AnsweredAssumed Answered

Why one installation is shown when application rule has 53 hits?

Question asked by Björn on Apr 23, 2018
Latest reply on Jun 4, 2018 by Björn

We try to figure out, where the Malware from Snow SRS catalog is installed.

 

SLM says one installations for "Malware - Ask Media Tookbar" is one(1):

SLM

 

But the application catalog rule shown 53 hits and redundant rules:

 

6 redundant rules

 

Question1:

What is the mechanism behind this rules, that reduces 53 to just one?

Question2:

Are not all "tbnotifier.exe" bad?

 

Such discrepancy between actuall files and "SRS detected installations" causes big confusion on our side.

 

I woudl appreciate any help.

Outcomes