Jump to content

False positive


Dinac23

Recommended Posts

15 minutes ago, cli said:

Do you have a scan log?

It was in the OP's zip.

Malwarebytes
www.malwarebytes.com

-Log Details-
Protection Event Date: 11/03/2021
Protection Event Time: 11:29
Log File: fa96528c-825c-11eb-9496-c8f733c5dddd.json

-Software Information-
Version: 4.3.0.98
Components Version: 1.0.1173
Update Package Version: 1.0.37995
Licence: Premium

-System Information-
OS: Windows 10 (Build 19041.804)
CPU: x64
File System: NTFS
User: System

-Exploit Details-
File: 0
(No malicious items detected)

Exploit: 1
Malware.Exploit.Agent.Generic, C:\Users\M\AppData\Local\Temp\QueryStorm2\Runtime\0d2773a1725846c58afe74ed0beeb92a\SQLite.Interop.QS.dll, Blocked, 0, 392684, 0.0.0, ,

-Exploit Data-
Affected Application: Microsoft Office Excel
Protection Layer: Application Behavior Protection
Protection Technique: Exploit LoadLibrary attempt blocked
File Name: C:\Users\M\AppData\Local\Temp\QueryStorm2\Runtime\0d2773a1725846c58afe74ed0beeb92a\SQLite.Interop.QS.dll
URL:

 

(end)

  • Thanks 1
Link to post
Share on other sites

  • Root Admin

Hello @Dinac23

I just ran the installer and had no issues with detection or blocking.

What product are you using? A standalone version of MBAE or a Business product or the Malwarebytes 4 Consumer product?

Can you run the following please to get me a full set of logs

Upload Malwarebytes Support Tool logs offline

Thank you

 

 

Link to post
Share on other sites

  • 3 weeks later...

Hey @AdvancedSetup, sorry for the delay, but the client has not replied to my email so I had to give it some time before giving up on expecting a reply.

The only thing that I didn't mention from the beginning of our conversation is that the client mentioned the following:
 

Quote

Loading of SQLite.Interop.QS.dll was blocked by the "Application Behavior Protection" part of Malwarebytes rather than a scan.

So maybe the false positive occurs when using QueryStorm? If I had to guess, it would occur when clicking on the SQL button in the QueryStorm tab in Excel.

Is this helpful information? 

Link to post
Share on other sites

  • Root Admin

They may have had a non-default setting in the program settings.

Typically you can click on the Restore Defaults under the Advanced setting via the main Settings

We've also made some changes to the meta-data that may also help prevent the block. If they're still getting a block though please let us know and gather logs.

 

image.png

Thank you @Dinac23

 

  • Thanks 1
Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.