Jump to content

Malwarebytes

False positives in Diablo uninstall apps


3 replies to this topic

#1
doomer

    New Member

  • Members
  • Pip
  • 2 posts
Hello. I would like to report two false positives generated by MBAM. I am using the latest version. The log file is the following.

============================

Malwarebytes' Anti-Malware 1.25
Database version: 1099
Windows 6.0.6001 Service Pack 1

09:07:55 31.8.2008 г.
mbam-log-08-31-2008 (09-07-53).txt

Scan type: Full Scan (C:\|)
Objects scanned: 217818
Time elapsed: 1 hour(s), 6 minute(s), 14 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 2
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 2

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\battle.net (Trojan.FakeAlert) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\diablo (Trojan.FakeAlert) -> No action taken.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Windows\bnetunin.exe (Trojan.FakeAlert) -> No action taken.
C:\Windows\diabunin.exe (Trojan.FakeAlert) -> No action taken.

============================================

Now, bnetunin.exe and diabunin.exe come straight from the original Diablo cd from Blizzard. Those files have been the same since 1996, which is the game's release date, and I can confirm they are definitely not viruses but the uninstall utilities for Diablo, and respectively the Battle.net service. That becomes more apparent since MBAM links the two files with their registry entries precisely where they should be, HKLM/....../CurrentVersion/Uninstall. Thank you in advance.

Edit: I updated in one hour ago, but I just noticed a 1101 database, so instead of doing another 1:10 hour scan.. I just scanned those two files. Still detected as viruses.

============================================

Malwarebytes' Anti-Malware 1.25
Database version: 1101
Windows 6.0.6001 Service Pack 1

10:07:51 31.8.2008 г.
mbam-log-08-31-2008 (10-07-48).txt

Scan type: Quick Scan
Objects scanned: 2
Time elapsed: 2 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 2
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 2

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\battle.net (Trojan.FakeAlert) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\diablo (Trojan.FakeAlert) -> No action taken.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
c:\Windows\bnetunin.exe (Trojan.FakeAlert) -> No action taken.
c:\Windows\diabunin.exe (Trojan.FakeAlert) -> No action taken.

=============================================

#2
Raid

    Malware Researcher

  • Experts
  • PipPipPipPipPipPip
  • 1,549 posts
  • Gender:Male
  • Location:United States
Hi there,

Please zip the offending files as FPcheck1.zip and upload it to uploads.malwarebytes.org We'll get this fixed!

#3
doomer

    New Member

  • Members
  • Pip
  • 2 posts
The files have been uploaded. Thank you for the quick reply.

#4
nosirrah

    Forum Deity

  • Administrators
  • PipPipPipPipPipPip
  • 5,399 posts
  • Location:Northampton, MA USA
Cinfirmed FPs , will be fixed within the next few hours .
Bruce Harrison
Vice President of Research

Posted Image

Follow us: Twitter, Become a fan: Facebook





1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users

Follow Us