Jump to content

Malwarebytes

Rising pc doctor

ip blocks

10 replies to this topic

#1
BlairWitch

    banned

  • Banned
  • PipPipPipPip
  • 257 posts
  • Gender:Male
  • Location:Atlantis
Hello. I installed the Rising pc doctor today
http://www.rising-global.com/products/rising-pc-doctor.html
Since then malwarebytes have popped up some boxes about blocked ip addressess, like these: IP-BLOCK 204.188.205.14 (Type: outgoing) IP-BLOCK 222.76.95.78 (Type: outgoing)

So i scanned the rising pc doctor installer with virustotal it was detected by clamav as W32.Trojan.Genome-14 https://www.virustot...sis/1339313054/

My question really is that is it safe to use this program? Many say that it's a good program.

#2
BlairWitch

    banned

  • Banned
  • PipPipPipPip
  • 257 posts
  • Gender:Male
  • Location:Atlantis
218.10.190.10 (Type: incoming)
Server Location:

Harbin, Heilongjiang in China

#3
BlairWitch

    banned

  • Banned
  • PipPipPipPip
  • 257 posts
  • Gender:Male
  • Location:Atlantis
Now there is more development in this case. Malwarebytes detected the rising pc doctor updater as downloader trojan:
DETECTION C:\Program Files\Rising\RSD\Backup\RSD\RSSetup\updater.exe Trojan.Downloader QUARANTINE

This detection happened twice when the program was installed and also after i uninstalled the program and rebooted the computer.

#4
BornSlippy

    Iconoclast

  • Malware Hunters
  • PipPipPipPipPipPip
  • 1,762 posts
  • Gender:Male
  • Location:London & Lincoln
The detections are False Positives. The software is safe.
Posted Image

#5
BlairWitch

    banned

  • Banned
  • PipPipPipPip
  • 257 posts
  • Gender:Male
  • Location:Atlantis

View PostBornSlippy, on 10 June 2012 - 10:57 AM, said:

The detections are False Positives. The software is safe.

That's good to know. I dumped the memory of the rising pc doctor driver protreg.sys and then uploaded it to virustotal and antivir detected it as rootkit.gen https://www.virustot...sis/1339343777/

I am so paranoid. Maybe i should quit using computer.

#6
Ibrad

    True Member

  • Honorary Members
  • PipPipPipPip
  • 351 posts
I use this software, its safe I don't know why the IP range is blocked. Nothing seems suspious on my machine since installing it. Its Anti-Trojan is cloud based so that is why you see it. It has no real time protection but has cloud task manager, and cloud software updater. I reported to MBAM FP to Rising so we shall see if MBAM fixes it.
My Security Setup: Panda Cloud Antivirus, ClearCloud DNS, Malwarebytes FREE, CounterSpy

#7
miekiemoes

    Forum Deity

  • Administrators
  • PipPipPipPipPipPip
  • 7,350 posts
  • Gender:Female
  • Location:Belgium
Hi,

I can't reproduce this detection. Just installed Rising PC Doctor and no detection here though. Can you verify this if mbam still detects? If so, please attach (zipped) the files to this thread that mbam detects.

Thanks.
Mieke Verburgh
Director of Research

Posted Image

Follow us: Twitter, Become a fan: Facebook

#8
DarkSnakeKobra

    Love thyself and thy penguin

  • Honorary Members
  • PipPipPipPipPipPip
  • 5,127 posts
  • Gender:Male
  • Location:USA
  • Interests:Security, scripting, Linux, fishing, camping

View PostBlairWitch, on 10 June 2012 - 02:34 AM, said:

Hello. I installed the Rising pc doctor today
http://www.rising-global.com/products/rising-pc-doctor.html
Since then malwarebytes have popped up some boxes about blocked ip addressess, like these: IP-BLOCK 204.188.205.14 (Type: outgoing) IP-BLOCK 222.76.95.78 (Type: outgoing)

So i scanned the rising pc doctor installer with virustotal it was detected by clamav as W32.Trojan.Genome-14 https://www.virustot...sis/1339313054/

My question really is that is it safe to use this program? Many say that it's a good program.

ClamAV is known for it's fp's on Windows files as it's a UNIX antivirus scanner. Detection rate isn't the best out there and certainly others have much better detection.

Computer Specs given when asked.
Bleeping Computer Malware Study Hall Junior


#9
noknojon

    you know why ---

  • Honorary Members
  • PipPipPipPipPipPip
  • 5,998 posts
  • Gender:Male

Quote

I installed the Rising pc doctor
There are many better A/virus programs, unless you are stuck in China and have limited internet.
As BornSlippery said "It is safe" but it is not regarded as a "Good" A/virus program in general -
If you run anything except a Linux system, I would choose one of the better known brands available -
Just another private helper .......................... The answer is always 42, or Reboot
If you are waiting for an answer Press F5 ................. you may have one waiting for you ........

#10
BlairWitch

    banned

  • Banned
  • PipPipPipPip
  • 257 posts
  • Gender:Male
  • Location:Atlantis

View Postmiekiemoes, on 18 June 2012 - 03:52 AM, said:

Hi,

I can't reproduce this detection. Just installed Rising PC Doctor and no detection here though. Can you verify this if mbam still detects? If so, please attach (zipped) the files to this thread that mbam detects.

Thanks.

Hello i just installed Rising pc doctor again and the file that was detected did not come with rising pc doctor installer that i downloaded yesterday. The one file that is in the quarantine is still detected by malwarebytes it was originally in the folder C:\Program Files\Rising\RSD\Backup\RSD\RSSetup which does not exist in this new installation.
Here is the detected file Attached File  updater.zip   268.22K   1 downloads

https://www.virustot...sis/1342170882/

Let me know if that file contains anything malicious. Thanks.

#11
miekiemoes

    Forum Deity

  • Administrators
  • PipPipPipPipPipPip
  • 7,350 posts
  • Gender:Female
  • Location:Belgium
Hi,

Thanks, I can reproduce detection on this and it's indeed a false positive here. This will be fixed in next update.
Mieke Verburgh
Director of Research

Posted Image

Follow us: Twitter, Become a fan: Facebook





1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users

Follow Us