• Should I believe this?

    Author
    Topic
    #2498974

    I currently have Malwarebytes Anti-exploit 1.13.1.494.  It is set to auto-update which it has done many times without problems.  I think it just tried to update itself and I got this notification from AVG Free.

    Threat-capture

    Is this to be taken seriously?

    Being 20 something in the 70's was far more fun than being 70 something in the insane 20's
    • This topic was modified 2 years, 3 months ago by Charlie.
    • This topic was modified 2 years, 3 months ago by Charlie.
    Viewing 9 reply threads
    Author
    Replies
    • #2498983

      Check the file on virustotal.

      1 user thanked author for this post.
      • #2498988

        VirusTotal wants me to send it the file.  I don’t have the file, it’s in quarantine.

        Being 20 something in the 70's was far more fun than being 70 something in the insane 20's
        • #2498991

          VirusTotal wants me to send it the file.  I don’t have the file, it’s in quarantine.

          Check the AVG procedures for restoring the file from quarantine and “ignoring” it as a possible threat.

          Don’t run it, just note the file’s location. If the original file was in a temp folder, that’s likely where it will be restored to.

          Windows 10 Pro 22H2

    • #2498984

      Is this to be taken seriously?

      If that file is still in quarantine, I would submit it to VirusTotal to see what the consensus of many AV engines are: https://www.virustotal.com/gui/home/upload

      Malwarebytes MBAE latest release posted online is 1.13.1.494. It’s possible that a new release was pushed out but has not been announced yet.

      https://forums.malwarebytes.com/topic/205865-malwarebytes-anti-exploit-113-build-494-released-june-28-2022/

      Windows 10 Pro 22H2

      1 user thanked author for this post.
    • #2498990

      Hi Charlie:

      You might want to post about this in the Malwarebytes Anti-Exploit BETA board at https://forums.malwarebytes.com/forum/126-anti-exploit-beta/.  I just checked employee Arthi’s Malwarebytes Anti-Exploit 1.13 Build 494 Released – June 28, 2022 pinned the top of that forum and the standalone MBAE v1.13.1.494 (NOT v1.13.1.516) is still listed as the current version.

      EDIT:

      Sorry, didn’t realize John W addressed this in post # 2498984 while I was composing my reply.

      2 users thanked author for this post.
      • #2499009

        and the standalone MBAE v1.13.1.494 (NOT v1.13.1.516) is still listed as the current version.

        Thank you for this.  It makes me wary of thinking it may be an AVG false positive.

        Being 20 something in the 70's was far more fun than being 70 something in the insane 20's
    • #2498995

      I googled “IDP.ALEXA.53” and it looks like it could be a false positive common to Avast, AVG, and Avira anti virus programs.

      Edit:  I think I’ll wait and see.  If I restore the MBAE setup program to Windows/Temp it may install itself or get detected by AVG again.  This is very weird.

      Being 20 something in the 70's was far more fun than being 70 something in the insane 20's
      • This reply was modified 2 years, 3 months ago by Charlie.
    • #2499011

      I took MBAE out of auto-update mode and then restored  the setup file in question.  Sent it to VirusTotal and this is what I got:

      Results

      Only one of 71 indicated a malicious program.

      Being 20 something in the 70's was far more fun than being 70 something in the insane 20's
    • #2499020

      Only one of 71 indicated a malicious program.

      If it’s only one, that is most likely a false positive.

      MBAE is beta software, so it’s possible Malwarebytes released an auto-update with the latest version, before the blog is updated.

      If you want to be 100% cautious, leave MBAE out of auto-update mode for a few days/weeks and stick with what you have…

      Windows 10 Pro 22H2

      1 user thanked author for this post.
      • #2499091

        That’s what I’ll do, wait and make sure that the MBAE 13.1.516 setup is a valid program and then let it install.  I’ve set AVG to ignore it.  Thanks to all for your help on this.

        Being 20 something in the 70's was far more fun than being 70 something in the insane 20's
    • #2499474

      Just checked and it appears MBAE 1.13.1.516 beta is now being reported as a valid update.  I, however, have MBAE 1.13.1.494 Premium.  Is it okay to let it update?

      Edit:  I put MBAE back into auto-update mode, and not too long after it updated to 516.  Program still calls itself Premium so, at this point I guess I’m okay.

      Being 20 something in the 70's was far more fun than being 70 something in the insane 20's
      • #2499502

        Just checked and it appears MBAE 1.13.1.516 beta is now being reported as a valid update.  I, however, have MBAE 1.13.1.494 Premium.  Is it okay to let it update?

        Edit:  I put MBAE back into auto-update mode, and not too long after it updated to 516.  Program still calls itself Premium so, at this point I guess I’m okay.

        MBAE free is a beta program. They call it Premium now because it is the full featured version of MBAE. The original MBAE free was “feature limited”.

        A stable version is incorporated into the real-time function of the full Malwarebytes Premium program. MBAE is not sold separately.

        Windows 10 Pro 22H2

        2 users thanked author for this post.
    • #2499503

      Windows 10 Pro 22H2

      1 user thanked author for this post.
    • #2499758

      So it seems that this was a false positive reported by AVG Free’s overzealous behavior shield.  Three days have passed and nothing is wrong so it seems things are okay.  I put the MBAE setup program into AVG’s “Menu – Settings – Exceptions” and it doesn’t detect it anymore.

      Thank you all for your help.

      Being 20 something in the 70's was far more fun than being 70 something in the insane 20's
      1 user thanked author for this post.
    • #2502452

      I think this has been resolved.

      Being 20 something in the 70's was far more fun than being 70 something in the insane 20's
    Viewing 9 reply threads
    Reply To: Reply #2499011 in Should I believe this?

    You can use BBCodes to format your content.
    Your account can't use all available BBCodes, they will be stripped before saving.

    Your information:




    Cancel