Skip to main content
Solved

QNAP NetBakScheduler.dll flagged with PUA.SUPERWEB in latest update. real?

  • November 16, 2019
  • 3 replies
  • 24 views

Forum|alt.badge.img+1

Tried submitting as a False Positive Detection but cant upload the dll and the zip executable is too big.

Best answer by TripleHelix

Hello @antz2k and Welcome to the Webroot Community!

 

The best way is to Submit a Support Ticket and they will be able to see it in your log. Also if you can supply them with the MD5 hash that would help big time and even post it here so we can see. You can see in the scan log near the bottom: https://docs.webroot.com/us/en/home/wsa_pc_userguide/wsa_pc_userguide.htm#UsingReportsAndViewers/SavingScanLogs.htm%3FTocPath%3DUsing%2520Reports%2520and%2520Viewers%7C_____1

 

Thanks,

3 replies

TripleHelix
Moderator
Forum|alt.badge.img+63
  • Moderator
  • Answer
  • November 17, 2019

Hello @antz2k and Welcome to the Webroot Community!

 

The best way is to Submit a Support Ticket and they will be able to see it in your log. Also if you can supply them with the MD5 hash that would help big time and even post it here so we can see. You can see in the scan log near the bottom: https://docs.webroot.com/us/en/home/wsa_pc_userguide/wsa_pc_userguide.htm#UsingReportsAndViewers/SavingScanLogs.htm%3FTocPath%3DUsing%2520Reports%2520and%2520Viewers%7C_____1

 

Thanks,


Forum|alt.badge.img+1
  • Author
  • Fresh Face
  • November 17, 2019

Thanks TripleHelix. I’ll open a ticket.

here is the log excerpt

Sat 2019-11-16 14:25:04.0737    Infection detected: C:\Users\Angela's Envy\AppData\Local\Temp\nsjF21.tmp\NetBakScheduler.dll [SHA256: 5A45E98CC701F782B1C5855537B3572824E035E9494BD290D4CDB697197F9846] [MD5: 47E607FC7E9E9203109D153B250743B2] [3/00000000] [Pua.Superweb]
Sat 2019-11-16 14:25:04.0738    File blocked in realtime: C:\Users\Angela's Envy\AppData\Local\Temp\nsjF21.tmp\NetBakScheduler.dll [UniqueID: 8CE9455A, MD5: 47E607FC7E9E9203109D153B250743B2, Size: 1575936 bytes] [0/00000003] [Pua.Superweb]
Sat 2019-11-16 14:25:04.0740    File blocked in realtime: C:\Users\Angela's Envy\AppData\Local\Temp\nsjF21.tmp\NetBakScheduler.dll [UniqueID: 8CE9455A, MD5: 47E607FC7E9E9203109D153B250743B2, Size: 1575936 bytes] [0/00000003] [Pua.Superweb]
Sat 2019-11-16 14:25:05.0184    Infection detected: C:\Users\Angela's Envy\AppData\Local\Temp\nsjF21.tmp\NetBakScheduler.dll [SHA256: 5A45E98CC701F782B1C5855537B3572824E035E9494BD290D4CDB697197F9846] [MD5: 47E607FC7E9E9203109D153B250743B2] [3/00000000] [Pua.Superweb]
Sat 2019-11-16 14:25:05.0185    File blocked in realtime: C:\Users\Angela's Envy\AppData\Local\Temp\nsjF21.tmp\NetBakScheduler.dll [UniqueID: 8CE9455A, MD5: 47E607FC7E9E9203109D153B250743B2, Size: 1575936 bytes] [0/00000003] [Pua.Superweb]
Sat 2019-11-16 14:25:05.0186    File blocked in realtime: C:\Users\Angela's Envy\AppData\Local\Temp\nsjF21.tmp\NetBakScheduler.dll [UniqueID: 8CE9455A, MD5: 47E607FC7E9E9203109D153B250743B2, Size: 1575936 bytes] [0/00000003] [Pua.Superweb]


TripleHelix
Moderator
Forum|alt.badge.img+63
  • Moderator
  • November 18, 2019

Hello@antz2k  I see they have Whitelisted that file now see here and notice the Determination Date! http://snup.webrootcloudav.com/SkyStoreFileUploader/upload.aspx