Jump to content

Malwarebytes

SvchostAnalyzer False Positve?


7 replies to this topic

#1
DonZ

    Regular Member

  • Honorary Members
  • PipPip
  • 68 posts
I downloaded this file this morning from Nueber.com. Norton AV 2012 Insight scan said file was OK.

I came out of standby a short time ago and MBAM Pro flagged it as hueistic as a result of a flash scan. I viewed a couple of forum postings from last year that stated this FP was fixed, Obviously it isn't.

Log attached.

#2
shadowwar

    Forum Deity

  • Moderators
  • PipPipPipPipPipPip
  • 2,680 posts
There is no log attached. Please attach in a response along with the file please.
Rich Matteo
Research Engineer

Posted Image

Follow us: Twitter, Become a fan: Facebook

#3
DonZ

    Regular Member

  • Honorary Members
  • PipPip
  • 68 posts
Lets try this again. Swore I attached the log the first time

Attached Files



#4
shadowwar

    Forum Deity

  • Moderators
  • PipPipPipPipPipPip
  • 2,680 posts
can u please attach that file in zip format.

I need the file to fix it and the link you provided doesnt exist.
Rich Matteo
Research Engineer

Posted Image

Follow us: Twitter, Become a fan: Facebook

#5
DonZ

    Regular Member

  • Honorary Members
  • PipPip
  • 68 posts
Here it is

Attached Files



#6
shadowwar

    Forum Deity

  • Moderators
  • PipPipPipPipPipPip
  • 2,680 posts
This will be fixed shortly.

To let you know this is a def that looks for misplaced files starting with the name svchost ( malware commonly does this) that isnt in the proper windows spot. Most of the time cause its a heuristic it can be simply added to ignore list. I have whitelisted your file for the next update.
Rich Matteo
Research Engineer

Posted Image

Follow us: Twitter, Become a fan: Facebook

#7
DonZ

    Regular Member

  • Honorary Members
  • PipPip
  • 68 posts
Thanks.

I do presently have it in the ignore list.

BTW - this is an excellent utility to determine if all your services are legit. More so now that it works with WIN 7.

#8
shadowwar

    Forum Deity

  • Moderators
  • PipPipPipPipPipPip
  • 2,680 posts
Yes i ran it and definately useful.

Thanks for reporting!
Rich Matteo
Research Engineer

Posted Image

Follow us: Twitter, Become a fan: Facebook





1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users

Follow Us