Jump to content

New Possible False Positive


Recommended Posts

Got a small problem.

One of our accounting 3rd party addons has been quarantined by Malwarebytes.  Timberscan.NET.exe resides on a server on our local domain and is executed via desktop shortcut and a "Named Pipes" MSSQL connection set up in 32bit ODBC Administrator.  C:\Users\ ”account-name” \AppData\Local\Spoon\Sandbox\TimberScan\3.8.6.40\local\stubexe\0xEF37104E112B0AD5\TimberScan.exe is the file created locally that is being quarantined.  I have attached it zipped.

I would like to see this particular item excluded from future updates, unless of course this IS malware.  Checking my server just in case.

 

Thanks,

 

TimberScan.zip

Link to post
Share on other sites

malwarebytes is not the only one that dont like it

https://www.virustotal.com/#/file/cc1228d71b46df179ed4066e3fc7c512204dd9847ab24daa4733c63f38a0d3e3/detection

you should report possible false positives here  >>  https://forums.malwarebytes.com/forum/42-file-detections/

 

Edited by pondus
Link to post
Share on other sites

Yeah, I was concerned until I ran the original file.  Only one and Malwarebytes is fine with it as well.  It's 136mb so I couldn't upload it.

https://www.virustotal.com/#/file/4d8ef3514506fd4f5ed1a3d497fc3399c24746124e0fb4df1b4dc671de8c4e71/detection

And thanks for the other link.  I'll read through those and follow up appropriately.

I've also emailed my account rep as I'm up for renewal.

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
 Share

  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.