#1
Posted 23 August 2009 - 12:21 AM
The latest updated MBAM (db 2680) on-demand Quick Scan is detecting a wmv file as infected with a trojan. I have had this file for months, am experiencing no problems, and it checks out clean at VirusTotal, so I have no doubt it is a false positive.
What interests me is why an on-demand Quick Scan by MBAM detects this file, but a right-click scan of this file only by MBAM detects no infection?
#2
Posted 23 August 2009 - 12:31 AM
#3
Posted 23 August 2009 - 12:39 AM
#4
Posted 23 August 2009 - 12:54 AM
Database version: 2680
Windows 5.1.2600 Service Pack 3
22/08/2009 8:44:35 PM
mbam-log-2009-08-22 (20-44-22).txt
Scan type: Quick Scan
Objects scanned: 105034
Time elapsed: 3 minute(s), 18 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
C:\endofcivilzation.wmv (Trojan.FakeAlert) -> No action taken. [38575351343036276138473711]
#5
Posted 23 August 2009 - 02:23 AM
Thanks
Edited by Raid, 23 August 2009 - 02:26 AM.
updated information
#6
Posted 23 August 2009 - 02:33 AM
Just my two cents.
Keith
Laptop ----- Intel C2D P8400 (2.4 Ghz), 4GB DDR3 1066, Mainboard, 160GB HD, Dualboot: Windows 7/openSUSE 11.1, Avira Antivir Personal
#7
Posted 23 August 2009 - 03:00 AM
Thanks- I have relocated it from root, and the detection has disappeared.
Out of curiosity, why is placing a wmv file in the root a bad idea? Is this true in general for any media file? And is this true only because of the way MBAM works?
#8
Posted 23 August 2009 - 05:16 AM
#9
Posted 23 August 2009 - 07:08 AM
#10
Posted 24 August 2009 - 04:03 AM

Dell Precision T5400, Win7 Ultimate 32bit fully updated, Symantec Endpoint Protection,
Watchguard Firewall, Intel Xeon CPU, Dual Quad Core Processors, 4GB Ram,
E5410 @ 2.33GHz, Nvidia Quadro FX570, Raid-1 Dual 500GB Sata 10000 rpm Hard Drives
Dual DVD Burners, IE9, Opera, MBAM
#11
Posted 24 August 2009 - 06:02 AM
I think what you're thinking of was the 512 root directory entries in Windows 95 - this does not apply to NTFS volumes.
Errors Creating Files or Folders in the Root Directory
File Names, Paths, and Namespaces
NTFS From Wikipedia
#12
Posted 24 August 2009 - 07:50 PM
Thanks for the refresher advancedsetup.....

Dell Precision T5400, Win7 Ultimate 32bit fully updated, Symantec Endpoint Protection,
Watchguard Firewall, Intel Xeon CPU, Dual Quad Core Processors, 4GB Ram,
E5410 @ 2.33GHz, Nvidia Quadro FX570, Raid-1 Dual 500GB Sata 10000 rpm Hard Drives
Dual DVD Burners, IE9, Opera, MBAM
1 user(s) are reading this topic
0 members, 1 guests, 0 anonymous users
Sign In
Create Account

Back to top










