Author Topic: Wtf ? mbamswissarmy.sys  (Read 10757 times)

0 Members and 1 Guest are viewing this topic.

Mr.Agent

  • Guest
Wtf ? mbamswissarmy.sys
« on: December 05, 2009, 05:34:59 PM »
What !!!! Wrong now !!! Your avast! detecting a suspect file now from malwarebytes ???? Why ???

Im going to scare now....

I hope i did a good move to ignore and remember the answer for the file...

Mr.Agent

Offline Chris Thomas

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1936
  • Christian Geek - aka 'born again' Geek
Re: Wtf ? mbamswissarmy.sys
« Reply #1 on: December 05, 2009, 05:39:03 PM »
Did ya push the update button of Avast?   :o

Mr.Agent

  • Guest
Re: Wtf ? mbamswissarmy.sys
« Reply #2 on: December 05, 2009, 05:40:38 PM »
I did update and its loading so i think its submit to ALWIL... Wow i cant believe it...

Damn !

I almost did died from a heart attack... :-\

Mr.gent

Offline igor

  • Avast team
  • Serious Graphoman
  • *
  • Posts: 11856
    • AVAST Software
Re: Wtf ? mbamswissarmy.sys
« Reply #3 on: December 05, 2009, 05:41:03 PM »
What malware name was reported?

Mr.Agent

  • Guest
Re: Wtf ? mbamswissarmy.sys
« Reply #4 on: December 05, 2009, 05:42:01 PM »
Oh damn igor thx for reply.

Its a Malwarebytes Files.

mbamswissarmy.sys its located on my system32 drivers for sure.

Offline Chris Thomas

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1936
  • Christian Geek - aka 'born again' Geek
Re: Wtf ? mbamswissarmy.sys
« Reply #5 on: December 05, 2009, 05:43:49 PM »
Igor asked for that Malware name :)

Was it Win32:Zbot - MKK or Win32:Delf-MZG ?

Or any other name?

You can refer your Virus Chest.

Mr.Agent

  • Guest
Re: Wtf ? mbamswissarmy.sys
« Reply #6 on: December 05, 2009, 05:44:17 PM »
Suspect Files

YoKenny

  • Guest
Re: Wtf ? mbamswissarmy.sys
« Reply #7 on: December 05, 2009, 06:44:33 PM »
That's a normal alert from Windows Defender when Malwarebytes' Anti-Malware it running a Quick scan.

Mr.Agent

  • Guest
Re: Wtf ? mbamswissarmy.sys
« Reply #8 on: December 05, 2009, 06:45:45 PM »
I did run a quick scan. And Windows Defender said nothing just avast! did it...

YoKenny

  • Guest
Re: Wtf ? mbamswissarmy.sys
« Reply #9 on: December 05, 2009, 06:53:34 PM »
With XP or Vista/Windows 7?

I don't get the alert on Windows 7.

Mr.Agent

  • Guest
Re: Wtf ? mbamswissarmy.sys
« Reply #10 on: December 05, 2009, 06:57:46 PM »
Vista.

But i think its normal like you said. I did push Ignore then Remember the Answer. I have sended the file to ALWIL too as its wanted to do it. So i think i wont got anymore problem.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89212
  • No support PMs thanks
Re: Wtf ? mbamswissarmy.sys
« Reply #11 on: December 05, 2009, 07:32:17 PM »
I believe what Mr.Agent fails to report that this is a alert by the anti-rootkit scan, see image, am I right ?

Alert text:
"A suspicious file has been detected (using a heuristic method). This may be a sign of malware infection. Please allow the file to be submitted to our virus lab for analysis."

If so it isn't saying it is infected just suspect and there would be no malware name given.

So you should chose the default action, Ignore and allow it to be sent to avast for analysis.

I think it a mistake to select the remember the answer as you would never know if this has been resolved by Alwil after the analysis as it wouldn't be asking for a decision in future.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Mr.Agent

  • Guest
Re: Wtf ? mbamswissarmy.sys
« Reply #12 on: December 05, 2009, 07:33:52 PM »
Right said David !!!!! You have win. I did do ignore and dont tell me this in the future and allow to be send in ALWIL Labs... So i did the right action ?

Wow great job David and thx for the reply. ;D

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89212
  • No support PMs thanks
Re: Wtf ? mbamswissarmy.sys
« Reply #13 on: December 05, 2009, 07:43:45 PM »
Well insofar as you didn't opt for deletion, yes you did OK.

As I said I personally wouldn't have selected remember/Do not tell me about this file in the future, but that's just me. I like to know exactly what is going on in my system, whilst I would have known that this was likely to be an FP, what I also want to know is when it has been analysed and the alert corrected.

When you choose the 'Do not tell me about this file in the future' option that won't happen as you are never told about it again. The other aspect is I don't know if there is a way to reverse that decision. So it is possible if it were malicious, you could have effectively allowed it and asked not to be told about it again, in my view this is a dangerous option.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Mr.Agent

  • Guest
Re: Wtf ? mbamswissarmy.sys
« Reply #14 on: December 05, 2009, 07:51:48 PM »
Well as far i know i did go in malwarebytes forum and search on it the file in question and they said its a malwarebytes file... So that why i did do remember in the future so we cant annoy me and i wont got a heart attack lol...