PDA

View Full Version : Fixed: Any chance new Wishbone infection is false positive



slejomatic
2012-08-19, 21:49
Running Windows XP, all updates installed. Never had a spyware issue before; scan with MalwareBytes and Spybot monthly.

Today, MalwareBytes came in clean, but spybot detected three entries for Wishbone in the registry:

Wishbone: [SBI $06D5FD4A] Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AtlBrCon.AtlBrCon

Wishbone: [SBI $06D5FD4A] Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AtlBrCon.AtlBrCon.1

Wishbone: [SBI $06D5FD4A] Class ID (Registry key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0818D430-6247-11D1-ABEE-00D049C10025}



Should I use Spybot to remove these three entries?

A couple of reasons that I think this might be false, but I welcome feedback:

1) Only three entries; a search on the net suggests real infections are associated with many more positive entries and files that I cannot seem to find on my drive.
2) I haven't intentionally installed any popup blockers; just use the one that comes within IE8; a review of "add/remove programs" doesn't show any Wishbone entry.
3) As best as I can tell, the company that made Wishbone is no longer in business; their website is no longer operational.

Thanks, in advance, for your help!

slejomatic
2012-08-20, 03:26
Last check by spybot was 8-4-12; no objects found.

Haven't noticed any browser slowness or hijack attempts (yet).

Only installs since last check: changed my antivirus software to mcafee (job required) and updated adobe flash. Also applied Augusts Microsoft updates.

Yodama
2012-08-20, 07:15
Thank you for reporting this issue.
We will regard it as a false positive for the reasons you stated above.

slejomatic
2012-08-31, 02:10
Just did a new install of Windows 7 (for an unrelated reason). During my initial scan, spybot detected:


Wishbone: [SBI $06D5FD4A] Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AtlBrCon.AtlBrCon

Wishbone: [SBI $06D5FD4A] Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AtlBrCon.AtlBrCon.1

Wishbone: [SBI $06D5FD4A] Class ID (Registry key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0818D430-6247-11D1-ABEE-00D049C10025}

Wishbone: [SBI $06D5FD4A] Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AtlBrCon.AtlBrCon.1

Wishbone: [SBI $06D5FD4A] Root class (Registry key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AtlBrCon.AtlBrCon



Am I the only one still having this problem?

Yodama
2012-08-31, 07:24
hello,

it seems the corrected detection file on this issue was not uploaded with our update yet. This will be fixed with our next detection update scheduled for Wednesday 2012-09-05.