Author Topic: MBAM false positive?  (Read 4984 times)

0 Members and 1 Guest are viewing this topic.

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
MBAM false positive?
« on: June 09, 2009, 10:43:42 PM »
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform\user-agent: mozilla/4.0 (compatible; msie 6.0; windows nt 5.1; sv1; http: // bsalsa.com)  (Trojan.Banker) -> Quarantined and deleted successfully.

Was the detection correct?
avast does not alert anything about the program which added or changed that registry key.
The best things in life are free.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89025
  • No support PMs thanks
Re: MBAM false positive?
« Reply #1 on: June 10, 2009, 01:26:57 AM »
No alert on mine, but I don't have that Data value in the Post Platform key, mine is the default value, see image.

What did you change ?
Seems like you are changing the user agent, perhaps for that site ???
e.g. do you know the site ?
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Wheresthelove

  • Guest
Re: MBAM false positive?
« Reply #2 on: June 10, 2009, 06:14:25 AM »
You should post that log on malwarebytes forum.... i would zip and attach a copy of the registry key.

Offline !Donovan

  • Web Analyst
  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 2219
    • The WAR Against Malware
Re: MBAM false positive?
« Reply #3 on: June 10, 2009, 06:27:10 AM »
You should post that log on malwarebytes forum.... i would zip and attach a copy of the registry key.

avast forum is better. ::)

It was deleted already. ;D
Familiarize Yourself! | Educate Yourself! | Beautify Yourself! | Scan Yourself!
"People who say it cannot be done should not interrupt those who are doing it."

Wheresthelove

  • Guest
Re: MBAM false positive?
« Reply #4 on: June 10, 2009, 06:29:24 AM »
Haha, i just noticed that like a few seconds after i reply.  On the other hand, you can always restore it.
« Last Edit: June 10, 2009, 06:30:55 AM by Wheresthelove »

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: MBAM false positive?
« Reply #5 on: June 10, 2009, 07:34:16 PM »
I've restored the registry key, updated MBAM and the detection is there yet.
If it is a false positive, it's not corrected yet.
The best things in life are free.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89025
  • No support PMs thanks
Re: MBAM false positive?
« Reply #6 on: June 10, 2009, 07:47:49 PM »
If you haven't reported it at the MBAM forums then you should as that is the only way to have it checked out. There is Report False Positive button in the More Tools tab.

There is a specific forum for reporting FPs (http://www.malwarebytes.org/forums/index.php). So a visit there to see if anyone else is reporting this and it also shows how to do a run with switches to gather more detailed information before posting (http://www.malwarebytes.org/forums/index.php?showtopic=3228)
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security