View Full Version : False Positives - Enhance Movie 2.2 and Send photos Gold 4
kentroup
10-24-2007, 10:23 AM
A scan of my system casts up the following program files (and their shortcuts) as being high level threats:- enhancemovie.exe from Enhance Movie 2.2 and sendphotos.exe from Send Photos Gold 4.
Here are the actual files:- http://rapidshare.com/files/64794967/false_positives.rar
Symantec Antivirus is quite happy with the files.
nosirrah
10-24-2007, 04:16 PM
File EnhanceMovie.exe received on 10.24.2007 17:07:09 (CET)
Result: 5/32 (15.63%)
Ikarus T3.1.1.12 2007.10.24 Trojan-Spy.Win32.Bancos.ha
Sunbelt 2.2.907.0 2007.10.23 VIPRE.Suspicious
TheHacker 6.2.9.106 2007.10.24 W32/Behav-Heuristic-060
VirusBuster 4.3.26:9 2007.10.24 Packed/Upack
Webwasher-Gateway 6.6.1 2007.10.24 Win32.Malware.gen#Upack (suspicious)
File size: 1511442 bytes
MD5: c4394f3682cc9bb72937729c8552b51a
SHA1: e2ee441ed78f6a04b0bd19cddfb220ffeb5ac17f
packers: UPack
packers: PE_Patch, UPack
I will fire this up tonight to see if this is true .
AChen
10-25-2007, 12:29 AM
A scan of my system casts up the following program files (and their shortcuts) as being high level threats:- enhancemovie.exe from Enhance Movie 2.2 and sendphotos.exe from Send Photos Gold 4.
Here are the actual files:- http://rapidshare.com/files/64794967/false_positives.rar
Symantec Antivirus is quite happy with the files.
Hi Kentroup,
Thanks for the info. We'll investigate this further and I will update you on this.
AChen
10-29-2007, 03:18 AM
We have done testing with this and it appears that the download for Send Photo Gold 4 and Enhanced movie 2.2 has been modified as a crack version.
Please download a clean version from trusted sites such as download.com.
kentroup
10-29-2007, 02:04 PM
We have done testing with this and it appears that the download for Send Photo Gold 4 and Enhanced movie 2.2 has been modified as a crack version.
Please download a clean version from trusted sites such as download.com.
hi AChen,
does that mean that Spyware Doctor has found a real threat that no other antivirus can find and my PC is in danger?
Or does it mean that no-one is really interested and it is a good excuse to brush it under the carpet?
When a virus hits, I would like my antivirus program to be trustworthy regardless of where the virus comes from - or does PCtools have 'out clauses' like - if you got your virus from a site not agreeable to us, then we will not be responsible etc etc
AChen
10-30-2007, 12:37 AM
hi AChen,
does that mean that Spyware Doctor has found a real threat that no other antivirus can find and my PC is in danger?
Or does it mean that no-one is really interested and it is a good excuse to brush it under the carpet?
When a virus hits, I would like my antivirus program to be trustworthy regardless of where the virus comes from - or does PCtools have 'out clauses' like - if you got your virus from a site not agreeable to us, then we will not be responsible etc etc
The file that you sent us are detected as Packed/UPack. This detection name doesn't mean the file is malicious, instead it's raising user awareness that the file is packed. PC Tools protect our customer by detecting packers that are commonly used by malware, not to indicate as malicious but to proactively inform users about the nature of the file.
Upon analyzing the code, the file doesn't contain any malicious code and will pose no threat to you're pc. Fortunate enough, the file is only modified and packed for cracking purposes. However, most of cracked files and packages found in different warez sites come along with different malwares.
Hope this helps :)
kentroup
10-30-2007, 09:09 AM
The file that you sent us are detected as Packed/UnPack. This detection name doesn't mean the file is malicious, instead it's raising user awareness that the file is packed. PC Tools protect our customer by detecting packers that are commonly used by malware, not to indicate as malicious but to proactively inform users about the nature of the file.
Upon analyzing the code, the file doesn't contain any malicious code and will pose no threat to you're pc. Fortunate enough, the file is only modified and packed for cracking purposes. However, most of cracked files and packages found in different warez sites come along with different malwares.
Hope this helps :)
Genuine thanks. I really was not expecting to get a helpful answer and you have rocked me on my heels. A most exhilarating experience.
Just one point though - I thought that nearly all exe and dll files are packed nowadays to keep then as compact as possible. Many packing programs are in existence - surely they are not all just used by hackers/crackers?
AChen
10-31-2007, 12:30 AM
Genuine thanks. I really was not expecting to get a helpful answer and you have rocked me on my heels. A most exhilarating experience.
Just one point though - I thought that nearly all exe and dll files are packed nowadays to keep then as compact as possible. Many packing programs are in existence - surely they are not all just used by hackers/crackers?
This is also correct, not all packing programs that exist today are being used by hackers/crackers. However, we detect packers that are prevalent to malwares such as Upack.
Powered by vBulletin™ Version 4.1.0 Copyright © 2012 vBulletin Solutions, Inc. All rights reserved.