• Home
  • About 404TS
  • Contact

404 Tech Support

Where IT Help is Found

  • Articles
    • Code
    • Entertainment
    • Going Green
    • Hardware, Gadgets, and Products
    • Management
    • Network
    • News
    • Operating Systems
    • Security and Privacy
    • Software
    • System Administration
    • Talking Points
    • Tech Solutions
    • Web
    • Webmaster
  • Reviews
  • Media
    • Infographics
    • Videos
  • Tech Events
  • Tools
    • How do I find my IP address?
    • Browser and plugin tests
  • Get a Technical Consultation
You are here: Home / Articles / Security and Privacy / Malwarebytes false positive detects thousands of entries and renders computers unbootable

Malwarebytes false positive detects thousands of entries and renders computers unbootable

2013-04-16 by Jason

A bad definition file affected Malwarebytes Anti-Malware yesterday. It detected scores of files as false positives and labeled them as Trojan.Downloader.ED. Processes, memory modules, files, and registry entries were all affected. If an unsuspecting user of the program chose to ‘clean’ the files, it would render the computer unbootable as key Windows system files were missing after being quarantined and moved from their normal location. Windows XP, Vista, 7, and 8 PCs were affected if manual action was taken at the end of a scan.

There was only a small window of time where people could update their system to the bad definitions, v2013.04.15.12, before they were replaced by a fixed definition database, v2013.04.15.13.

Some of those affected by the false positive reported their plight and the files detected in this thread on the Malwarebytes forums. Malwarebytes staff have another thread providing steps to fix the problem.

  1. Boot into Safe Mode with Networking
  2. Install Malwarebytes Anti-Malware (because Malwarebytes itself was detected as a false positive)
  3. Go into the quarantine and restore all of the items quarantined incorrectly.
  4. Reboot into normal Windows.

You may also need to download and install VB 6.0 Run-Time service pack 6, as those files were quarantined and are a prerequisite to running Malwarebytes.

Other support options in the thread include using the Malwarebytes Anti-Malware FP Fix Tool for Enterprise customers or contacting home user support and business user support.

From the Malwarebytes staff:

We have also taken extensive measures to ensure that a false positive like this never happens again. Once more, I apologize that this occurred and hopefully we will be able to get everyone’s systems in proper working order once more without too much trouble.

I know the war between malware and security software definitions are an ongoing battle and it’s hard to criticize but I think this event shows that Malwarebytes at the time had little to no quality assurance in place. How did a definition get out that detected so many files incorrectly across the system? I could understand if some random third-party software gets detected as a false positive but when you are detecting and quarantining key Windows files across all version, something got missed. Not to mention that mbam.exe itself was detected and quarantined. Running a simple flash scan with the definitions in-house would have caught this problem before it was distributed to the masses.

malwarebytes_enterprise

Filed Under: Security and Privacy, Software

Trending

  • AV-Test announces 2016 Endpoint Protection awards; Gartner updates antivirus Magic Quadrant
    In Featured, Security and Privacy, Software
  • Ask 404TS: How do I expand your phpBB mods to work for the Subsilver2 theme?
    In Tech Solutions, Webmaster
  • Product Review: Uniden Wireless DVR and Security Cameras
    In Hardware, Gadgets, and Products, Reviews

Latest Media Posts

Find Out Where To Download SNES ROMs

Find Out Where To Download SNES ROMs

Multifunctional Video Conversion Tools – Wondershare Video Converter

Multifunctional Video Conversion Tools – Wondershare Video Converter

  • Popular
  • Latest
  • Today Week Month All
  • Access to the resource [servershare] has been disallowed Access to the resource [servershare] has been disallowed
  • Read the Event Logs on Windows Server Core Read the Event Logs on Windows Server Core
  • What is the AllJoyn Router Service on Windows 10? What is the AllJoyn Router Service on Windows 10?
  • Increase IIS Private Memory Limit to improve WSUS availability Increase IIS Private Memory Limit to improve WSUS availability
  • SOLVED: “This modification is not allowed because the selection is locked.” SOLVED: "This modification is not allowed because the selection is locked."
  • How Virtual Reality Supports Mental Health Therapy How Virtual Reality Supports Mental Health Therapy
  • Key Strategies of Successful Coin Listing on Exchange Key Strategies of Successful Coin Listing on Exchange
  • Keeping Your Mac Healthy: A Comprehensive Guide to Maintenance and Troubleshooting Keeping Your Mac Healthy: A Comprehensive Guide to Maintenance and Troubleshooting
  • Making Distributed Software Development Work: Strategies and Best Practices for Managing Remote Teams Making Distributed Software Development Work: Strategies and Best Practices for Managing Remote Teams
  • customer contactless payment for drink with mobile phon at cafe counter bar,seller coffee shop accept payment by mobile.new normal lifestyle concept The Latest Innovations In Payment Technology
Ajax spinner

Elevator Pitch

404 Tech Support documents solutions to IT problems, shares worthwhile software and websites, and reviews hardware, consumer electronics, and technology-related books.

Subscribe to 404TS articles by email.

Recent Posts

  • How Virtual Reality Supports Mental Health Therapy
  • Key Strategies of Successful Coin Listing on Exchange
  • Keeping Your Mac Healthy: A Comprehensive Guide to Maintenance and Troubleshooting

Search

FTC Disclaimer

404TechSupport is an Amazon.com affiliate; when you click on an Amazon link from 404TS, the site gets a cut of the proceeds from whatever you buy. This site also uses Skimlinks for smart monetization of other affiliate links.
Use of this site requires displaying and viewing ads as they are presented.

Copyright © 2025 · Magazine Pro Theme on Genesis Framework · WordPress · Log in