Jump to content

false positive?


volc

Recommended Posts

I've made various analyses these days and every analysis show me an alert for things like:

C:\System Volume Information\_restore{AF11A44E-87A6-4ABD-8713-3C178D60C753}\RP297\A0131762.sys

The strange thing is MBAM can remove it (after restarting the computer) but if I do another analysis the day after, or sometimes the same day, I have another file, at the same place but with a different name, for example:

A0131762.sys

A0114805.sys

A0131682.sys

...

I also have Avira Antivir personal (free antivirus) and Spybot

My OS is Windows XP

Is this a false positive?

As aked before, here is the log in developer mode:

-------------------

Malwarebytes' Anti-Malware 1.30

Database version: 1422

Windows 5.1.2600 Service Pack 3

25/11/2008 13:20:57

mbam-log-2008-11-25 (13-20-57).txt

Scan type: Full Scan (C:\|)

Objects scanned: 188605

Time elapsed: 1 hour(s), 45 minute(s), 30 second(s)

Memory Processes Infected: 0

Memory Modules Infected: 0

Registry Keys Infected: 0

Registry Values Infected: 0

Registry Data Items Infected: 0

Folders Infected: 0

Files Infected: 1

Memory Processes Infected:

(No malicious items detected)

Memory Modules Infected:

(No malicious items detected)

Registry Keys Infected:

(No malicious items detected)

Registry Values Infected:

(No malicious items detected)

Registry Data Items Infected:

(No malicious items detected)

Folders Infected:

(No malicious items detected)

Files Infected:

C:\System Volume Information\_restore{AF11A44E-87A6-4ABD-8713-3C178D60C753}\RP298\A0131994.sys (Trojan.Downloader) -> Quarantined and deleted successfully. [4134524130538380756679153780887977806669708313012225262018196620672123241918682

266242218702169221919196625266770]

Link to post
Share on other sites

OK thanks

A question: I deleted this one

C:\System Volume Information\_restore{AF11A44E-87A6-4ABD-8713-3C178D60C753}\RP297\A0131737.sys

Is it a problem for my computer?

Also what should I do with all the same type files in my MBAM quarantine? Do I restore them?

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.