 |
Welcome to Windows 7 Forums. Our forum is dedicated to helping you find solutions with any problems, errors or issues you are experiencing with Windows 7. The Windows 7 forum also covers news and updates and has an extensive Windows 7 tutorial section that covers a wide range of tips and tricks.
Windows 7 - Malwarebytes false positives? |
01-03-2012
|
#1 | | Windows 7 Ultimate Edition, 64 Bit Build 7600 |
Malwarebytes false positives? I scanned my system using Malwarebytes flash scan and here is the Log Files:
1/3/2012 3:24:19 PM
mbam-log-2012-01-03 (15-24-19).txt
Scan type: Flash scan
Scan options enabled: Memory | Startup | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: Registry | File System | P2P
Objects scanned: 139684
Time elapsed: 1 minute(s), 21 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 10
e:\users\public\documents\my pictures\aweks.pikz (Backdoor.Bot) -> Delete on reboot.
e:\users\public\documents\my pictures\my pictures.exe (Worm.AutoRun) -> Delete on reboot.
e:\users\public\documents\my pictures\my pictures.url (Trojan.Zlob) -> Delete on reboot.
e:\users\public\documents\my pictures\sample pictures\blue hills.exe (Trojan.Xanib) -> Delete on reboot.
e:\users\public\documents\my pictures\sample pictures\cakep.exe (Worm.Xanib) -> Delete on reboot.
e:\users\public\documents\my pictures\sample pictures\cuakep.exe (Worm.Xanib) -> Delete on reboot.
e:\users\public\documents\my pictures\sample pictures\sunset.exe (Trojan.Xanib) -> Delete on reboot.
e:\users\public\documents\my pictures\sample pictures\water lilies.exe (Trojan.Xanib) -> Delete on reboot.
e:\users\public\documents\my pictures\sample pictures\winter.exe (Trojan.Xanib) -> Delete on reboot.
e:\users\public\documents\my pictures\seram.pikz (Backdoor.Bot) -> Delete on reboot.
(end)
It says here that the files are deleted on reboot..but when I scanned it again using flash scan it detected the same thing again..
could it be that it's just a false positive?
I'm using windows 7 ultimate x64..
Thanks!
| My System Specs | | System Manufacturer/Model Number Acer 4730Z OS Windows 7 Ultimate Edition, 64 Bit Build 7600 CPU Intel Pentium Dual Core Motherboard Aspire 4730Z (uPGA-478) Memory 2.00 GB Dual-Channel DDR2 @ 332MHz (5-5-5-15) Graphics Card Mobile Intel(R) 4 Series Express Chipset Family Sound Card High Definition Audio Device Monitor(s) Displays Generic PnP Monitor (1280x800@60Hz) Screen Resolution 1280x800 @60 Hz Hard Drives 156GB Hitachi Hitachi HTS542516K9SA00 ATA Device (SATA) |
01-03-2012
|
#2 | | Windows 7 Professional x64 |
Necro,
No, it may not be getting all of it. What antivirus do you have in addition to Malwarebytes, and why isn't it picking anything up?
:It isn't a false positive if it deletes it, and then it reappears. Its a false positive if it deletes something that isn't a virus. | My System Specs | | System Manufacturer/Model Number Custom Built PC (In French it is called "PC de moi") OS Windows 7 Professional x64 CPU Intel Core i7-3820 CPU OC @ 3.80GHz Motherboard Gigabyte G1.Assassin2 Memory 8.00GB (2GBx4) DDR3 1866MHz Graphics Card Nvidia-Gigabyte GeForce GTX 580 1.5GB SLI-soon 680 Sound Card On board Creative SB X-Fi Monitor(s) Displays acer 24" H243H Screen Resolution 1920x1080 Keyboard Microsoft Comfort Curve 2000 Mouse Tek Republic Wired Laser 3600 dpi Gaming Mouse PSU Silent Pro 1000w gold 80+ Case Azza Hurrican 2000 Cooling Liquid CPU cooler & fan Hard Drives 120GB OCZ Vertex III SSD,
500GB OS Hybrid Drive @ 7,200RPM Internet Speed 5.14Mbps Download Speed, .65Mbps Upload Speed & 5ms Ping Other Info You're such a good person for reading all the way down to the end. People like you truly do care! We should take all the people, and make them into people like you! :p |
01-03-2012
|
#3 | | Windows 7 Ultimate Edition, 64 Bit Build 7600 |

Quote: Originally Posted by DustSailor Necro,
No, it may not be getting all of it. What antivirus do you have in addition to Malwarebytes, and why isn't it picking anything up?
:It isn't a false positive if it deletes it, and then it reappears. Its a false positive if it deletes something that isn't a virus.
I'm using Avira Personal edition..but when I look up to the directories where the files are detected, it is missing.. | My System Specs | | System Manufacturer/Model Number Acer 4730Z OS Windows 7 Ultimate Edition, 64 Bit Build 7600 CPU Intel Pentium Dual Core Motherboard Aspire 4730Z (uPGA-478) Memory 2.00 GB Dual-Channel DDR2 @ 332MHz (5-5-5-15) Graphics Card Mobile Intel(R) 4 Series Express Chipset Family Sound Card High Definition Audio Device Monitor(s) Displays Generic PnP Monitor (1280x800@60Hz) Screen Resolution 1280x800 @60 Hz Hard Drives 156GB Hitachi Hitachi HTS542516K9SA00 ATA Device (SATA) |
01-03-2012
|
#4 | | Windows 7 Professional x64 |
Necro,
could you post a picture, I'm not sure what you mean. I've heard some good and bad things about Avira Personal, and can't say I know how well it performs myself.
You might try this out: Microsoft Safety Scanner
In addition, make sure both avira and Malwarebytes are updated completely and run the full scan on each, one after the other. This will take time. Make sure windows is completely updated, restart, and let me know if the problem persists. | My System Specs | | System Manufacturer/Model Number Custom Built PC (In French it is called "PC de moi") OS Windows 7 Professional x64 CPU Intel Core i7-3820 CPU OC @ 3.80GHz Motherboard Gigabyte G1.Assassin2 Memory 8.00GB (2GBx4) DDR3 1866MHz Graphics Card Nvidia-Gigabyte GeForce GTX 580 1.5GB SLI-soon 680 Sound Card On board Creative SB X-Fi Monitor(s) Displays acer 24" H243H Screen Resolution 1920x1080 Keyboard Microsoft Comfort Curve 2000 Mouse Tek Republic Wired Laser 3600 dpi Gaming Mouse PSU Silent Pro 1000w gold 80+ Case Azza Hurrican 2000 Cooling Liquid CPU cooler & fan Hard Drives 120GB OCZ Vertex III SSD,
500GB OS Hybrid Drive @ 7,200RPM Internet Speed 5.14Mbps Download Speed, .65Mbps Upload Speed & 5ms Ping Other Info You're such a good person for reading all the way down to the end. People like you truly do care! We should take all the people, and make them into people like you! :p |
01-03-2012
|
#5 | | Windows 7 Ultimate (x86) Laptop: x64 Home Premium 7 |
Just put them in quarantine and see if all your programs are still working if so delete it then if not then put them out of the quarantine | My System Specs | | System Manufacturer/Model Number Dell Dimension 5000 OS Windows 7 Ultimate (x86) Laptop: x64 Home Premium 7 CPU Intel Pentium 4 HT @3GHz Motherboard Dell Memory 2GB DDR2 Kingston Graphics Card Ati Radeon x300se (128mb) Sound Card Creative Monitor(s) Displays Delium Monitor Screen Resolution 1360 x 768 Keyboard Logitech Mouse Logitech wireless mouse M 505 Hard Drives C: (320gb) Internet Speed 50MBPS Other Info I'm still running an old computer because my laptop died (half)
So i'll have to wait till I have more money to buy a new system :) |
01-03-2012
|
#6 | | Windows 7 Ultimate x64 SP1, LinuxMint 9 LTS x64, Debian 6, Ubuntu 10.04 LTS x64 |
Hi,
Be very careful : notice the files are renamed .EXE, they should be .JPG Code:
e:\users\public\documents\my pictures\sample pictures\sunset.exe This was reported as part of a Vista bug a few years ago in the Malwarebytes forums, but you really need to login to the Malwarbytes forums and post this message there.
Regards,
golden | My System Specs | | System Manufacturer/Model Number Golden Mk. I.3 OS Windows 7 Ultimate x64 SP1, LinuxMint 9 LTS x64, Debian 6, Ubuntu 10.04 LTS x64 CPU Intel i7 860 @ 2.80 GHz Motherboard Gigabyte P55A-UD3R Rev.1. Award BIOS F13 Memory 16GB Corsair Vengance DDR3 @ 661 MHz Dual Channel (9-9-9-24) Graphics Card EVGA NVidia GTX 560 1024MB Sound Card Realtek Integrated Monitor(s) Displays Dual Samsung SyncMaster 2494HS Screen Resolution 1920*1080 and 1920*1080 Keyboard Logitech G110 Mouse Logitech MX518 PSU Thermaltake ToughPower QFan 750W Case Thermaltake Element S VK60001W2Z Cooling Corsair H60 Water Cooling, 2*230mm and 2*80mm case fans Hard Drives 1*OCZ Vertex 2 60GB SSD;
2*Samsung F3 SpinPoint 1TB in RAID0;
2*Samsung F1 SpinPoint 1TB in RAID1;
1*Western Digital WD10EARS 1TB
1*Western Digital 500GB External USB 3.0
1*Seagate 500GB External USB 2.0 Internet Speed Not fast enough!!! |
01-03-2012
|
#7 | | Windows 7 Ultimate Edition, 64 Bit Build 7600 |

Quote: Originally Posted by Golden Hi,
Be very careful : notice the files are renamed .EXE, they should be .JPG Code:
e:\users\public\documents\my pictures\sample pictures\sunset.exe This was reported as part of a Vista bug a few years ago in the Malwarebytes forums, but you really need to login to the Malwarbytes forums and post this message there.
Regards,
golden
Thanks for the replies!
Actually I'm using a dual boot with Windows Vista and 7 right now.
Maybe I will post this problem at Malwarebytes forum... | My System Specs | | System Manufacturer/Model Number Acer 4730Z OS Windows 7 Ultimate Edition, 64 Bit Build 7600 CPU Intel Pentium Dual Core Motherboard Aspire 4730Z (uPGA-478) Memory 2.00 GB Dual-Channel DDR2 @ 332MHz (5-5-5-15) Graphics Card Mobile Intel(R) 4 Series Express Chipset Family Sound Card High Definition Audio Device Monitor(s) Displays Generic PnP Monitor (1280x800@60Hz) Screen Resolution 1280x800 @60 Hz Hard Drives 156GB Hitachi Hitachi HTS542516K9SA00 ATA Device (SATA) |
01-03-2012
|
#8 | | Windows 7 SP1, Home Premium, 64-bit |

Quote: Originally Posted by NecroticisM666
Thanks for the replies!
Actually I'm using a dual boot with Windows Vista and 7 right now.
Maybe I will post this problem at Malwarebytes forum... You could also upload the files here, where they will be examined by dozens of different antivirus scanners: VirusTotal - Free Online Virus, Malware and URL Scanner | My System Specs | | System Manufacturer/Model Number Ignatz Special; 4 speed manual gearbox; factory air conditioning; one of one OS Windows 7 SP1, Home Premium, 64-bit CPU Intel Sandy Bridge i5-2500, not overclocked Motherboard Gigabyte H67A-UD3H-B3, full ATX Memory 4 GB Crucial DDR3-1333 Graphics Card none; graphics are integrated on CPU Sound Card onboard: Realtek ALC892; external: USB Behringer UF0-202 Monitor(s) Displays NEC 90GX2-BK 19" LCD Screen Resolution 800 x 640 Keyboard Leopold Tenkeyless with Cherry Blue switches, USB Mouse Logitech or Microsoft optical wired; either USB or PS 2 PSU Seasonic SS-560KM, modular Case Antec Solo II Cooling CPU: Scythe Big Shuriken; Case: Scythe Slipstream 800 & 500 Hard Drives System: Intel 320 Series SSD, 80 GB;
Data: Samsung Spinpoint 103SJ, 1 TB;
Backup: WD Caviar Green WD15EADS-00P8B0, 1.5TB Other Info Power consumption of this system, including monitor: 68 watts at idle; 144 watts at full load Malwarebytes false positives? problems? All times are GMT -5. The time now is 01:14 AM. |  |