Theoracle117
Joined: 18 Sep 2008 |
Posts: 0 |
Location: san diego |
|
 |
Posted: Sun Oct 05, 2008 3:29 am |
|
 |
 |
 |
 |
Malwarebytes(im sure some of you are familiar with it) is a antivirus program i use along side my Bitdefender total 2009 and clam win portable on my usb.
I noticed a wierd file in the Malwarebytes directory named mbam-dor.exe When i double click on it, Nothing happens and Bitdefender says that it has just removed a trojan
here is the image i uploaded of what happens
https://img72.imageshack.us/my.php?image=malwarebytesvirusml8.png
this happens everytime i click on that file. I uploaded it to virustotal, and four Av's recognize it as a virus, Clam Av as something that starts with "Fake."
A direct scan on the file with Bitdefender, and nothing happens. So can anyone varify that this is a false positive or not?
|
|
GuitarBob
Joined: 09 Jul 2006 |
Posts: 9 |
Location: USA |
|
 |
Posted: Sun Oct 05, 2008 1:52 pm |
|
 |
 |
 |
 |
McAfee supposedly said it was a false positve. Here's a Malwarebytes thread:
https://www.malwarebytes.org/forums/index.php?s=78332325ec3f6c4102e269b9c198579d&showtopic=6643&pid=29812&st=0&#entry29812
On the other hand, here's a McAfee forum thread from a few months ago about it:
https://forums.mcafeehelp.com/showthread.php?s=56caa69c2085d99d5a4c9ce1f785ba69&p=533608#post533608
If McAfee still calls the file infected after these months, I would go by that.
Regards,
|
|
Theoracle117
Joined: 18 Sep 2008 |
Posts: 0 |
Location: san diego |
|
 |
Posted: Sun Oct 05, 2008 5:33 pm |
|
 |
 |
 |
 |
something else thats strange. Bitdefender does not detect the file directly, but if you run the exe, it will try to create a .sys file in the system32/drivers directory.
The words/numbers/letters before the .sys a random because everytime i click on it, it genereates a new sys file.
|
|