Jump to content

False positive - dash.exe (Cygwin 32-bit)


swwright
 Share

Recommended Posts

Anti-Ransomware BETA has flagged "dash.exe" as ransomware and quarantined it.  FYI, Dash is the Debian Almquist Shell, a minimalist alternative to Bash for those who use Unix, Linux, Cywin, or similar.

At the time MBARW quarantined the file, Cygwin was not running.

I am following your procedure for restoring the file and reporting a false positive.  I also scanned the file with MBAM and (for what it's worth) Symantec Endpoint Protection.  Neither found anythying amiss with the dash.exe file.  I therefore conclude that this is a false positive.

Per your procedure, two PK-ZIP archives are attached to this post, one containing a copy of the dash.exe file (48KB), and the other containing a copy of the MBARW log directory (182KB).

Thank you.

dash.zip

logs.zip

Link to post
Share on other sites

Thanks, Bob!

I cleared the exclusion list, and will wait a couple of days and see if it triggers again.  I presume my copy of the software was automatically updated.

It would be nice to have some control, or at least visibility, concerning updates in the final product.

Thanks again for the anti-ransomware product.

Link to post
Share on other sites

  • Staff

Hi swwright. Yes, please do monitor the situation for a day or two.

As for a final product, eventually this Anti-Ransomware tech will make it into one of our Malwarebytes Anti-Malware releases. As a standalone, it's intended to be a Beta development platform. When ARW is rolled into MBAM any automatic updates like this will be logged in the program logs for visibility. In ARW, major upgrades are done in the form of a new installer, and the user is notified.

Thanks again for your participation.

 

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
 Share

  • Recently Browsing   0 members

    No registered users viewing this page.

Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.