| Hello and Welcome to Tech Support Team! Before you can start posting and answering questions, you'll have to register. Registration is fast, simple and absolutely free! Feel free to browse through existing questions by choosing the forum you want to visit below. | | |  | | 
11th March 2009, 01:40 AM
|  | TST Member | | Join Date: Feb 2009, 81 posts. Location: Steeler Nation Capital Reputation:  | | | fake.drive
I ran my normal daily quick scan with MBAM and found 'fake.drive' MBAM removed it on a restart. Did a full scan after found nothing else. Anyone heard of fake.drive?
| 
11th March 2009, 03:42 AM
|  | Security Team | | Join Date: Dec 2007, 2,555 posts. Location: Tulsa, OK Reputation:   | | |
Hello danjmilos.
Don't have MBAM fix that, it's a false positive and fixing it will kill your Internet connection. If you did have MBAM fix it then please restore it from the MBAM Quarantine and then update MBAM. Run a new scan and see if it is detected again.
The correct version should be: (or higher)
Malwarebytes' Anti-Malware 1.34
Database version: 1833
Last edited by evilfantasy; 11th March 2009 at 03:44 AM.
| 
11th March 2009, 08:47 AM
|  | TST Oracle | | Join Date: Dec 2007, 8,001 posts. Location: Market Haemorrhoids, Middle England Reputation:  | | |
Not come across this one before EF - what ISP service or process is this associated with?
__________________ Confuse and Prosper. | 
11th March 2009, 04:34 PM
|  | Security Team | | Join Date: Dec 2007, 2,555 posts. Location: Tulsa, OK Reputation:   | |
It's a registry key. Code: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WS2IFSL
| 
11th March 2009, 04:39 PM
|  | TST Oracle | | Join Date: Dec 2007, 8,001 posts. Location: Market Haemorrhoids, Middle England Reputation:  | | |
Not in my registry (XP Pro SPIII) - is it Vista?
__________________ Confuse and Prosper. | 
11th March 2009, 04:43 PM
|  | Security Team | | Join Date: Dec 2007, 2,555 posts. Location: Tulsa, OK Reputation:   | |
Looking through these logs it seems to be both XP and Vista.
Maybe it's manufacturer specific? Not sure...
| 
11th March 2009, 04:53 PM
|  | TST Oracle | | Join Date: Dec 2007, 8,001 posts. Location: Market Haemorrhoids, Middle England Reputation:  | | |
A Google for it shows it is a nasty!
__________________ Confuse and Prosper. | 
11th March 2009, 05:07 PM
|  | TST Oracle | | Join Date: Dec 2007, 8,001 posts. Location: Market Haemorrhoids, Middle England Reputation:  | | |
I googled the registry entry - try it and see?
__________________ Confuse and Prosper. | 
11th March 2009, 05:11 PM
|  | Security Team | | Join Date: Dec 2007, 2,555 posts. Location: Tulsa, OK Reputation:   | |
Maybe by itself it's OK but can be exploited by malware?
Not sure..
I'm off to the dentist. Broke one of my back teeth a few days ago on some butter toffee pop-corn. Trust me I would like to investigate this more rather than see a dentist!
Talk to you later (hopefully  )
| 
11th March 2009, 05:16 PM
|  | TST Oracle | | Join Date: Dec 2007, 8,001 posts. Location: Market Haemorrhoids, Middle England Reputation:  | | |
I would not know where to start with it - except maybe ask Kaspersky support who are pretty sharp!
Enjoy dentistry - butter popcorn - mmmm!
__________________ Confuse and Prosper. | 
11th March 2009, 05:34 PM
|  | Security Team | | Join Date: Dec 2007, 2,555 posts. Location: Tulsa, OK Reputation:   | | Heh, yea now I associate it with the feeling of a baseball bat hitting me across the side of my head.
I'm offff....
| 
11th March 2009, 05:37 PM
|  | TST Oracle | | Join Date: Dec 2007, 8,001 posts. Location: Market Haemorrhoids, Middle England Reputation:  | | |
Best of luck EF!
__________________ Confuse and Prosper. | 
11th March 2009, 07:32 PM
|  | TST Member | | Join Date: Feb 2009, 81 posts. Location: Steeler Nation Capital Reputation:  | | |
Always keep my MBAM up to date. Had 1.34 1833 when I did my scan last night. MBAM deleted it last night, went last night and now, seems like nothing wrong with the net. I'll mark this in my event log and if I have problems I'll restore to a previous day. I'll let you know if anything funny starts happening.
Thank you all,
Dan
| 
11th March 2009, 07:35 PM
|  | TST Oracle | | Join Date: Jul 2008, 8,171 posts. Location: UK Norfolk ..... Reputation:  | | |
MB is updated as soon as there is a problem reported
the team works hard
__________________ Life should NOT be a journey to the grave with the intention of arriving safely in an attractive and well preserved body, but rather to skid in sideways, chocolate in one hand, wine in the other, body thoroughly used up, totally worn out and screaming...
Damn, What a ride!! | 
12th March 2009, 12:20 AM
|  | TST Member | | Join Date: Aug 2008, 105 posts. Location: Island of Misfit Toys Reputation:  | | Quote:
Originally Posted by Blackmirror MB is updated as soon as there is a problem reported
the team works hard | Hello Bm
Yes they do.
__________________
"You cant drink the oil when the water is gone"
Peruvian Shaman
| 
12th March 2009, 01:18 AM
|  | TST Expert | | Join Date: Aug 2008, 776 posts. Reputation:  | |
I saw another MB log:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\WS2IFSL (Fake.Driver) -> No action taken.
If it's removed and no probs, no harm and no foul.
It is not a standard XP or Vista entry. | 
12th March 2009, 01:29 AM
|  | Security Team | | Join Date: Dec 2007, 2,555 posts. Location: Tulsa, OK Reputation:   | | Quote:
Originally Posted by evilfantasy Maybe by itself it's OK but can be exploited by malware? | Spyware.GuardMon Technical Details | Symantec Quote:
Creates a service with the following attributes: Service Name: "WS2IFSL" Display Name: "Windows Socket 2.0 Non-IFS Service Provider Support Environment" Path to executable: "%System%\drivers\ws2ifsl.sys" Startup type: "Manual" Note: This is a legitimate service and is used by LSPs which do not use IFS (Installable File System) supported sockets.
| | 
12th March 2009, 02:11 AM
|  | TST Member | | Join Date: Feb 2009, 81 posts. Location: Steeler Nation Capital Reputation:  | | |
I'll restore it right now.
Thanks,
Dan
10:15PM done
Last edited by danjmilos; 12th March 2009 at 02:15 AM.
| 
12th March 2009, 09:14 AM
|  | TST Oracle | | Join Date: Dec 2007, 8,001 posts. Location: Market Haemorrhoids, Middle England Reputation:  | | |
So what is the conclusion on this - OK or dangerous?
__________________ Confuse and Prosper. |  | | Only registered members can participate in forum threads. You must register or log in to contribute. All times are GMT. The time now is 12:14 PM.
| |
|