View Single Post
  #133  
Old November 3rd, 2009, 02:45 PM
Fuzzfas's Avatar
Fuzzfas Fuzzfas is offline
Very Frequent Poster
 
Join Date: Jun 2007
Posts: 1,864
Default Re: Malwarebytes claim: IObit is stealing signature databases

Sorry if this has been already posted (i don't remember), but this is also interesting:

This is an Oct 24 article-review on IobIt:


Quote:
The virus scan found mostly cookies on my machine. The virus scan also found “Hijack.DisplayProperties.” Interestingly, this is identical to what MalwareBytes Antispyware finds and is not a result of malicious modification.

http://freeantivirushelp.com/blog/po...-Download.aspx

The HijackDisplayProperties detection is a registry key detection, which MBAM flags if you have changed display settings (because theoretically a malware can also do that to camouflage itself).

I have that FALSE POSITIVE , in every scan in Win7 x64 and it's a false positive because it is flagged even after a clean install.


Here's my own screenshot from MBAM Free:

Click image for larger version

Name:	1.png
Views:	16
Size:	13.2 KB
ID:	213473

Yet another satanic coincidence... I suppose by luck they decided to flag the same, generally harmless registry key, as detection and with the same name...

I suppose some user of MBAM, saw this "detection", exported the registry key, renamed it to "HiJackDisplayProperties" , sent it to Iobit, where the same samples analyst put it in the detection list with the same name.

Or, both companies had by coincidence the idea to name the same key with the same name.

The key itself, doesn't help at all the imagination to call it like that (there is no mention about Display Properties).

Name:  2.png
Views: 1134
Size:  1.8 KB
__________________
Avast Home 5 - Win 7 Firewall Control PLUS - WinPatrol Plus
On Demand: Shadow Defender - MBAM Free - Macrium Free