Roadkil
Dec 5 2008, 12:44 AM
hey all i just intalled the new version of mbam 1.31 and my Kaspersky finds the setup file as this....12/4/2008 6:22:30 AM Detected: Trojan.generic Malwarebytes' Anti-Malware C:\PROGRAM FILES\MALWAREBYTES' ANTI-MALWARE\MBAM.EXE
This is the 2nd time it has happened and the second time I submitted the file asking it to be whitelisted. The powers that be might want to contact Kaspersky and ask because i guess they dont listen to me. =(
Raid
Dec 5 2008, 12:51 AM
Hiyas Roady!
Thanks for bringing this to our attention.
Roadkil
Dec 5 2008, 01:04 AM
np brother!!! I think its their heuristics doing it because its d/l inside the MBAM he thinks its a trojan. hopefully they will whitelist it this time. i can post it on their forum and see if i get any replies if you want me to.
Roadkil
Dec 5 2008, 11:27 AM
Hey all
Just got a reply in the kaspy forum they said its prob not the heuristics but is prob trojan-like behavior because it is adding itself to auto-run.
Roadkil
Dec 5 2008, 10:00 PM
so is there anyway we can get kaspersky to white-list the program since it is obiviously NOT a trojan? i asked this in their forum and havnt gotten a reply yet.
Tigger93
Dec 5 2008, 10:03 PM
We'll have to wait until they fix this false positive yet again.
Roadkil
Dec 9 2008, 10:01 PM
Grrrrrrrrrrrrrrrrr i just got a reply from the kaspersky virus lab that i submitted the mbam setup exe to that they quratined as a trojan and they said this......
Hello.
No malicious software was found in the attached file.
I posted this to the kaspersky forum and they pretty much told me that mbam showed trojan behavior even tho it is not a trojan and it was flagged correctly. they said it prob wont be white-listed and i would have to white-list it locally on my box. **shrug** I vote we sick Marcin on them =)=)
exile360
Dec 10 2008, 01:47 AM
Are you using KIS or KAV? I use KAV 2009 (ver 8.0.0.506) and haven't gotten this detection. It is probably a heuristic/behavioral detection due to the way MBAM installs it's drivers.
Roadkil
Dec 10 2008, 02:13 AM
its KAV
Tech0utsider
Dec 10 2008, 02:54 AM
Like ComboFix, MBAM uses lots of obsecure methods to remove malware. ComboFix implements NirCmd, which is considered a potentially unwanted program.
exile360
Dec 10 2008, 03:31 AM
Hmm, wierd. KAV doesn't detect Combofix as a PUP now and hasn't for at least a month (I download it regularly to update my toolkit). And like I said, it still doesn't detect mbam-setup.exe. I dunno, strange. It does detect some of my other tools though. It was detecting GMER as a trojan till I contacted the creator to ask Kaspersky to whitelist it (I couldn't send it through my email, even zipped and password protected).
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please
click here.