th March 2009, 03:42 AM
evilfantasy's Avatar
Security Team
 
Join Date: Dec 2007, 2,555 posts.
Location: Tulsa, OK
Reputation: evilfantasy will become famous soon enoughevilfantasy will become famous soon enough
Hello danjmilos.

Don't have MBAM fix that, it's a false positive and fixing it will kill your Internet connection. If you did have MBAM fix it then please restore it from the MBAM Quarantine and then update MBAM. Run a new scan and see if it is detected again.

The correct version should be: (or higher)

Malwarebytes' Anti-Malware 1.34
Database version: 1833
__________________
.

ƃolq s’ʎsɐʇuɐɟlıʌǝ

Last edited by evilfantasy; 11th March 2009 at 03:44 AM.
Reply With Quote
  #3 (permalink)   Top
Old 11th March 2009, 08:47 AM
Albert Lionheart's Avatar
TST Oracle
 
Join Date: Dec 2007, 8,001 posts.
Location: Market Haemorrhoids, Middle England
Reputation: Albert Lionheart is on a distinguished road
Not come across this one before EF - what ISP service or process is this associated with?
__________________
Confuse and Prosper.
Reply With Quote
  #4 (permalink)   Top
Old 11th March 2009, 04:34 PM
evilfantasy's Avatar
Security Team
 
Join Date: Dec 2007, 2,555 posts.
Location: Tulsa, OK
Reputation: evilfantasy will become famous soon enoughevilfantasy will become famous soon enough
It's a registry key.

Code:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WS2IFSL
__________________
.

ƃolq s’ʎsɐʇuɐɟlıʌǝ
Reply With Quote
  #5 (permalink)   Top
Old 11th March 2009, 04:39 PM
Albert Lionheart's Avatar
TST Oracle
 
Join Date: Dec 2007, 8,001 posts.
Location: Market Haemorrhoids, Middle England
Reputation: Albert Lionheart is on a distinguished road
Not in my registry (XP Pro SPIII) - is it Vista?
__________________
Confuse and Prosper.
Reply With Quote
  #6 (permalink)   Top
Old 11th March 2009, 04:43 PM
evilfantasy's Avatar
Security Team
 
Join Date: Dec 2007, 2,555 posts.
Location: Tulsa, OK
Reputation: evilfantasy will become famous soon enoughevilfantasy will become famous soon enough
Looking through these logs it seems to be both XP and Vista.

Maybe it's manufacturer specific? Not sure...
__________________
.

ƃolq s’ʎsɐʇuɐɟlıʌǝ
Reply With Quote
  #7 (permalink)   Top
Old 11th March 2009, 04:53 PM
Albert Lionheart's Avatar
TST Oracle
 
Join Date: Dec 2007, 8,001 posts.
Location: Market Haemorrhoids, Middle England
Reputation: Albert Lionheart is on a distinguished road
A Google for it shows it is a nasty!
__________________
Confuse and Prosper.
Reply With Quote
  #8 (permalink)   Top
Old 11th March 2009, 05:05 PM
evilfantasy's Avatar
Security Team
 
Join Date: Dec 2007, 2,555 posts.
Location: Tulsa, OK
Reputation: evilfantasy will become famous soon enoughevilfantasy will become famous soon enough
I think this is the key that's being flagged falsely. Windows Socket 2.0 Non-IFS Service Provider Support Environment - ws2ifsl.sys - Program Information

This is a legitimate service and is used by LSPs which do not use IFS (Installable File System) supported sockets. <- Explains why removing it kills the connection.
__________________
.

ƃolq s’ʎsɐʇuɐɟlıʌǝ
Reply With Quote
  #9 (permalink)   Top
Old 11th March 2009, 05:07 PM
Albert Lionheart's Avatar
TST Oracle
 
Join Date: Dec 2007, 8,001 posts.
Location: Market Haemorrhoids, Middle England
Reputation: Albert Lionheart is on a distinguished road
I googled the registry entry - try it and see?
__________________
Confuse and Prosper.
Reply With Quote
  #10 (permalink)   Top
Old 11th March 2009, 05:11 PM
evilfantasy's Avatar
Security Team
 
Join Date: Dec 2007, 2,555 posts.
Location: Tulsa, OK
Reputation: evilfantasy will become famous soon enoughevilfantasy will become famous soon enough
Maybe by itself it's OK but can be exploited by malware?

Not sure..

I'm off to the dentist. Broke one of my back teeth a few days ago on some butter toffee pop-corn. Trust me I would like to investigate this more rather than see a dentist!

Talk to you later (hopefully )
__________________
.

ƃolq s’ʎsɐʇuɐɟlıʌǝ
Reply With Quote
  #11 (permalink)   Top
Old 11th March 2009, 05:16 PM
Albert Lionheart's Avatar
TST Oracle
 
Join Date: Dec 2007, 8,001 posts.
Location: Market Haemorrhoids, Middle England
Reputation: Albert Lionheart is on a distinguished road
I would not know where to start with it - except maybe ask Kaspersky support who are pretty sharp!
Enjoy dentistry - butter popcorn - mmmm!
__________________
Confuse and Prosper.
Reply With Quote
  #12 (permalink)   Top
Old 11th March 2009, 05:34 PM
evilfantasy's Avatar
Security Team
 
Join Date: Dec 2007, 2,555 posts.
Location: Tulsa, OK
Reputation: evilfantasy will become famous soon enoughevilfantasy will become famous soon enough
Quote:
butter popcorn - mmmm!
Heh, yea now I associate it with the feeling of a baseball bat hitting me across the side of my head.

I'm offff....
__________________
.

ƃolq s’ʎsɐʇuɐɟlıʌǝ
Reply With Quote
  #13 (permalink)   Top
Old 11th March 2009, 05:37 PM
Albert Lionheart's Avatar
TST Oracle
 
Join Date: Dec 2007, 8,001 posts.
Location: Market Haemorrhoids, Middle England
Reputation: Albert Lionheart is on a distinguished road
Best of luck EF!
__________________
Confuse and Prosper.
Reply With Quote
  #14 (permalink)   Top
Old 11th March 2009, 07:32 PM
danjmilos's Avatar
TST Member
 
Join Date: Feb 2009, 81 posts.
Location: Steeler Nation Capital
Reputation: danjmilos is on a distinguished road
Always keep my MBAM up to date. Had 1.34 1833 when I did my scan last night. MBAM deleted it last night, went last night and now, seems like nothing wrong with the net. I'll mark this in my event log and if I have problems I'll restore to a previous day. I'll let you know if anything funny starts happening.

Thank you all,
Dan
Reply With Quote
  #15 (permalink)   Top
Old 11th March 2009, 07:35 PM
Blackmirror's Avatar
TST Oracle
 
Join Date: Jul 2008, 8,171 posts.
Location: UK Norfolk .....
Reputation: Blackmirror is on a distinguished road
MB is updated as soon as there is a problem reported
the team works hard
__________________
Life should NOT be a journey to the grave with the intention of arriving safely in an attractive and well preserved body, but rather to skid in sideways, chocolate in one hand, wine in the other, body thoroughly used up, totally worn out and screaming...
Damn, What a ride!!
Reply With Quote
  #16 (permalink)   Top
Old 12th March 2009, 12:20 AM
sho-dan's Avatar
TST Member
 
Join Date: Aug 2008, 105 posts.
Location: Island of Misfit Toys
Reputation: sho-dan is on a distinguished road
Quote:
Originally Posted by Blackmirror View Post
MB is updated as soon as there is a problem reported
the team works hard
Hello Bm

Yes they do.
__________________
"You cant drink the oil when the water is gone"
Peruvian Shaman
Reply With Quote
  #17 (permalink)   Top
Old 12th March 2009, 01:18 AM
Gunner's Avatar
TST Expert
 
Join Date: Aug 2008, 776 posts.
Reputation: Gunner is on a distinguished road
I saw another MB log:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\WS2IFSL (Fake.Driver) -> No action taken.
If it's removed and no probs, no harm and no foul.
It is not a standard XP or Vista entry.
Reply With Quote
  #18 (permalink)   Top
Old 12th March 2009, 01:29 AM
evilfantasy's Avatar
Security Team
 
Join Date: Dec 2007, 2,555 posts.
Location: Tulsa, OK
Reputation: evilfantasy will become famous soon enoughevilfantasy will become famous soon enough
Quote:
Originally Posted by evilfantasy View Post
Maybe by itself it's OK but can be exploited by malware?
Spyware.GuardMon Technical Details | Symantec

Quote:
Creates a service with the following attributes:

Service Name: "WS2IFSL"
Display Name: "Windows Socket 2.0 Non-IFS Service Provider Support Environment"
Path to executable: "%System%\drivers\ws2ifsl.sys"
Startup type: "Manual"

Note: This is a legitimate service and is used by LSPs which do not use IFS (Installable File System) supported sockets.
__________________
.

ƃolq s’ʎsɐʇuɐɟlıʌǝ
Reply With Quote
  #19 (permalink)   Top
Old 12th March 2009, 02:11 AM
danjmilos's Avatar
TST Member
 
Join Date: Feb 2009, 81 posts.
Location: Steeler Nation Capital
Reputation: danjmilos is on a distinguished road
I'll restore it right now.
Thanks,
Dan

10:15PM done

Last edited by danjmilos; 12th March 2009 at 02:15 AM.
Reply With Quote
  #20 (permalink)   Top
Old 12th March 2009, 09:14 AM
Albert Lionheart's Avatar
TST Oracle
 
Join Date: Dec 2007, 8,001 posts.
Location: Market Haemorrhoids, Middle England
Reputation: Albert Lionheart is on a distinguished road
So what is the conclusion on this - OK or dangerous?
__________________
Confuse and Prosper.
Reply With Quote
Reply

Only registered members can participate in forum threads. You must register or log in to contribute.


Thread Tools

Forum Jump


All times are GMT. The time now is 12:14 PM.






Post A Question!
Useful Links
Main Menu
Home
Forum Rules
FAQ
About Us
Welcome Pack
Search the forums
TST Mobile
Contact Us
Send Message

These are the 8 most used thread tags
Tag Cloud
geforce modem monitor no ring response no signal nvidia soft modem win7