Author Topic: SVC:MBAMSwissArmy Rootkit Detected  (Read 3216 times)

0 Members and 1 Guest are viewing this topic.

Offline mchain

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 5639
  • Spartan Warrior
SVC:MBAMSwissArmy Rootkit Detected
« on: September 02, 2012, 10:21:50 PM »
Started cold boot, 8 Minute scan by Avast! came up with this.  Definitions 120902-1.  Was updating MBAM at the time.  Options were to either delete or ignore, followed by a request for a boot-time scan.  Ignored and no boot-time scan done yet.

FP?
Windows 10 Home 64-bit 22H2 Avast Premier Security version 24.1.6099 (build 24.1.88821.762)  UI version 1.0.797
 UI version 1.0.788.  Windows 11 Home 23H2 - Windows 11 Pro 23H2 Avast Premier Security version 24.2.6105 (build 24.1.8918.827) UI version 1.0.801

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: SVC:MBAMSwissArmy Rootkit Detected
« Reply #1 on: September 02, 2012, 10:22:46 PM »
Yep that is MBAM's low level driver

Offline mchain

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 5639
  • Spartan Warrior
Re: SVC:MBAMSwissArmy Rootkit Detected
« Reply #2 on: September 02, 2012, 10:25:25 PM »
Oh, is ok?  Seems it's a service that would only be running when the gui is open as in downloading updates.
Windows 10 Home 64-bit 22H2 Avast Premier Security version 24.1.6099 (build 24.1.88821.762)  UI version 1.0.797
 UI version 1.0.788.  Windows 11 Home 23H2 - Windows 11 Pro 23H2 Avast Premier Security version 24.2.6105 (build 24.1.8918.827) UI version 1.0.801

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: SVC:MBAMSwissArmy Rootkit Detected
« Reply #3 on: September 02, 2012, 10:27:05 PM »
No its runs all the time .. Even on the free version

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37547
  • Not a avast user
Re: SVC:MBAMSwissArmy Rootkit Detected
« Reply #4 on: September 02, 2012, 10:29:01 PM »
not the first time it is detected ...

Offline mchain

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 5639
  • Spartan Warrior
Re: SVC:MBAMSwissArmy Rootkit Detected
« Reply #5 on: September 02, 2012, 10:34:41 PM »
just curious, how low is l
                                       o
                                         w?

(For the mbam system driver)
Windows 10 Home 64-bit 22H2 Avast Premier Security version 24.1.6099 (build 24.1.88821.762)  UI version 1.0.797
 UI version 1.0.788.  Windows 11 Home 23H2 - Windows 11 Pro 23H2 Avast Premier Security version 24.2.6105 (build 24.1.8918.827) UI version 1.0.801