Jump to content

Are these false positive? Please advise


tomstam
 Share

Recommended Posts

Hi there,

I ran a scan and quarentined these 2, are they false positives?

Thank you.

Malware's scan results:

Malwarebytes' Anti-Malware 1.39

Database version: 2421

Windows 5.1.2600 Service Pack 3

7/17/2009 4:48:43 PM

mbam-log-2009-07-17 (16-48-36).txt

Scan type: Quick Scan

Objects scanned: 91427

Time elapsed: 6 minute(s), 25 second(s)

Memory Processes Infected: 0

Memory Modules Infected: 0

Registry Keys Infected: 1

Registry Values Infected: 0

Registry Data Items Infected: 0

Folders Infected: 0

Files Infected: 1

Memory Processes Infected:

(No malicious items detected)

Memory Modules Infected:

(No malicious items detected)

Registry Keys Infected:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\install.exe (Trojan.Agent) -> No action taken.

Registry Values Infected:

(No malicious items detected)

Registry Data Items Infected:

(No malicious items detected)

Folders Infected:

(No malicious items detected)

Files Infected:

C:\install.exe (Trojan.Agent) -> No action taken.

Link to post
Share on other sites

  • Staff

If you want to use root to store files please use the ignore function as detection in root is more aggressive than in other locations .

This is likely a FP but to be sure please zip and attach the file to your next post or submit it to virustotal.com to get a report .

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
 Share

  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.