Author Topic: MBAM false positives?  (Read 26154 times)

0 Members and 1 Guest are viewing this topic.

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: MBAM false positives? No. avast missdectection again.
« Reply #15 on: April 23, 2010, 09:40:07 PM »
For sure MBAM is detecting it with the latest two virus databases.
The files are the same but they're completely hidden...
The best things in life are free.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: MBAM false positives? No. avast missdectection again.
« Reply #16 on: April 23, 2010, 09:43:24 PM »
No it is just that it is quicker if no other programmes are running, the scan will generate about 300 lines of code.  Obviously if you have just Updated a service pack or something similar there will be a lot more files within the 30 day time frame.  Takes about 10 minutes on mine whilst I am surfing and playing music  ;D

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: MBAM false positives? No. avast missdectection again.
« Reply #17 on: April 23, 2010, 09:55:00 PM »
I'm posting both logs. I just only change my user logon name for Tech.
The best things in life are free.

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: MBAM false positives? No. avast missdectection again.
« Reply #18 on: April 23, 2010, 09:55:27 PM »
The second log...
The best things in life are free.

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: MBAM false positives? No. avast missdectection again.
« Reply #19 on: April 23, 2010, 09:58:57 PM »
I'll boot the computer... see you soon.
Thanks for the help.
The best things in life are free.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: MBAM false positives? No. avast missdectection again.
« Reply #20 on: April 23, 2010, 10:11:13 PM »
You can remove the log attachments now Tech, there are no tasks on your system.  Not even hidden ones as OTL would show them as locked even if they could not be identified
%systemroot%\Tasks\*.job /lockedfiles


It may well be a MBAM false positive.  I am not sure how they are reported as they usually need the file to play with 

To remove OTL run the programme and hit the cleanup button and it will disappear  ;D

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: MBAM false positives? No. avast missdectection again.
« Reply #21 on: April 23, 2010, 10:33:01 PM »
Wow! My computer is clean then!
Thanks for the help. Although a mystery...
The best things in life are free.

bong2x

  • Guest
Re: MBAM false positives? No. avast missdectection again.
« Reply #22 on: April 23, 2010, 10:36:18 PM »
hello tech

i know im not qualified to post here but i like also to share some of my experience about this.
this dynamic link library (dll) virus is difficult to see.
it some kind of murfer process, its run only by service host.

this one don't have a registry that's why resident protection cannot detect it.

if you willing to try my idea, it simple only but maybe it will help

Regards!!!

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: MBAM false positives? No. avast missdectection again.
« Reply #23 on: April 23, 2010, 10:37:20 PM »
Ok, bong2x, but if it is so, how to remove it?
The best things in life are free.

bong2x

  • Guest
Re: MBAM false positives? No. avast missdectection again.
« Reply #24 on: April 23, 2010, 10:48:11 PM »
we will try,
first unhide your system folder

then using search option, search the file  sshnas21.dll,

and open the command prompt, at the end of string type tasklist/svc

this revealed all the service host

let check irrelevant service running there.

 

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: MBAM false positives? No. avast missdectection again.
« Reply #25 on: April 23, 2010, 11:00:51 PM »
Look... the file isn't there... There is no reason to search...
The best things in life are free.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: MBAM false positives? No. avast missdectection again.
« Reply #26 on: April 23, 2010, 11:08:43 PM »
No netsvc indications on OTL either

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: MBAM false positives? No. avast missdectection again.
« Reply #27 on: April 23, 2010, 11:13:13 PM »
Essexboy, why does MBAM is detecting it?
Is there any other scanning I could do to check if my computer is clean?
No abnormal activity in the computer as far I can see...
The best things in life are free.

bong2x

  • Guest
Re: MBAM false positives? No. avast missdectection again.
« Reply #28 on: April 23, 2010, 11:18:31 PM »
tech if the file is hidden cannot be seen physically even in search option,

you must unhide it first. (folder option show hidden files and folder)

sorry i am not good at expressing a word,

ok, how about the service host is there anything you found running not related to any of your application?

Regards!!


Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: MBAM false positives? No. avast missdectection again.
« Reply #29 on: April 23, 2010, 11:36:38 PM »
For pure peace of mind we can run Combofix - I see nothing on your system that would cause problems, so I am happy for you to run it

 Download ComboFix from one of these locations:


Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal.  It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.




Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:




Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you.  Please include the C:\ComboFix.txt in your next reply.