Jump to content

Malwarebytes

cant find infected file


5 replies to this topic

#1
normishmael

    New Member

  • Members
  • Pip
  • 16 posts
I get the below hit with Data Base 949 .

Files Infected:
C:\Documents and Settings\norman ishmael\Local Settings\Application Data\GDIPFONTCACHEV1.DAT (Rogue.SpywareDestructor) -> No action taken.

When I follow the follow the file link up to "Applicaton data" I cant locate the file,and I do not know what is is.
I need to know how likely it is to be a false positive,and if I can find out what the file the malware is in does,and if it is safe to quarntine or delete

thanks.

#2
joe53

    Advanced Member

  • Honorary Members
  • PipPipPip
  • 125 posts
Same here:

Malwarebytes' Anti-Malware 1.20
Database version: 949
Windows 5.1.2600 Service Pack 3

Scan type: Quick Scan

Files Infected:
C:\Documents and Settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT (Rogue.SpywareDestructor) -> No action taken.
C:\Documents and Settings\joseph\Local Settings\Application Data\GDIPFONTCACHEV1.DAT (Rogue.SpywareDestructor) -> No action taken.

I can however, find these files. Viruscan.jotti and VirusTotal says they are clean, and thus are presumptive FPs by MBAM.

#3
melboy

    True Member

  • Experts
  • PipPipPipPip
  • 290 posts
Hey, Joe

Its on the FP board. I found it and got the same results from Jotti and VT.

http://malwarebytes.org/forums/index.php?s...amp;#entry22795

#4
joe53

    Advanced Member

  • Honorary Members
  • PipPipPip
  • 125 posts
All fixed with DB 950.

Now that's fast fixin'!

#5
normishmael

    New Member

  • Members
  • Pip
  • 16 posts
Quite a bit of fixin Today.

#6
antonpaco

    New Member

  • Members
  • Pip
  • 34 posts

View Postnormishmael, on Jul 14 2008, 07:21 PM, said:

I get the below hit with Data Base 949 .

Files Infected:
C:\Documents and Settings\norman ishmael\Local Settings\Application Data\GDIPFONTCACHEV1.DAT (Rogue.SpywareDestructor) -> No action taken.

When I follow the follow the file link up to "Applicaton data" I cant locate the file,and I do not know what is is.
I need to know how likely it is to be a false positive,and if I can find out what the file the malware is in does,and if it is safe to quarntine or delete

thanks.

hello, the file that you are talking about is not a virus, is a false positive, don't worry.





1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users

Follow Us