Jump to content

Possible False Positive - Games.exe


lmacri

Recommended Posts

MBAM PRO v. 1.60.1.1000 (database v2012.02.02.08) quarantined a file on 02-Feb-2012 at C:\ProgramData\games.exe that I believe is a false positive. The zipped file, as well as a log file from a Quick Scan run in developers mode, is attached.

This file is a Macromedia Flash application and has been on my hard drive since 09-Mar-2011. I installed both WinRAR 4.00 and HP QuickPlay 3.7.7508 on that same date, so I suspect it was part of the HP QuickPlay installation.

A previous on-demand Quick Scan two days ago (31-Jan-2012) with database v. v2012.01.31.09 did not flag games.exe as a potential threat.

I also have Norton Internet Security 2011 v. 18.7.0.13 running in real-time protection mode and NIS Quick Scans have not flagged this file as a threat. My MBAM PRO real-time protection is currently disabled but I have a MBAM Quick Scan scheduled to run daily.

mbam-log-2012-02-02 (18-25-07).txt

Games.zip

Link to post
Share on other sites

  • 1 month later...

Further to my post of 02-Feb-2012, MBAM v. 1.60.1.100 (database v2012.03.13.06) has again incorrectly detected games.exe (C:\ProgramData\games.exe) as a potential threat (this time as Backdoor.Messa).

The games.exe file was quarantined and deleted this time, but a zipped copy of the file is still attached to my post of 02-Feb-2012. Today's log file from my MBAM Quick Scan of 13-Mar-2012 is attached here.

mbam-log-2012-03-13 (20-20-34).txt

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.