- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic to the Top
- Bookmark
- Subscribe
- Printer Friendly Page
malwarebyt es reporting dmload.sys as trojan
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Email to a Friend
- Report Inappropriate Content
08-04-2009 09:02 AM
When I perform a full scan on a T60, that has Rescue & Recovery installed, with Malwarebytes it reports dmload.sys as a trojan.
I have run it on serveral different T60s in our office with the same result.
Is this a false positive?
Re: malwarebyt es reporting dmload.sys as trojan
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Email to a Friend
- Report Inappropriate Content
08-04-2009 10:04 AM
This is a good question. I've seen cases where this file has been infected indeed. You can read the technical information on this link.
http://www.threatexpert.com/report.aspx?md5=32569d
If this is the case, I'd highly recommend running your Antivirus program in safe mode first to see if it can detect and remove (or quarantine) it for you. I had that nasty TDSS backdoor trojan on my own machine a couple a days ago. I used Avira to get it removed.
So to answer your question, I'd say no. It's not false.
Now if you want to repair that file, you can follow the steps below given by a friend of mine. But I must caution you though -IF that file IS infected, this will NOT help you.
- Browse to the following file path:
C:\Windows\ServicePackFiles\i386 - Search for the file "dmload.sys"
- Right click the file and hit Copy.
- Go to the following file path:
C:\Windows\System32\drivers - Right click in the folder and select Paste.
- Please confirm the overwrite.
- Now please reboot your system.
Hope this will give you some insite.
Regards,
Mark
Do NOT PM me with technical issues. Post in the forum for assistance. Thanks
