Jump to content

Rogue.AntiVirusPC2009


Recommended Posts

Whenever I run a scan, quick or otherwise, MB finds this . . .

c:\program files\antivirus pc 2009\quarantine (Rogue.AntiVirusPC2009) -> Delete on reboot.

c:\program files (x86)\antivirus pc 2009\quarantine (Rogue.AntiVirusPC2009) -> Delete on reboot.

I can reboot the computer, run the scan again shortly thereafter or the next day and MB finds the same entries again. In windows explorer with the view options set to view hidden and system files, neither of the above program files\ folders exist.

Any ideas anyone?

Link to post
Share on other sites

  • 2 weeks later...

@digdeep

You have anothet thread from a few weeks ago. ref http://forums.malwarebytes.org/index.php?showtopic=104399&hl=&fromsearch=1

Please stop multi-posting, and follow prior advice to open a new topic in Malware Removal

Read and follow the directions >> here << , skipping any steps you are unable to complete.

Link to post
Share on other sites

If you have any Comodo products installed you may want to read this post concerning the same detections:

Guys, this may be an incompatibility issue with Comodo Internet Security and Malwarebytes.

I don't know what option in Comodo is actually responsible for this, but it looks like Comodo maintains a blacklist of known malware folders (or something that can be manually configured). Maybe this is a part of its sandbox, maybe not...

In anyway, the folders malwarebytes detects are not actually there. It's Comodo which is responsible for these "ghost" folders, probably as a part of their defense protection or sandbox, this probably to prevent the creation of these folders in the first place. And because of this behavior, it makes malwarebytes believe those folders are there, thus it reports them as infected.

Or, Comodo intercepts the enumeration of malwarebytes scan, compares with its own blacklist database, and acts as a block here.. and because of that, it confuses malwarebytes scan and makes malwarebytes believe those folders are actually there.

We've had similar reports before already and uninstalling and reinstalling Comodo seems to have solved these "ghost" detections by Malwarebytes.

Also, it may be an idea to disable Comodo during a malwarebytes scan, this to see if it's still detecting the same.

Posted here: http://forums.malwarebytes.org/index.php?showtopic=69003&st=0&p=356541entry356541

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.