This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

ML/PE-A detected..

ML/PE-A detected at C:\Program Files (x86)\Steam\steamapps\common\Street Fighter IV\SF4Launcher.exe

Since it was deleted I could not even send a sample to get this False Positive corrected.



This thread was automatically locked due to age.
  • Hi Jose,

    Thank you for reaching us, With regards to this, can you accessing the sample submission portal via incognito or other browsers. If the issue persist, please share with us the snapshot of the error you're getting upon submitting sample submission.

    Glenn ArchieSeñas (GlennSen)
    Global Community Support Engineer

    The New Home of Sophos Support Videos!  Visit Sophos Techvids
    • Hi GlennSen,

      You seem to have misunderstood what I meant. The issue is that when ML/PE-A detection comes up, it automatically deletes that file. So how can one send a sample to Sophos when the Endpoint have already deleted it? 

      • Hi Jose,

        Apology for the confusion, with that being said we're you able to re-download the SF4Launcher.exe file? Have you tried re-installing the said application? Was there any option on your central to restore the deleted file?

        Glenn ArchieSeñas (GlennSen)
        Global Community Support Engineer

        The New Home of Sophos Support Videos!  Visit Sophos Techvids
        • Thanks GlennSen,

          I will try to get it re-downloaded. It is unusual though that it only got detected as ML/PE-A the other night when the file has been there for a long time. 

          • Yeah, It's actually odd as to why it got detected as FP in the first place. Unless you use a crack version of SF4. Once you've re-install the application copy the said exe file and submit it right away to our lab's team to change its reputation. 

            Glenn ArchieSeñas (GlennSen)
            Global Community Support Engineer

            The New Home of Sophos Support Videos!  Visit Sophos Techvids
            • Hi ,

              By Any chance, we're you able to re-download the said application? May we know the status of it? We're you still getting the detection or have you already submitted the file as a sample? 

              Glenn ArchieSeñas (GlennSen)
              Global Community Support Engineer

              The New Home of Sophos Support Videos!  Visit Sophos Techvids
              • Hi GlennSen, case number 04023150