Malwarebytes found Adware.BHO in Inkscape. Any explanation?

General discussions about Inkscape.
Guest

Malwarebytes found Adware.BHO in Inkscape. Any explanation?

Postby Guest » Mon Aug 31, 2009 3:43 am

As the subject suggests, Malwarebytes found two entries in Inkscape for Adware.BHO. For those unfamiliar, Malewarebytes is a popular detection tool for finding and removing spyware, etc. I HIGHLY doubt that this is a false positive. After doing a little research, I am still not able to determine what Adware.BHO does. If you are interested, here is the log:

Malwarebytes' Anti-Malware 1.40
Database version: 2713
Windows 6.0.6002 Service Pack 2

8/29/2009 4:21:32 PM
mbam-log-2009-08-29 (16-21-32).txt

Scan type: Full Scan (C:\|)
Objects scanned: 251782
Time elapsed: 1 hour(s), 11 minute(s), 2 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\inkscape (Adware.BHO) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Program Files (x86)\Inkscape\Uninstall.exe (Adware.BHO) -> Quarantined and deleted successfully.

User avatar
prkos
Posts: 1625
Joined: Tue Nov 06, 2007 8:45 am
Location: Croatia

Re: Malwarebytes found Adware.BHO in Inkscape. Any explanation?

Postby prkos » Mon Aug 31, 2009 6:33 am

AV software can often show false positives, it uses algorithms to find features of software that resemble viruses but there are regular software that can have those characteristics...

Does Inkscape installation even change registry? I know you can just unzip Inkscape into a directory, this means it doesn't write to registry in which case this report is false.
just hand over the chocolate and nobody gets hurt

Inkscape Manual on Floss
Inkscape FAQ
very comprehensive Inkscape guide
Inkscape 0.48 Illustrator's Cookbook - 109 recipes to learn and explore Inkscape - with SVG examples to download

Simarilius
Posts: 626
Joined: Wed Jun 06, 2007 2:37 am

Re: Malwarebytes found Adware.BHO in Inkscape. Any explanation?

Postby Simarilius » Mon Aug 31, 2009 7:10 am

Guest wrote: I HIGHLY doubt that this is a false positive.


I highly doubt your right. There have been false positives from a number of packages over the years.
from the log its not liking the uninstall, which is standard NSIS, which would suggest that the malware is using NSIS too, and the programs getting confused.
I'd suggest trying some other of the alternatives to see if any of them flag it.

I'd check it but you dont say what version etc so theres no way for anyone else to check.

pkros: we dont write to the registry in the software itself, but the installer does.

DL.

Re: Malwarebytes found Adware.BHO in Inkscape. Any explanation?

Postby DL. » Tue Sep 08, 2009 8:34 am

http://en.wikipedia.org/wiki/NSIS#NSIS_Media_Malware

Inkscape might use NSISdl, has been known according to wikipedia to cause false positives

Slow Dog
Posts: 180
Joined: Wed Sep 24, 2008 7:51 pm

Re: Malwarebytes found Adware.BHO in Inkscape. Any explanation?

Postby Slow Dog » Tue Sep 08, 2009 9:06 pm

Guest wrote:I HIGHLY doubt that this is a false positive. After doing a little research, I am still not able to determine what Adware.BHO does.


After doing a little research of my own, I determined that a "BHO" file is a "Browser Helper Object" for Internet Explorer, and an Adware.BHO (that is "<somefilename>.BHO") file would thus such a file which modified IE behaviour for ad monitoring purposes. "Uninstall.exe" clearly isn't of the form "<somefilename>.BHO", and thus can't be such a file, and is therefore a false positive.


Return to “General Discussions”