Jump to content

PC Matic False Positive DLL Detection


jscotto

Recommended Posts

Hi,

I am attaching the log our customer sent us.  It looks like it has to do with your whitelist signatures.  The info in question starts around line 5286:

01/12/23 " 08:31:29.731" 147855796 1560 2114 INFO CleanControllerImpl mb::cleanctlrimpl::whitelist::PredetectWLCache::FindEntry "predetectwlcache.cpp" 341 "Removing modified entry: 'C:\Program Files (x86)\PCPitstop\Super Shield\SuperShieldProcessHooker32.exe'"
01/12/23 " 08:31:29.731" 147855796 1560 2114 INFO CleanControllerImpl mb::cleanctlrimpl::whitelist::SystemProtectedWhiteLister::IsFileWhiteListed "systemprotectedwhitelister.cpp" 126 "Checking limited system protected white listing for 'C:\Program Files (x86)\PCPitstop\Super Shield\SuperShieldProcessHooker32.exe'"
01/12/23 " 08:31:29.731" 147855796 1560 2114 INFO CleanControllerImpl mb::cleanctlrimpl::whitelist::PredetectSignatureWhiteLister::IsObjectWhiteListedEx "predetectsignaturewhitelister.cpp" 101 "'PC Matic, Inc' not found in whitesigs"

 

Thanks

MBAMSERVICE.txt

Link to post
Share on other sites

  • 3 weeks later...

Hi,

The user finally got back with us and said he is using a different version and that the instructions you provided don't work.  His version is Malwarebytes Endpoint Agent (1. 2. 0. 1022).  I am attaching a log that may be what you are looking for.  Otherwise, I'll need more direction on how to get the correct logs.

 

Thanks

EndpointAgent.txt

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.