Jump to content

Ransom.Cerber false positive, Solid Edge xutil.dll


Recommended Posts

Wondering if this Ransom.Cerber result is a false positive, like some of the other recent ones. The detected file is xutil.dll, which has a creation and modified date of 1/2/2003. This DLL is part of the Solid Edge V14 3D CAD program, and the dll itself is listed as being from Spatial Corp. Thanks.

Malwarebytes Anti-Malware

Scan Date: 6/27/16
Scan Time: 12:56 PM
Administrator: Yes

Malware Database: v2016.06.27.05
Rootkit Database: v2016.05.27.01
License: Premium
Malware Protection: Enabled
Malicious Website Protection: Enabled
Self-protection: Disabled

OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: -----

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 300177
Time Elapsed: 5 min, 6 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

Processes: 0
(No malicious items detected)

Modules: 1
Ransom.Cerber, C:\Program Files (x86)\Solid Edge V14\Program\xutil.dll, , [05ec48b91a80c5719ee6717a4db4fd03],

Registry Keys: 0
(No malicious items detected)

Registry Values: 0
(No malicious items detected)

Registry Data: 0
(No malicious items detected)

Folders: 0
(No malicious items detected)

Files: 1
Ransom.Cerber, C:\Program Files (x86)\Solid Edge V14\Program\xutil.dll, , [05ec48b91a80c5719ee6717a4db4fd03],

Physical Sectors: 0
(No malicious items detected)


Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.