Malwarebytes probably picking up false positives again

Discussion in 'Software' started by Nexus_, Feb 18, 2015.

  1. Nexus_

    Nexus_ Staff Sergeant

    i don't think this is a ''virus'' issue so i just posted this here to have an open discussion about false positives malware bytes seems to have.

    I just did a new installation because a hard drive die on one pc i had, i barely did anything on while i set up the new installation but i ran a malware bytes scan just for the heck of it and it said i got this why another person just made a thread about it

    http://forums.majorgeeks.com/showthread.php?t=290870

    it also seems to pick up false positives with virtual drive software as well, and it someone lets the program ''fix'' said ''virus'' then it goes downhill from there.

    Anyone using the most updated (Free) version of malwarebytes (2.0.4) with success? I tried the earlier version hated the features and ui , not only that some of the ''bonus'' features were locked in and i couldn't seem to disable some things unless i got or had a paid version.

    It doesn't seem like it worth going past 1.75
     
  2. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    HI Nexus

    TBH every antivirus/malware software will at some point give out false positives, none are 100% effective at catching all malware anyways, the onus is in two parts to keeping a computer as free from malware as possible.

    1. Keeping any anti-malware/virus, all 3rd party software and Windows fully upto date
    1a. is not having too many antivirus/malware live scanning apps on a PC as false positives can happen at times
    2. The user safe surfing and downloading and having a small amount of doubt about any alert about malware found on a PC as the alert may just be the malware itself.

    The best thing in that users case you highlighted is to follow the advise Chas gave, but also look in the location of the highlighted wordpad.exe is it the correct location for the Windows used, test the exe at something like Jotti

    indeed Wordpad is found in C:\Program Files\Windows NT\Accessories\en-GB but thats the exact file that user found in the mui version (Multi User Interface) the full exact general exe that runs is one folder up C:\Program Files\Windows NT\Accessories

    The en-GB folder will be the english language of Wordpad, if a US user looks its likely in en-US etc for other languages.

    As for Malwarebytes, I find the new version (2.04.1028) fine and ok, latest virus dat file v2015.02.18.05 didnt pick up any issues at all and didnt flag wordpad.

    not going past v1.75 is a choice but at some point in the future updates will likely stop and the app may not in the older form protect, what are the "bonus" features you can adjust in 1.75 that 2.04 cannot? Its great that a company offers free versions, and we all know that they will have features not available in free versions that paid have, this is business and how a company can offer us free versions.
     
  3. Eldon

    Eldon Major Geek Extraordinaire

    Like DavidGP, I am using Malwarebytes Anti-Malware 2.0.4.1028 (Windows 7 Ultimate 32-bit).

    I have just scanned the 3 files (wordpad.exe, WordpadFilter.dll, and wordpad.exe.mui) in "C:\Program Files\Windows NT\Accessories".

    Malwarebytes Anti-Malware found no malicious objects. Which OS are you using?
     
  4. b1jqxk44

    b1jqxk44 Specialist

    Nexus_ check your PM.
     
  5. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    HI

    What other security software do you have installed and as Eldon said do post your Windows version.

    What types of false positives does it pick up in your Virtual Drive, screenshot will help in file names and locations. Plus do test the actual files on Jotti.

    Edit: as the poster in that other thread has posted some logs and looks as if today's definition update may have cured a possible false positive, so run MBAM and update and run again to check yours.

    More info HERE from Malwarebytes, as I mentioned some if not all security software will at times flag a legit app or file up, its a measure of the company to how quick they fix it, and this is a good quick turnaround.
     
    Last edited: Feb 18, 2015
  6. Eldon

    Eldon Major Geek Extraordinaire

    I just checked the Malwarebytes Forum.

    In a nutshell, if you update the database, the false positive will be fixed. :wave

    PS The problem seems peculiar to Windows 8/8.1.
     
  7. Nexus_

    Nexus_ Staff Sergeant

    i am running windows 7 64 bit professional

    The funny thing is right after it came up with this error , i reinstalled the operating system in another hard drive and i got the same exact ''trojan again'' when the only things installed were:
    SUperantispyware, firefox, adobe reader, and ccleaner

    It does seem related to the latest database

    I remember a couple of years ago they released a database update which caused and messed up some users registry and corrupted the operating system. This is why i always try to look at what its trying to quarantine or remove because when it goes into things like the registry etc its bound to cause problems.
     
  8. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Hi

    Are you still getting the same trojan alert?


    If a antimalware app has a false positive in its database def file and its liked as this one was to a core Windows component then you will always get the same flagged file no matter how many times you re-install Windows, until the false positive is removed in the next database update.


    Sadly can happen with any security applications update (for that matter Windows itself), in work we had Trend Enterprise and one update of theirs rendered all Office documents on the network un-openable and usable, good job we have backup servers, this issue affected in our building complex 600+ users.

    So this is why backup of important data is always needed, personally I never keep personal or important data on a OS drive.
     
  9. Eldon

    Eldon Major Geek Extraordinaire

    The question remains - have you updated the database? The advice posted on the Malwarebytes Forum came from a Research Engineer.
     
    Last edited: Feb 19, 2015
  10. Nexus_

    Nexus_ Staff Sergeant

    I did after i duplicated the issue twice on purpose, issue is no longer present well at least not for me.
     
  11. Eldon

    Eldon Major Geek Extraordinaire

    Good to know the issue has been sorted out.

    I think publishers are having a hard time. They release programs supporting Windows XP, Vista, 7, 8, and now 10. And then there's 32-bit and 64-bit.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds