More ransomware detection false positives?
I recently updated Acronis True Image 2021 and I have been getting "Possible ransomware attack" notifications with respect to the latest version of Emu48, the most popular Windows based HP48 calculator emulator.
When I run the Emu48 executable, all is fine -- it's when I try to save the emulator state to an e48 file that triggers Acronis True Image 2021 to "pause" the Emu48 executable after which Acronis reports a "Possible ransomware attack". When I view the affected files, they're a bunch of icon cache database files in my user profile directory on this Windows 10 x64 machine.
I'm also running the latest version of Malwarebytes premium and also the latest version of ESET NOD32 and they both detect no threat. In addition, running the Emu48 executable and its installer through Virustotal only results in one detection from the dozens of virus scanners, and the scanner which detects a possible threat is some obscure scanner which I've never heard of.
Can anyone confirm that this is indeed a false positive ransomware detection? ( I have had Emu48 running in a Windows 10 x64 VM on a Linux system without any Acronis software and I never noticed any malicious behavior. This leads me to believe that the ransomware detection on my native Windows system is a false positive )
Thanks,
jdb2
P.S. Sorry for not including links to the zip files containing the installers, but the forum software forbids me from including hyperlinks in the body of this post.


- Se connecter pour poster des commentaires