Skip to main content
droehrig
New Member
July 30, 2019
Question

False Positives Event Logs

  • July 30, 2019
  • 0 replies
  • 1893 views

We have been seeing alot of HkEngineEventFile .xel files flagged as Malware:W32/PossibleThreat and Microsoft-Windows-RemoteDesktopServices-SessionServices%4Operational.evtx files being flagged as Malware:W32/Mauvais.A and they are being quarantined. This really just started in the past couple of weeks. Using the FotiEMS I cannot see where to submit these as false positives. Has anyone else had these quarantined?

 

Donna