Jump to content

Malware.AI.3913580972 False Positive


pab49162

Recommended Posts

The following 6 files were flagged by Malwarebytes in a scan that took last night.  I believe these are a false positive and most of these files haven't changed in 2+ years and are scanned every night.

Malwarebytes
www.malwarebytes.com

-Log Details-
Scan Date: 4/21/21
Scan Time: 2:00 AM
Log File: 3053972c-a26f-11eb-8259-00155da437b3.json

-Software Information-
Version: 4.3.0.98
Components Version: 1.0.1251
Update Package Version: 1.0.39665
License: Premium

-System Information-
OS: Windows 10 (Build 19041.928)
CPU: x64
File System: NTFS
User: System

-Scan Summary-
Scan Type: Threat Scan
Scan Initiated By: Scheduler
Result: Completed
Objects Scanned: 345867
Threats Detected: 6
Threats Quarantined: 0
Time Elapsed: 6 min, 49 sec

-Scan Options-
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Detect
PUM: Detect

-Scan Details-
Process: 0
(No malicious items detected)

Module: 0
(No malicious items detected)

Registry Key: 0
(No malicious items detected)

Registry Value: 0
(No malicious items detected)

Registry Data: 0
(No malicious items detected)

Data Stream: 0
(No malicious items detected)

Folder: 0
(No malicious items detected)

File: 6
Malware.AI.3913580972, C:\USERS\PAB49\DESKTOP\Currrent Interests\LinuxLite 5\PuTTYtray - LL5.lnk, No Action By User, 1000000, 0, , , , , 9D9BAEB3A79738AC719C0A5968F174B2, E75C6E6D88E6C18439CBC0582C9DF3920DBC49CAACB325A094C0A5288E93694E
Malware.AI.3913580972, C:\USERS\PAB49\DESKTOP\PC Links\Biostar - openSUSE SSH.lnk, No Action By User, 1000000, 0, , , , , DA88E70ACF05EEA9F7FA534BA36B61CF, 14E6C74EE3D0F510B92F0449010ABA189AEAC8F4254149DC641D36C358ADD743
Malware.AI.3913580972, C:\USERS\PAB49\DESKTOP\PC Links\HomeNAS - SSH.lnk, No Action By User, 1000000, 0, , , , , 61CC2B2AC74B19C513585BFC0EA22751, 42A17AC84E186CE5E5F044C6BB16CFB1E3F5536602961FD344B215837828DFF8
Malware.AI.3913580972, C:\USERS\PAB49\DESKTOP\PC Links\Oasis LinuxLite SSH.lnk, No Action By User, 1000000, 0, , , , , 8AAC14BD5FEC3F3DFD66C55852F749EA, 76C02DFC88FE65233970F45B0584694E22A5FCF5322FA74D298810DF93F1EDCF
Malware.AI.3913580972, C:\USERS\PAB49\DESKTOP\PC Links\Zalman - MX Linux SSH.lnk, No Action By User, 1000000, 0, , , , , 7F0A475ECC78CC8960478CBDC845773B, EC8C699C126A4655C702225618AFC9B2B63974BC190A377FE61EB9C16CEC4DDE
Malware.AI.3913580972, C:\PROGRAM FILES\PUTTYTRAY\PUTTYTRAY.EXE, No Action By User, 1000000, 0, 1.0.39665, B09CA8299C1D8CBFE94481AC, dds, 01211361, EDA980652A56777DB1F52BADCD8FBBA0, 31BA5B51450E1B1FD2CC6038CEB107058068519E9535907AB06850ED23C989B3

Physical Sector: 0
(No malicious items detected)

WMI: 0
(No malicious items detected)


(end)

Most of the files flagged are shortcuts to PuTTYTray which is an improved version of PuTTY, the SSH and telnet client.  It also flagged the PuTTYTray executable itself.  This executable is Version 0.67-t029 and is about 5 years old.  The shortcut files open PuTTYtray using a specific configuration file such as "C:\Program Files\PuTTYtray\PuTTYtray.exe" -load "Oasis LinuxLite"

Attached is a zip file with the executable and a sample of two of the shortcut link files. 

Please let me know if you have any questions.

Thanks, Paul

sample files.zip

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.