W32.Trojan.Gen false positives



Show first post

37 replies

from the looks it's ALL OVER....random....i hope it doesnt....i dont have money to move to someone else ><
Userlevel 1
We are in teh same boat here...tons of false positives today. I has set it not to resolve by deletion..but who knows how long that will take. So far removed everything from updaters to database management tools. This is pretty awful. Really hope the restore from quarantine works. Noticed in the logs webroot also deletes registry and any associated config files as well for delete applications.
FYI This is taking out all of the MSPs.  Specifically we are losing almost all .EXE files across all of our clients.
 
It is also hitting our management tools so this has the potential to become a huge labor issue.
 
Do you have any recommended policy settings that we can setup as a new policy to temporarily put a halt to them?
Or a multi-million dollar company trying to conduct business and not able to because it has flagged server applications as malicious and quarantined them. I would have much rathered it be Rocket League not opening.
Same here. I was up to 83 false positives in c:windowssystem32 before I just gave up and disabled Webroot. Everything I submitted to VirusTotal showed up with old hashes and 0 hits, but re-analysing the exact same file showed only 1 new hit, which was Webroot.

I'm not sure what all it screwed up but one of the exes was needed to raise admin privileges. It finally had multiple scans going at once and just locked my PC for 20 minutes. That's when I just gave up, powered on, and disabled it. I have this deployed on hundreds of clients and servers at my company so I hope this doesn't wipe us out today.

It appears some update today has screwed things up badly.
 
Windows 10 64bit Faster insider ring.
i can imagine someone on break playing something like Rocket League and they get kicked off and Webroot locking them off the game
Badge +1
Major False Positives involving known good client applications...

Brought down one of my servers with Sage Businessworks installed. I was not able to restore from quarantine via web panel.. or either I didn't wait long enough. I ended up having to set the Endpoint as unmanaged and restore directly from the GUI on the server.
 
How long should have the restore have taken and I hope this gets fixed VERY quickly before it flags anymore of my servers as malicious.
 
What is everyone's recommendation about removing server files? Do you have it set to automatically resolve or just send the alert so that you can determine what to do with the file?
Userlevel 7
Getting tyhe same re. about 25 .exes that I know are clean, and in fact have been on my system for some weeks now...so something gone a bit funny in the Cloud...I reckon.
 
Baldrick
Userlevel 7
Thanks, @

Our Team is aware of the rule causing False Positives and is actively working now to resolve. Please stay tuned for updates.
i'm getting Brutal Doom 64, one of my games and EVERYTHING involving SteamVR
Userlevel 7
Badge +62
Hi kentko,
 
I am getting False Positives as well...Maybe @ can advise here.
 
Here are my False Positives:
 

Reply