Author Topic: Asus ROG Pugio mouse Armoury v30038 had idp.alexa.51 during uninstall  (Read 1353 times)

0 Members and 1 Guest are viewing this topic.

Offline jarcto

  • Newbie
  • *
  • Posts: 1
I bought Asus Rog Pugio mouse about a week ago and installed the armory program as guided in the instructions given.
(for Win 7 64-bit)

Later I noticed program NahimicAPI on the uninstall programs list installed at the same time as the armory for my new mouse.
I tought I have no need for this since it is apparently some sort of audio program that slows down the computer (according to quick google search) I clicked uninstall. Uninstaller ran and at the end of it Avast alarmed of a virus detection. I put it in the virus chest.
Was it just a false alarm or why did it get detected only when uninstalled?

this popped up from avast:
"Threat blocked
We've blocked 136EAC8 because it was infected with IDP.ALEXA.51"
Threat name IDP.ALEXA.51
File path C:\CONFIG.MSI\136EAC8.RBF
Process  C:\PROGRAM FILES\NAHIMICAPI\X86\NAHIMICAPISVC32.EXE
Detected by  Behavior shield

Detection log:

[2019-12-12 08:38:07.545] [info   ] [manager    ] [  652: 3360] Initialize mgr for id 'av'
[2019-12-12 14:13:56.006] [info   ] [manager    ] [  652: 6260] Get detection for hash 'C:\CONFIG.MSI\136EAC8.RBF'
[2019-12-12 14:13:56.006] [info   ] [manager    ] [  652: 6260]  - not found - create with action required '1'
[2019-12-12 14:13:56.006] [info   ] [detection  ] [  652: 6260] Window is closed - open
[2019-12-12 14:13:56.006] [info   ] [win_creator] [  652: 5836] opening window (C:\CONFIG.MSI\136EAC8.RBF)
[2019-12-12 14:13:56.006] [info   ] [manager    ] [  652: 5836] Get detection for hash 'C:\CONFIG.MSI\136EAC8.RBF'
[2019-12-12 14:14:54.437] [info   ] [detection  ] [  652: 6260] User choice - 'block'
[2019-12-12 14:14:59.758] [info   ] [manager    ] [  652: 6260] Get detection for hash 'C:\CONFIG.MSI\136EAC8.RBF'
[2019-12-12 14:14:59.758] [info   ] [detection  ] [  652: 6260] Detection resolved
[2019-12-12 14:14:59.758] [info   ] [manager    ] [  652: 6260] Remove detection for hash 'C:\CONFIG.MSI\136EAC8.RBF'
[2019-12-12 14:15:05.854] [info   ] [win_creator] [  652: 5836] window closed (C:\CONFIG.MSI\136EAC8.RBF)



PS: for those thinking of deleting the program. Apparently it is used for Rog armory interface, since now it shows nothing when opened, but it still remembers settings so apparently it is not a big loss if all settings are done already.
« Last Edit: December 12, 2019, 04:16:05 PM by jarcto »

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37554
  • Not a avast user
Re: Asus ROG Pugio mouse Armoury v30038 had idp.alexa.51 during uninstall
« Reply #1 on: December 12, 2019, 05:00:53 PM »
Quote
Was it just a false alarm or why did it get detected only when uninstalled?
My guess a false positive  "Detected by  Behavior shield"