Malwarebytes Update causes Massive false positives.

Phone Man

Retired Bell Head
Guru
Gold Member
VIP
Local time
1:51 PM
Messages
2,673
Location
Covington, La
A definition update for Malwarebytes causes Trojan.Donloader.ED false positive on a massive amount of files that it can disable your system. It was corrected with new update. It hit me this afternoon and sure glad I had a recent Macrium Refresh image.


***False positive Trojan.Downloader.ED*** - Malwarebytes Forum

Jim :cool:
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Home Built
OS
Windows 8.1 Pro w/Media Center 64bit, Windows 7 HP 64bit
CPU
Phenom II X6 1100T
Motherboard
ASUS M5A99X EVO
Memory
Crucial Balistic 8gb DDR3-1866 CL9
Graphics Card(s)
MSI R6850 Cyclone IGD5 PE
Sound Card
On Board
Monitor(s) Displays
ASUS VE258Q 25" LED with DVI-HDMI-DisplayPort
Screen Resolution
1920 x 1080
Hard Drives
Two WD Cavier Black 2TB Sata III, WD My Book Essential 2TB USB 3.0
PSU
Seasonic X650 80 Plus GOLD Modular
Case
Corsair 400R
Cooling
Antec Kuhler H2O 620, Two 120mm and four 140mm
Keyboard
Logitech K120
Mouse
Logitech Marble Mouse USB, Logitech Precision Game Pad
Internet Speed
15MB
Antivirus
Norton IS 2013, Malwarebytes Pro Beta 2
Browser
IE-11, FF-27
Other Info
APC UPS ES 750, Netgear WNR3500L Gigabit & Wireless N Router with SamKnows Test Program, Motorola SB6120 Gigabit Cable Modem. Brother HL-2170W Laser Printer, Epson V300 Scanner
So as long as I update as of now, this shouldn't be a problem then? If so I might had dodged a bullet as I was going to run a full scan when I went to bed
 

My Computer

Computer type
PC/Desktop
OS
Microsoft Windows 7 Professional 64-bit SP1
CPU
Intel(R) Core(TM) i5 CPU M 520 @ 2.40GHz
Motherboard
Dell Inc. 0K42JR
Memory
8.00 GB
Graphics Card(s)
NVIDIA NVS 3100M
Sound Card
(1) NVIDIA High Definition Audio (2) IDT High Definition A
Monitor(s) Displays
1
Screen Resolution
1440 x 900 x 32 bits (4294967296 colors) @ 59 Hz
Hard Drives
Samsung SSD 840 PRO Series ATA Device
So as long as I update as of now, this shouldn't be a problem then? If so I might had dodged a bullet as I was going to run a full scan when I went to bed

Your lucky, I was online and my Pro version runs a flash scan after each update. The latest update fixed the problem so you should be fine.

Jim :cool:
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Home Built
OS
Windows 8.1 Pro w/Media Center 64bit, Windows 7 HP 64bit
CPU
Phenom II X6 1100T
Motherboard
ASUS M5A99X EVO
Memory
Crucial Balistic 8gb DDR3-1866 CL9
Graphics Card(s)
MSI R6850 Cyclone IGD5 PE
Sound Card
On Board
Monitor(s) Displays
ASUS VE258Q 25" LED with DVI-HDMI-DisplayPort
Screen Resolution
1920 x 1080
Hard Drives
Two WD Cavier Black 2TB Sata III, WD My Book Essential 2TB USB 3.0
PSU
Seasonic X650 80 Plus GOLD Modular
Case
Corsair 400R
Cooling
Antec Kuhler H2O 620, Two 120mm and four 140mm
Keyboard
Logitech K120
Mouse
Logitech Marble Mouse USB, Logitech Precision Game Pad
Internet Speed
15MB
Antivirus
Norton IS 2013, Malwarebytes Pro Beta 2
Browser
IE-11, FF-27
Other Info
APC UPS ES 750, Netgear WNR3500L Gigabit & Wireless N Router with SamKnows Test Program, Motorola SB6120 Gigabit Cable Modem. Brother HL-2170W Laser Printer, Epson V300 Scanner
So as long as I update as of now, this shouldn't be a problem then? If so I might had dodged a bullet as I was going to run a full scan when I went to bed

Your lucky, I was online and my Pro version runs a flash scan after each update. The latest update fixed the problem so you should be fine.

Jim :cool:

:eek: Thanks for the heads up Phone Man
 

My Computer

Computer type
PC/Desktop
OS
Microsoft Windows 7 Professional 64-bit SP1
CPU
Intel(R) Core(TM) i5 CPU M 520 @ 2.40GHz
Motherboard
Dell Inc. 0K42JR
Memory
8.00 GB
Graphics Card(s)
NVIDIA NVS 3100M
Sound Card
(1) NVIDIA High Definition Audio (2) IDT High Definition A
Monitor(s) Displays
1
Screen Resolution
1440 x 900 x 32 bits (4294967296 colors) @ 59 Hz
Hard Drives
Samsung SSD 840 PRO Series ATA Device
I got hit pretty good with this yesterday.
MBAM Pro went crazy all of a sudden, flashing warnings and quarantining files at a pace I never saw before.
It disabled security scanners, start button and more.
Managed to do a hard shutdown, restarting did nothing, could not start any programs at all, Win7 was DOA.
Another shutdown, did a system restore point and went back to what appears to be normal so far.
I disabled MBAM, then removed it with Revo, downloaded a new copy 3 hours later.
All files in quarantine would not restore, so had to look in sys32 and other places to be sure they were there, very time consuming.
After verifying everything, I deleted all from quarantine.

This shows the chaos : http://forums.malwarebytes.org/index.php?showtopic=125127&st=0
 

My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
Lenovo Z710 #59400485
OS
Windows 8.1.1 64bit
CPU
i7-4700MQ
Memory
8.0GB PC3-12800 DDR3L SDRAM 1600 MHz
Graphics Card(s)
Intel® HD Graphics 4600
Sound Card
on-board
Monitor(s) Displays
17.3"
Screen Resolution
1920x1080
Hard Drives
1TB 5400 RPM;(OS,programs)



Hitachi, 1Tb external,(B'up)
PSU
4 Cell 41 Watt Hour Lithium-Ion
Case
Lenovo
Cooling
Air in, Air out.
Keyboard
Logitech - Y-UY95 - Illuminated
Mouse
M$ - Arc Touch
Internet Speed
59 Mb down / 25 Mb up
Antivirus
Defender
Browser
Firefox (newest)
Other Info
MBAM Pro, SAS Pro, Revo Pro.

Ext. HP 2311 Monitor
Wow, I was going to download and run MBAM yesterday on a different system but got distracted- sure am glad I didn't!
 

My Computer

Computer type
Laptop
OS
Windows 7 Ultimate 64bit SP-1
CPU
Intel Core i5 3rd Gen. w/ Turbo Boost 2.6
Motherboard
Asus
Hard Drives
8" Drive (primary storage device)
2 TB External
1 Internal HD
Mouse
Logitech Anywhere MX
Internet Speed
Light Speed
Antivirus
MSE
Yikes! It looks like chaos......but strangely, I had no issues at all :confused:
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Golden Mk. I.4
OS
Windows 10 Pro x64 ; Xubuntu x64
CPU
Intel i7 860 @ 2.80 GHz O/C'ed to 4.0GHz
Motherboard
Gigabyte P55A-UD3R Rev.1. Award BIOS F13
Memory
16GB Corsair Vengance DDR3 @ 661 MHz Dual Channel (9-9-9-24)
Graphics Card(s)
EVGA NVidia GTX 560 1024MB
Sound Card
Realtek Integrated
Monitor(s) Displays
Dual Samsung SyncMaster 2494HS
Screen Resolution
1920*1080 and 1920*1080
Hard Drives
1*Samsung 840 EVO 120GB SSD;
1*OCZ Vertex 2 60GB SSD;
2*Samsung F3 SpinPoint 1TB in RAID0;
1*Samsung F1 SpinPoint 1TB;
2*Western Digital 1TB External USB 3.0
1*Western Digital 500GB External USB 3.0
1*Seagate 500GB External USB 2.0
PSU
Thermaltake ToughPower QFan 750W
Case
Thermaltake Element S VK60001W2Z
Cooling
Corsair H60 Water Cooling, 2*230mm and 2*80mm case fans
Keyboard
Logitech G110
Mouse
Logitech MX518
No bother here either working fine On my Windows 8 system
 

My Computer

Computer Manufacturer/Model Number
W530-3630QM1
OS
windows 7 home 64bit
CPU
INTEL-CORE I7
Memory
16GB
Hard Drives
750GB
Browser
Chrome
Yikes! It looks like chaos......but strangely, I had no issues at all :confused:

Your very lucky.
There was one person who knew he would be going to face a mountain of disasters this morning as he had 600 machines which he believed were damaged by this. IT person I'm guessing.
Others were threatening law suits, some wanted monetary compensation.
I'm guessing today is a very busy day for a lot of people around the world.
 

My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
Lenovo Z710 #59400485
OS
Windows 8.1.1 64bit
CPU
i7-4700MQ
Memory
8.0GB PC3-12800 DDR3L SDRAM 1600 MHz
Graphics Card(s)
Intel® HD Graphics 4600
Sound Card
on-board
Monitor(s) Displays
17.3"
Screen Resolution
1920x1080
Hard Drives
1TB 5400 RPM;(OS,programs)



Hitachi, 1Tb external,(B'up)
PSU
4 Cell 41 Watt Hour Lithium-Ion
Case
Lenovo
Cooling
Air in, Air out.
Keyboard
Logitech - Y-UY95 - Illuminated
Mouse
M$ - Arc Touch
Internet Speed
59 Mb down / 25 Mb up
Antivirus
Defender
Browser
Firefox (newest)
Other Info
MBAM Pro, SAS Pro, Revo Pro.

Ext. HP 2311 Monitor
The Enterprise version just knocked all the computers connected to this product out. Thank god were only evaluating it on a couple computers. Forefront may suck, but at least its not taking our systems out.

^ Off the Malwarebytes forum......they are going to have to work hard to regain some credibility it would appear. In the meantime, I'm taking the safe option and turning OFF automatic quarantining:

Capture.PNG

If your system is completely hosed as some are reporting, then this is apparently the fix:

http://forums.malwarebytes.org/index.php?showtopic=125137
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Golden Mk. I.4
OS
Windows 10 Pro x64 ; Xubuntu x64
CPU
Intel i7 860 @ 2.80 GHz O/C'ed to 4.0GHz
Motherboard
Gigabyte P55A-UD3R Rev.1. Award BIOS F13
Memory
16GB Corsair Vengance DDR3 @ 661 MHz Dual Channel (9-9-9-24)
Graphics Card(s)
EVGA NVidia GTX 560 1024MB
Sound Card
Realtek Integrated
Monitor(s) Displays
Dual Samsung SyncMaster 2494HS
Screen Resolution
1920*1080 and 1920*1080
Hard Drives
1*Samsung 840 EVO 120GB SSD;
1*OCZ Vertex 2 60GB SSD;
2*Samsung F3 SpinPoint 1TB in RAID0;
1*Samsung F1 SpinPoint 1TB;
2*Western Digital 1TB External USB 3.0
1*Western Digital 500GB External USB 3.0
1*Seagate 500GB External USB 2.0
PSU
Thermaltake ToughPower QFan 750W
Case
Thermaltake Element S VK60001W2Z
Cooling
Corsair H60 Water Cooling, 2*230mm and 2*80mm case fans
Keyboard
Logitech G110
Mouse
Logitech MX518
OK, thank's

Just did it to mine also.
Still waiting for CS to get back to me as I can not re-register it. It did not do it automatically and I lost the ID and key #
 

My Computer

Computer type
Laptop
Computer Manufacturer/Model Number
Lenovo Z710 #59400485
OS
Windows 8.1.1 64bit
CPU
i7-4700MQ
Memory
8.0GB PC3-12800 DDR3L SDRAM 1600 MHz
Graphics Card(s)
Intel® HD Graphics 4600
Sound Card
on-board
Monitor(s) Displays
17.3"
Screen Resolution
1920x1080
Hard Drives
1TB 5400 RPM;(OS,programs)



Hitachi, 1Tb external,(B'up)
PSU
4 Cell 41 Watt Hour Lithium-Ion
Case
Lenovo
Cooling
Air in, Air out.
Keyboard
Logitech - Y-UY95 - Illuminated
Mouse
M$ - Arc Touch
Internet Speed
59 Mb down / 25 Mb up
Antivirus
Defender
Browser
Firefox (newest)
Other Info
MBAM Pro, SAS Pro, Revo Pro.

Ext. HP 2311 Monitor
The Enterprise version just knocked all the computers connected to this product out. Thank god were only evaluating it on a couple computers. Forefront may suck, but at least its not taking our systems out.
^ Off the Malwarebytes forum......they are going to have to work hard to regain some credibility it would appear. In the meantime, I'm taking the safe option and turning OFF automatic quarantining:

View attachment 264356

If your system is completely hosed as some are reporting, then this is apparently the fix:

***False positive Trojan.Downloader.ED*** - Malwarebytes Forum

I got burned on the last two recent FP's...
I'm trying to make sure nothing gets quarantined/deleted automatically going forward.
I just want to be notified if anything malicious is found, but I'm not sure if that's possible.
In addition to Golden's screen print, there are some other settings that may come into play.
Does anyone know what settings to use for all of these? :confused:

MBQSP01.PNG

MBQSP02.PNG

MBQSP03.PNG

I think I can turn everything off, but then will I ever know if there is any malware detected?
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
home built
OS
Multi-Boot W7_Pro_x64 W8.1_Pro_x64 W10_Pro_x64 +Linux_VMs +Chromium_VM
CPU
AMD Athlon II x4 620
Motherboard
Gigabyte GA-MA785G-UD3H
Memory
6GB GSkill DDR2 800
Graphics Card(s)
AMD 4670 GPU + AMD 4200 IGP
Sound Card
on board Realtek ALC889A
Monitor(s) Displays
RCA 40" LCD TV, Insignia 32" LCD TV, HP 15" LCD monitor
Screen Resolution
1680 x 1050
Hard Drives
OCZ Vertex 3 120GB,
Samsung F3 1TB (3),
Several others - WD, Seagate, Hitachi, ...
PSU
Corsair 500 W
Case
Rosewill mid tower
Cooling
CM 90mm rifle
Keyboard
Gyration wireless, Logitech wireless, Dell USB wired
Mouse
Gyration wireless, Logitech wireless, V7 USB wired
Internet Speed
Spectrum - 100Mbps D / 10Mbps U
Antivirus
Avast, MBAM3, EMET, WinPatrol
Browser
Pale Moon, Firefox, IE
Other Info
2 multi-boot PC's
Mainly HTPC/Office/Gen purpose (no gaming).
Trendnet USB KVM.
LG DVD burner/Blue Ray Player.
Tray system for removable SATA backup drives.

Not currently OCd, under-volted.
I use Hybrid sleep, rarely re-boot or shutdown.

Hauppauge HD-PVR, Avermedia PCIe TV Tuner, Hauppauge PCI TV Tuner.
Thanks for the heads up phoneman, I'll check this out when I get home on my machine there.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom Build (multiple machines)
OS
Windows 7 Ultimate x86, Windows 7 Professional x64, Windows 8 Pro x64
CPU
AMD Athlon 7750 Dual-Core 2.70 GHz
Motherboard
ECS GF8200A
Memory
3GB
Graphics Card(s)
Nvidia
Monitor(s) Displays
Asus 24''
Screen Resolution
1680x1050
Antivirus
Microsoft Security Esentials
Browser
IE, Chrome, Firefox (Primary)
Other Info
Will update a full list soon...am planning on upgrading my system later this summer anyways.
Thanks for the heads up phoneman, I'll check this out when I get home on my machine there.

Be sure to run an update before running a scan. That way you get a new definition file.

Jim :cool:
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Home Built
OS
Windows 8.1 Pro w/Media Center 64bit, Windows 7 HP 64bit
CPU
Phenom II X6 1100T
Motherboard
ASUS M5A99X EVO
Memory
Crucial Balistic 8gb DDR3-1866 CL9
Graphics Card(s)
MSI R6850 Cyclone IGD5 PE
Sound Card
On Board
Monitor(s) Displays
ASUS VE258Q 25" LED with DVI-HDMI-DisplayPort
Screen Resolution
1920 x 1080
Hard Drives
Two WD Cavier Black 2TB Sata III, WD My Book Essential 2TB USB 3.0
PSU
Seasonic X650 80 Plus GOLD Modular
Case
Corsair 400R
Cooling
Antec Kuhler H2O 620, Two 120mm and four 140mm
Keyboard
Logitech K120
Mouse
Logitech Marble Mouse USB, Logitech Precision Game Pad
Internet Speed
15MB
Antivirus
Norton IS 2013, Malwarebytes Pro Beta 2
Browser
IE-11, FF-27
Other Info
APC UPS ES 750, Netgear WNR3500L Gigabit & Wireless N Router with SamKnows Test Program, Motorola SB6120 Gigabit Cable Modem. Brother HL-2170W Laser Printer, Epson V300 Scanner
Hosed my neighbors computer, finishing up a clean install right now... probably needed it anyway.

I was impressed that the computer was still running with over 2000 Trojans, big shot in the foot for MBAM.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Self Built
OS
Win 10 Pro x64
CPU
Intel I5-2500K @3.3GHz
Motherboard
Asrock P67 Extreme4
Memory
16GB G.Skill Ripjaws X (4x4GB)
Graphics Card(s)
EVGA GeForce 750 Ti SC 2GB
Sound Card
ASUS Xonar DG 5.1 Channels 24-bit 96KHz PCI Interface Sound
Monitor(s) Displays
auria eq2367
Screen Resolution
1920 x 1080
Hard Drives
250GB Samsung 850 EVO SSD
1TB WD Blue
1TB Hitachi
PSU
SeaSonic X 650W 80 Plus Gold
Case
Corsair Obsidian 750D
Cooling
Corsair H60, Three 140mm case fans
Keyboard
Logitech Wireless Keyboard K520
Mouse
Logitech Wireless Mouse M310
Internet Speed
Wave Broadband ~ 100 dn 5 up
Antivirus
Windows Defender, Malwarebytes Premium
Browser
Edge, IE11, Chrome
Other Info
Laptop specs: HP g7-1365dx /
CPU: AMD A6-3420M APU with Radeon(tm) HD Graphics /
RAM: Crucial 8Gb (2x4Gb) /
SSD: Crucial M4-CT128M4SSD2 ATA Device/ FW 000F /
GFX: AMD Radeon HD 6520G /
OS: Windows 10 Pro x64
"The offending database was v2013.04.15.12, and was live for only 8 minutes."

Glad I was a little late updating. I run the free version and mark all "check for removal". The free version doesn't have Scheduling with the auto quarantine.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Built 2/11/2011
OS
Windows 7 Pro-x64
CPU
i7-2600 3.4GHz - 3.8GHz Turbo
Motherboard
Intel DH67BL-B3
Memory
8Gb - 2x4GB, Muskin 991770 PC3-1333
Graphics Card(s)
Integrated Intel HD 2000
Sound Card
Integrated Intel 10.1 HD, RealTek ALC892
Monitor(s) Displays
Asus LCD VH222H, Haier HL24XSL2a
Screen Resolution
1920x1080, 1920x1080
Hard Drives
Crucial SSD C300-128Gb,
Western Digital WD5002AALX - 500Gb,
Western Digital WD7501AALS - 750Gb
PSU
Seasonic 650W 80+ Gold Modular
Case
Rosewill Defender
Cooling
Stock CPU, Four 120mm case fans, PCH fan added
Keyboard
Logitech EX100 Y-RBH94 Wireless
Mouse
Logitech EX100 M-RCE95 Wireless
Internet Speed
3.0/1.5 Mbs
Antivirus
Microsoft Security Essentials
Browser
Microsoft Internet Explorer 11
Other Info
Antec Veris Premier-Multimedia IR Station,
Cyber Accoustics-3602 Speakers,
AFT XM-5U Card Reader,
Hauppauge TV-HVR-2250,
Sony LX300 USB Turntable
Back
Top