Jump to content

Detection of "MachineLearning/Anomalous.100%" and generic.malware.ai.dds.


eiksend

Recommended Posts

I ran a scan using Malwarebytes premium edition on a refurbished laptop, and this error was detected. Should I be worried? The file path is C:\Users\PC\AppData\Local\Temp, I can provide any other information if needed, just trying to stay safe and ensure this is nothing to worry about.

Captura de pantalla 2024-03-18 212901.png

Link to post
Share on other sites

Please provide the detection log. @eiksend

You can find Scan and Protection logs within the Malwarebytes 4 program in the following location

 

image.png

 

RTP stands for Real-Time Protection and is where automatic protection operations would normally be logged

 

image.png

 

If you click on the View option you should get something similar to the following with other options available.

 

image.png

 

 

 

Thank you

 

Link to post
Share on other sites

Malwarebytes
www.malwarebytes.com

-Log Details-
Scan Date: 3/18/2024
Scan Time: 7:16 PM
Log File: 1d31d7d4-e575-11ee-a1ee-54e1ad100cc0.json

-Software Information-
Version: 5.1.0.102
Components Version: 1.0.1179
Update Package Version: 1.0.82312
License: Trial

-System Information-
OS: Windows 11 (Build 22621.1778)
CPU: x64
File System: NTFS
User: DESKTOP-IOKNPDR\PC

-Scan Summary-
Scan Type: Threat Scan
Scan Initiated By: Manual
Result: Completed
Objects Scanned: 222509
Threats Detected: 2
Threats Quarantined: 2
Time Elapsed: 2 min, 6 sec

-Scan Options-
Memory: Enabled
Startup: Enabled
File system: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Detect
PUM: Detect

-Scan Details-
Process: 0
(No malicious items detected)

Module: 0
(No malicious items detected)

Registry Key: 0
(No malicious items detected)

Registry Value: 0
(No malicious items detected)

Registry Data: 0
(No malicious items detected)

Data Stream: 0
(No malicious items detected)

Folder: 0
(No malicious items detected)

File: 2
Generic.Malware.AI.DDS, C:\USERS\PC\APPDATA\LOCAL\TEMP\TEST.EXE, Quarantined, 1000002, 0, 1.0.82312, E986A8384AA72CE0D15A2601, dds, 02741584, CC470D06E9AFC9A7C0B395274B02AC88, 81F84A27C49DDD56C799D935787BECB989A6E5B8E000E76E21C82B6CDE4C42FF
MachineLearning/Anomalous.100%, C:\USERS\PC\APPDATA\LOCAL\TEMP\BITF0AE.TMP, Quarantined, 0, 392687, 1.0.82312, , shuriken, , 867C7D073A7F67F86571FA5A39205E64, 210D0249D69C0EB54888BC987753A166A577D6E123D378FAD453F15CBC1B17D4

Physical Sector: 0
(No malicious items detected)

WMI: 0
(No malicious items detected)


(end)

Link to post
Share on other sites

  • Staff

C:\USERS\PC\APPDATA\LOCAL\TEMP\TEST.EXE is a KMSAuto, which is a hacktool. If you trust it and would like to keep it, add it to your allow list.

C:\USERS\PC\APPDATA\LOCAL\TEMP\BITF0AE.TMP we would need the file.

  • Thanks 1
Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.