Jump to content

Malwarebytes

ClamAV detecting part of MBAM


16 replies to this topic

#1
lordpake

    Advanced Member

  • Honorary Members
  • PipPipPip
  • 215 posts
  • Gender:Male
  • Location:Helsinki / European Union
  • Interests:Anime / Manga / Comp. security
Seems there's f/p in ClamAV database regarding certain file belonging to MBAM.

Quote

C:\Program Files\Malwarebytes' Anti-Malware\mbam-dor.exe: Joke.FakeInfect FOUND

(At least) I have reported this to them.
Men make good pets.

~i~System info~i~

#2
RubbeR DuckY

    Marcin

  • Root Admin
  • PipPipPipPipPipPip
  • 4,092 posts
  • Gender:Male
Thanks for reporting it! Let me know when they have fixed it :).
Marcin Kleczynski
Chief Executive Officer

Posted Image

Follow me on Twitter or check out my Blog!

#3
lordpake

    Advanced Member

  • Honorary Members
  • PipPipPip
  • 215 posts
  • Gender:Male
  • Location:Helsinki / European Union
  • Interests:Anime / Manga / Comp. security
Will do :) I have no idea have fast (or slow) those guys are correcting f/p's ...
Men make good pets.

~i~System info~i~

#4
S3v3n

    New Member

  • Members
  • Pip
  • 1 posts
Mcafee Enterprise is also showing mbam-dor.exe to be infected with Generic.dx Trojan

#5
Killavirus.:LLS:.

    New Member

  • Members
  • Pip
  • 9 posts
  • Gender:Male
  • Location:UK

View PostS3v3n, on Oct 4 2008, 05:32 PM, said:

Mcafee Enterprise is also showing mbam-dor.exe to be infected with Generic.dx Trojan
is somebody else reporting mcafee enterprise or shall i ???

*edit nm done it

#6
DaChew

    Elite Member

  • Experts
  • PipPipPipPipPip
  • 591 posts
http://forums.mcafeehelp.com/showthread.ph...3608#post533608
Regards
Chewy the wild wookie

#7
Rainbow1112

    Regular Member

  • Honorary Members
  • PipPip
  • 72 posts
Fortinet is now detecting this file as a PossibleThreat

http://www.virustotal.com/analisis/21c6c05...8325204f604af2b

#8
lordpake

    Advanced Member

  • Honorary Members
  • PipPipPip
  • 215 posts
  • Gender:Male
  • Location:Helsinki / European Union
  • Interests:Anime / Manga / Comp. security

View PostRainbow1112, on Oct 6 2008, 09:46 PM, said:

Fortinet is now detecting this file as a PossibleThreat
I reported that one to them (or so I hope).
Men make good pets.

~i~System info~i~

#9
JeanInMontana

    Delete this account!!

  • Honorary Members
  • PipPipPipPipPipPip
  • 3,867 posts
  • Interests:would love to see some honesty around this site.
All seems a bit too coincidental.

#10
lordpake

    Advanced Member

  • Honorary Members
  • PipPipPip
  • 215 posts
  • Gender:Male
  • Location:Helsinki / European Union
  • Interests:Anime / Manga / Comp. security
Got a reply from Fortinet. They have removed the detection. And running the file throug VT confirms this :) http://www.virustotal.com/analisis/a551202...b6899e29f49b527
Men make good pets.

~i~System info~i~

#11
Raid

    Malware Researcher

  • Experts
  • PipPipPipPipPipPip
  • 1,549 posts
  • Gender:Male
  • Location:United States

View Postlordpake, on Oct 7 2008, 03:56 AM, said:

Got a reply from Fortinet. They have removed the detection. And running the file throug VT confirms this :) http://www.virustotal.com/analisis/a551202...b6899e29f49b527

Welcome to the world of cutthroat Antivirus. :)

Basically, when one major player decides to detect something, the others tend to follow suit until/unless it's brought to their attention that the suspect file isn't bad at all. The only recourse for the user is to wait for their av to fix the issue, or switch to another av. Neither of which is what I would call, excellent as your at the avers mercy at that point.

#12
lordpake

    Advanced Member

  • Honorary Members
  • PipPipPip
  • 215 posts
  • Gender:Male
  • Location:Helsinki / European Union
  • Interests:Anime / Manga / Comp. security

Quote

ClamAV update process started at Thu Oct 16 12:40:03 2008
main.cld is up to date (version: 48, sigs: 399264, f-level: 35, builder: sven)
daily.cld is up to date (version: 8433, sigs: 48055, f-level: 35, builder: guitar)

2 weeks has passed. False positive detection involving mbam-dor.exe remains.


They obviously place high priority on fixing false positives :blink: Lucky for us MBAM users Clam-derivates enjoy such widespread usage in the Windows world
Men make good pets.

~i~System info~i~

#13
lordpake

    Advanced Member

  • Honorary Members
  • PipPipPip
  • 215 posts
  • Gender:Male
  • Location:Helsinki / European Union
  • Interests:Anime / Manga / Comp. security
Fixed. Either that or the file has changed :)

http://www.virustotal.com/analisis/9308c90...d0257fb8731bdfd (0/36 detection)
Men make good pets.

~i~System info~i~

#14
RubbeR DuckY

    Marcin

  • Root Admin
  • PipPipPipPipPipPip
  • 4,092 posts
  • Gender:Male
Nice, thanks :).
Marcin Kleczynski
Chief Executive Officer

Posted Image

Follow me on Twitter or check out my Blog!

#15
leofelix

    Advanced Member

  • Honorary Members
  • PipPipPip
  • 158 posts
  • Gender:Male
Real time protection of Kasperky Internet Security 2009 detects MBAM 1.30 setup file as "Trojan.Generic", It's a false positive, I know.
I could install MBAM anyway :)

#16
lordpake

    Advanced Member

  • Honorary Members
  • PipPipPip
  • 215 posts
  • Gender:Male
  • Location:Helsinki / European Union
  • Interests:Anime / Manga / Comp. security
(I just had to resurrect this thread :) )

Ah! The ultimate in irony :)

I did a memory scan with ClamWin, witness the shocking result:

Quote

D:\Program Files\ClamWinPortable\ClamWinPortable.exe: Trojan.Agent-65355 FOUND



:) Seems it happens even to the best of us.
Men make good pets.

~i~System info~i~

#17
Mad Dog Vee

    Advanced Member

  • Honorary Members
  • PipPipPip
  • 138 posts
  • Gender:Male
  • Location:Australia
I'm glad you did. That has me ROFL
Posted Image





1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users

Follow Us