Hello,
Malwarebytes has detected this Winflash.sys as a Rootkit.Necurs
Is this right? or is it a false positive?
The file is located here:
C:\Program Files (x86)\Lenovo\System Update\session\8buj14us\WinFlash.sys
I'm pretty sure it's a false positive as i keep my Lenovo as clean as possible & don't visit dodgy sites etc but i quarantined the file anyway just in case.
Thanks in advance.
-
The file itself is for bios flashing................
-
Plenty of Google hits indeed mentioning the 8buj14us\WinFlash.sys file, being the official Lenovo BIOS flash utility.
But as the W520 is sold plenty, I'd expect it to be recognized by Malwarebytes'Antimalware.
Why not report the file as a FP on the MBAM forum to be sure? Let them analyze the file and you'll help fellow W520 users also. MBAM false positive forum page link -
Thank you both for your replies.
Thank you for the link, i'll do that. -
Hello,
You can confirm whether it is a false positive by uploading the file to virustotal.com for analysis.
Advice needed please rootkit or false positive?
Discussion in 'Security and Anti-Virus Software' started by Dealz, Aug 3, 2012.