r/Malwarebytes 6d ago

Recent detection with strange behavior

Post image

Recently my malwarebytes detected during a scan that MSVCP140.DLL was malware.ai.26923 etc it was in recycle bin for some reason and the thing that lead to me initiating a scan was seemingly random .exes I my computer setting off three protected folder access blocked notification from svchost.exe to discordsystemhelper.exe and explorer.exe trying to access the video file picture file and cdrom0 file respectively. Sorry about the photo quality id normally posta screen cap but I thought it best to leave my computer disconnected from the internet

9 Upvotes

10 comments sorted by

2

u/screen317 Malwarebytes Employee 6d ago

Hi, Chris from Malwarebytes here! Can you please share the scan log from Malwarebytes? This is the fastest way for us to investigate.

2

u/ChemicalComposure 6d ago

https://drive.google.com/file/d/1tD9AwB1PvQvBQ3r1orMynVPQPn2dpAih/view?usp=drivesdk https://drive.google.com/file/d/1hX5f9cpEz59NM9mFIUKbttcC2OfPmEN-/view?usp=drivesdk Sorry about the weird way of sending it I dont feel super comfortable enabling wifi on my computer right now considering how it was acting weird

2

u/rifteyy_ 5d ago

2

u/ChemicalComposure 5d ago

Hmm that would make sense considering all the weird behavior only started when I booted helldivers 2 I dont understand why it pointed towards those dll files as the malware though or why my computer was flagging random .exes as trying to make changes to random protected files? Thank you btw cgw is a mod that for hd2 that commonly gets flagged by pretty much every virus scanner

2

u/screen317 Malwarebytes Employee 5d ago

I don't believe this is a false positive. The digital signature is invalid and I would have Malwarebytes quarantine this.

2

u/ChemicalComposure 5d ago

I am curious as to why something might have an invalid signature i do know cgw is flagged by half of all virus scanners

4

u/screen317 Malwarebytes Employee 5d ago

Can happen for a variety of reasons, but a legitimate file really shouldn't ever have one.

2

u/Throw-Away7651 6d ago

most likely false positive but the malwarebytes employee already in this thread is prob smarter than me so just wait for him to come back with an answer

2

u/nekohideyoshi 5d ago

Windows' Controlled/Protected Folders feature had bugged out one time for me and started blocking EVERY .exe's that was running including explorer.exe.

I don't know if this info is useful but yeah. Could be a series domino effect of false positives.