Malwarebytes

Welcome Guest ( Log In | Register )

 
Reply to this topicStart new topic
> False Positive
SweetTech
post Nov 5 2009, 12:29 AM
Post #1


New Member
*

Group: Members
Posts: 2
Joined: 4-November 09
Member No.: 24,111



I've been helping a user at WhatTheTech. A link to the thread.
The file in question is: D:\Program Files\Sierra\Half-Life\gearbox\Dq2249.icd. I suspect the file in question is a false positive because it belongs to the legitimate Sierra Half-Life program. MBAM is detecting the file as a Trojan.Agent infection. It was first detected when the user ran a full scan using MBAM here. The user scanned the file using VirusTotal. I then had the user upload the file to your UploadNet! server. Then I had the user run MBAM in Developer mode and the log can be found here.

I hope that I've provided you with enough information. If you should require any additional scans/logs please let me know.

Thanks,
SweetTech.
Go to the top of the page
 
+Quote Post
miekiemoes
post Nov 5 2009, 06:52 AM
Post #2


Forum Deity
******

Group: Administrators
Posts: 6,617
Joined: 26-December 05
From: Belgium
Member No.: 102



Hi,

QUOTE
The user scanned the file using VirusTotal.
.

I think above results say it already, 21 out of 41 other scanners detect it as well.
In either way, since you uploaded it for us, we will investigate it again and remove detection if it's indeed a false positive.


--------------------
Mieke Verburgh
Malwarebytes Assistant Director of Research



Follow us: Twitter, Become a fan: Facebook
Go to the top of the page
 
+Quote Post
SweetTech
post Nov 6 2009, 03:40 AM
Post #3


New Member
*

Group: Members
Posts: 2
Joined: 4-November 09
Member No.: 24,111



Thanks miekiemoes!

Go to the top of the page
 
+Quote Post

Reply to this topicStart new topic
1 User(s) are reading this topic (1 Guests and 0 Anonymous Users)
0 Members:

 



Lo-Fi Version Time is now: 21st November 2009 - 08:24 AM ()