Jump to content

Asphalt8 False positive?


ARIMO
 Share

Recommended Posts

MBARW put Asphalt8_w8.exe in quarantine, and it was not possible to restore it, but after have reinstalled the app, I found that the MD5 of Asphalt8_w8.exe does not match to the quarantined file, it may have been infected, or MBARW modified the file? I attach also the original executable, and the quarantine files, for a possible confrontation.

 

In the windows events it's reported that a few minutes before MBARW put Asphalt8_w8.exe in quarantine, there were errors with shadow copies (Event ID 12293 - Volume Shadow Copy Service Operations), also was running the quick scan planned of Avira, I don't know if these activities may have triggered the detection of the false positive.

 

Malwarebytes Anti-Ransomware.zip

logs.zip

Asphalt8_w8_exe_orig.zip

Asphalt8 QuarantineFiles.zip

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
 Share

  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.