It looks like avast! may have set the Windows registry HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify to 1, i.e. Windows itself won’t provide a notification if avast! On-Access is disabled or paused. I suppose the Windows notification is unnecessary because avast! provides its own notification in the system tray. Is my assumption correct that this registry mod was done by avast! and it’s appropriate to add it to my MBAM ignore list?
The reason I mention this now is because the MBAM scan I ran an hour ago reported it as a Security Center hijack:
Registry Data Items Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Hijack.SecurityCenter) -> Bad: (1) Good: (0)
Apparently MBAM just added this check a couple of days ago. A search in the MBAM forum provided me with an analysis at http://www.malwarebytes.org/forums/index.php?showtopic=12624&view=findpost&p=64638
I too received the following errors on my scan today. I got this in my restricted user account on Window$ XP SP3. My understanding of the cause of these entries on my system is:AntiVirusDisableNotify (Hijack.SecurityCenter) - Avast Pro anti-virus disabled this and is currently installed, updating and running correctly
MBAM’s lead researcher responded:
QUOTE Why did these entries suddenly appear?We were asked to start fixing these as multiple infections are disabling them . Security center notification defs were added yesterday .
QUOTE
Is my interpretation on the entries above reasonable?Yes
QUOTE
Is it safe to keep these entries in the ignore list permanently? (assuming the above reasons continue to be valid)Yes it is safe and this is the correct course of action for all user/legit software initiated system modifications that MBAM may detect .
One thing people reading this need to keep in mind is that there is no way to tell how something got disabled , only that it is . The vast majority of people never go beyond the antivirus software preinstalled on their system and the occasional free scanner so these detections (for the vast majority of people) will only show up if malware has disabled them.