
Malware Or False-positive?
#1
Отправлено 05 Август 2011 - 16:30
------------
Link download file:
http://www.reohix.com/Software/Sleep%20Moon.msi
Link VirusTotal scanning result:
http://www.virustotal.com/file-scan/report...8abc-1312550694
SECOND FILE
---------------
Link download file:
http://software-files-l.cnet.com/s/softwar...ckSetup_exe.exe
Link VirusTotal scanning result:
http://www.virustotal.com/file-scan/report...86b3-1312548864
#2
Отправлено 05 Август 2011 - 16:53
FIRST FILE
------------
Link download file:
http://www.reohix.com/Software/Sleep%20Moon.msi
Link VirusTotal scanning result:
http://www.virustotal.com/file-scan/report...8abc-1312550694
SECOND FILE
---------------
Link download file:
http://software-files-l.cnet.com/s/softwar...ckSetup_exe.exe
Link VirusTotal scanning result:
http://www.virustotal.com/file-scan/report...86b3-1312548864
The first file is most likely a false, yes, please send it to us at vas.drweb.com.
The second one is being detected not only by Dr.Web according to your link and it seems correct, but to make sure you'd better send it to us as well.
Thanks.
R&D www.drweb.com
#3
Отправлено 05 Август 2011 - 17:34
What does it mean?The first file is most likely a false, yes, please send it to us at vas.drweb.com.


Борис А. Чертенко aka Borka.
#4
Отправлено 05 Август 2011 - 17:38
A mistype, of course, sorry! VMS.drweb.com is correct.What does it mean?The first file is most likely a false, yes, please send it to us at vas.drweb.com.
Sure not vMs.drweb.com ?
R&D www.drweb.com
#5
Отправлено 05 Август 2011 - 21:26
http://online.us.drweb.com/cache/?i=f33bbc...5b076d811f4f2a6
#6
Отправлено 06 Август 2011 - 12:19
Scanning them in the DrWeb sandbox I've received the same results I received in the DrWeb scanner of VirusTotal (as you can see in the links I've posted).
According to me it is obvious!
What I'm looking for posting in this forum, is the revision of the files by DrWeb official stuff, as rhey can say me if REALLY the files are malware or not.
Thank you in advance.
Best regards.
#7
Отправлено 06 Август 2011 - 12:41
only virlab can say, are these files malicious or not. Have you sent the files to Dr.Web virlab http://vms.drweb.com/sendvirus ? (sergeyko told you to do this). Have you received any reply?What I'm looking for posting in this forum, is the revision of the files by DrWeb official stuff, as rhey can say me if REALLY the files are malware or not.
Best regards.
#8
Отправлено 06 Август 2011 - 12:58
btw, cnet_FreeAlarmClockSetup_exe.exe contains an advertising software Adware.Zugo.38 - according to Dr.Web it's not-a-virus anyway
#9
Отправлено 08 Август 2011 - 17:02
So, I've sent your files to the Dr.Web virlab.
Sleep_Moon_Xpress.exe - it was false positive. fixed, no detect from Dr.Web now.
cnet_FreeAlarmClockSetup_exe.exe - it is an advertising software Adware.Zugo.38