Jump to content
Sign in to follow this  
CoffeeLover

Possible False Positive: Spybot S&D Plugins Detected as Trojan.Agent/Gen-Buzus

Recommended Posts

Hello

 

Just updated the free version of SuperAntiSpyware and started a scan. It is still in progress, but it's currently detecting 3 files as Trojan.Agent/Gen-Buzus:

 

C:\PROGRAM FILES (X86)SPYBOT - SEARCH & DESTROY\PLUGINS\CHAI.DLL

C:\PROGRAM FILES (X86)SPYBOT - SEARCH & DESTROY\PLUGINS\FENNEL.DLL

C:\PROGRAM FILES (X86)SPYBOT - SEARCH & DESTROY\PLUGINS\MATE.DLL

 

I looked at the files to see when they were last changed and the system says they have been there since 2008. It looks to me like this are probably a legitimate part of Spybot, does anyone know if this is SAS with a False Positive or if the threat is genuine?

 

Thanks, will submit a false positive report once scan completes.

Share this post


Link to post
Share on other sites

Hello CoffeeLover,

 

I have done some investigating and have found the source of this false detection. I have made some adjustments to the database, and these files should no longer be detected as of database version 11127 which I am releasing now.

 

Please let me know if you have any other questions or concerns,

 

SAS Malware Research

Share this post


Link to post
Share on other sites

Okay I submitted the false positive report (from before) in case you wanted to look at it. Thanks for making sure they were ok! I figured they were probably legit but I just wanted to make sure. I also saw the Spybot on here was an older version (1.6.2) not the current Spybot 2, so it may be that the older version was just wonky and clashing with SAS.

Share this post


Link to post
Share on other sites
Guest
This topic is now closed to further replies.
Sign in to follow this  

×
×
  • Create New...