Jump to content

VKBDevCfg-C_v0.92.33 showing up as Malware.Heuristic.1006


zim55533

Recommended Posts

  • 3 weeks later...
13 hours ago, Porthos said:

If it is the exact same file  in the attachment from the original post, I do not see a detection. If it has changed we need the new file.

image.png.8c29408e689ccaa160c2b466ef64085b.png

As for Virus total,

 

Actually, it seems like it may have changed. The VirusTotal scan in my OP goes to a file that was scanned 15 days ago, but the .exe in the ZIP I just re-downloaded has a new SHA now despite the .ZIP having the same...?

"New" EXE:
https://www.virustotal.com/gui/file/aa495f2105abaee3cb3da0cd77886924c4c4a295a499a55bfb2c8978cda64b32

VKBDevCfg-C_v0.92.33.zip

Link to post
Share on other sites

3 hours ago, zim55533 said:

It's still detected as "Malware.Heuristic.1006" in my desktop app running 4.5.14 with the latest definitions?

Please clear your hubble cache by doing the following:

  1. Click on the Malwarebytes icon in the system tray
  2. Select "Quit Malwarebytes"
  3. Navigate to %PROGRAMDATA%\Malwarebytes\MBAMService
  4. Delete the file HubbleCache
  5. Open Malwarebytes
Link to post
Share on other sites

4 hours ago, Porthos said:

Please clear your hubble cache by doing the following:

  1. Click on the Malwarebytes icon in the system tray
  2. Select "Quit Malwarebytes"
  3. Navigate to %PROGRAMDATA%\Malwarebytes\MBAMService
  4. Delete the file HubbleCache
  5. Open Malwarebytes

Nope, same thing even after deleting the file before.

Link to post
Share on other sites

5 minutes ago, zim55533 said:

Nope, same thing even after deleting the file before.

Could you post the log showing the detection.

You can find Scan and Protection logs within the Malwarebytes 4 program in the following location

 

image.png

 

RTP stands for Real-Time Protection and is where automatic protection operations would normally be logged

 

image.png

 

If you click on the View option you should get something similar to the following with other options available.

 

image.png

 

 

 

Thank you

Link to post
Share on other sites

20 hours ago, Porthos said:

Could you post the log showing the detection.

You can find Scan and Protection logs within the Malwarebytes 4 program in the following location

 

image.png

 

RTP stands for Real-Time Protection and is where automatic protection operations would normally be logged

 

image.png

 

If you click on the View option you should get something similar to the following with other options available.

 

image.png

 

 

 

Thank you

I'm not sure what's going on now. I re-downloaded the file, it finally wasn't detected, but then it was re-detected while I scanned the downloads folder? But after restarting MB it's back to undetected?

Link to post
Share on other sites

6 minutes ago, zim55533 said:

I'm not sure what's going on now. I re-downloaded the file, it finally wasn't detected, but then it was re-detected while I scanned the downloads folder? But after restarting MB it's back to undetected?

It re-appeared. Here's the log:

Quote

Malwarebytes
www.malwarebytes.com

-Log Details-
Scan Date: 9/21/22
Scan Time: 6:31 PM
Log File: dc2e1542-39ca-11ed-84ce-2c4d54d861b6.json

-Software Information-
Version: 4.5.14.210
Components Version: 1.0.1767
Update Package Version: 1.0.60360
License: Free

-System Information-
OS: Windows 10 (Build 19044.2075)
CPU: x64
File System: NTFS
User: DESKTOP-PITRH5Q\zim

-Scan Summary-
Scan Type: Custom Scan
Scan Initiated By: Manual
Result: Completed
Objects Scanned: 74
Threats Detected: 1
Threats Quarantined: 0
Time Elapsed: 0 min, 13 sec

-Scan Options-
Memory: Disabled
Startup: Disabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Detect
PUM: Detect

-Scan Details-
Process: 0
(No malicious items detected)

Module: 0
(No malicious items detected)

Registry Key: 0
(No malicious items detected)

Registry Value: 0
(No malicious items detected)

Registry Data: 0
(No malicious items detected)

Data Stream: 0
(No malicious items detected)

Folder: 0
(No malicious items detected)

File: 1
Malware.Heuristic.1006, C:\USERS\ZIM\DOWNLOADS\VKBDEVCFG-C_V0.92.33\VKBDEVCFG-C.EXE, No Action By User, 1000001, 0, 1.0.60360, 0000000000000000000003EE, dds, 01955584, C62D66FF992C1A69F6F2478CD024CBCD, AA495F2105ABAEE3CB3DA0CD77886924C4C4A295A499A55BFB2C8978CDA64B32

Physical Sector: 0
(No malicious items detected)

WMI: 0
(No malicious items detected)


(end)

 

Link to post
Share on other sites

1 hour ago, zim55533 said:

It re-appeared. Here's the log:

Lets use the support tool and do a clean uninstall and reinstall.

Download the Malwarebytes Support Tool.

Please close all browsers and programs before running the tool. Right click and quit MB from the system tray also.

Once done it will attempt to reinstall both Malwarebytes and Privacy VPN.

Please say no and close the X button on the top right for Privacy unless you have a subscription to it.

image.png.b93181fb3b80e80f52d97f763b34864c.png
Link to post
Share on other sites

6 minutes ago, Porthos said:

Lets use the support tool and do a clean uninstall and reinstall.

 

Download the Malwarebytes Support Tool.

 

 

 

Please close all browsers and programs before running the tool. Right click and quit MB from the system tray also.

 

Once done it will attempt to reinstall both Malwarebytes and Privacy VPN.

 

Please say no and close the X button on the top right for Privacy unless you have a subscription to it.

 

 

image.png.b93181fb3b80e80f52d97f763b34864c.png

Are you sure the file isn't still being falsely flagged? Still marked as malicious on VT with the same name.

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.