Jump to content

False positive when installing software


lostinkc

Recommended Posts

The attached file (inside the .zip) was quarantined as containing Malware.Ransom.Agent.Generic, preventing installation of commercial software from TRichView.com.

MalwareBytes concurrently quarantined a registry key (as containing Malware.Ransom.Agent.Generic, blocking its value as well.  The registry key was used in validating software registration.

 

IDEInstall.zip

Link to post
Share on other sites

For Malwarebytes Staffers:

https://www.virustotal.com/gui/file/ddb854064d343f7cc1f28c4ab48ce3fd62f214e3cf37ec3791831ead4793b2d4?nocache=1

Hello @lostinkc and :welcome::

Would you please reply to this topic with the Malwarebytes' scan log? Thank you.

Link to post
Share on other sites

Thank you for whitelisting.  I'm still concerned.  I downloaded updates a few minutes ago which included a restart of Malwarebytes. 

I tried the two installs (D:\Download ISO & Installs\TRichView\TRichViewSetupV22.3.1.exe and D:\Download ISO & Installs\TRichView\TRichViewFMXSetupV22.3.1.exe) again which each failed again, though without moving anything to quarantine.

I copied MBAMSERVICE.LOG and briefly reviewed.  I see reference to each install and the author's name (Sergei Tkachenko).  I have zipped the file for your reference/analysis.

My initial suspicion is that some information about these files is cached and therefore the whitelist may not have been checked (or perhaps wasn't in the Malwarebytes update yet).

MBAMSERVICE.zip

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.