Jump to content

Malwarebytes

false positive Backdoor.Bot.HPWGen

Backdoor.Bot.HPWGen

9 replies to this topic

#1
daftcrack31

    New Member

  • Members
  • Pip
  • 6 posts
hello

scuse me for my english but i'm french ^^


i scanned my pc on the afternoon and i see 14 false positive in the report
in fact , the false positive are my projects in visual basic express 2010

the false positive :

C:\Users\daftcrack31\Desktop\visual basic\VB web radio\VB web radio.exe (Backdoor.Bot.HPWGen) -> Aucune action effectuée.
C:\Users\daftcrack31\Documents\Visual Studio 2010\Projects\true web radio\true web radio\obj\x86\Release\VB web radio.exe (Backdoor.Bot.HPWGen) -> Aucune action effectuée.

and there are the same 14 false positive


cordially


ps : if you have questions , please speak in a very easy english. thanks you

#2
daftcrack31

    New Member

  • Members
  • Pip
  • 6 posts
scan virus total : https://www.virustot...sis/1345313759/

#3
shadowwar

    Forum Deity

  • Moderators
  • PipPipPipPipPipPip
  • 2,680 posts
can u please attach one of the files detected? thanks. you will have to zip it to attach.
Rich Matteo
Research Engineer

Posted Image

Follow us: Twitter, Become a fan: Facebook

#4
daftcrack31

    New Member

  • Members
  • Pip
  • 6 posts
Hello


This application is my web radio in visual basic language.

For open this application ( not the zip) , you must write the password.

The button " obtenir illégalement le pass" is a funny URL ^^


Attached File  tool detected.zip   499.51K   2 downloadsAttached File  tool detected.zip   499.51K   2 downloadsIf you have other questions , please speak in easy english



Thanks ;)

#5
shadowwar

    Forum Deity

  • Moderators
  • PipPipPipPipPipPip
  • 2,680 posts
The reason this is being detected is because of the huerisitics of company name being Hewlett packard with generic version info. Do you work for hewlett packard?

Is there a reason you put company name as hewlett packard and not properly filled out the version info of the file?
Rich Matteo
Research Engineer

Posted Image

Follow us: Twitter, Become a fan: Facebook

#6
daftcrack31

    New Member

  • Members
  • Pip
  • 6 posts
scuse me but i don't understand ( i'm french)

i can say : i have HP computer and it's my projects ( visual basic) who are detected

#7
malwarepanda

    New Member

  • Members
  • Pip
  • 9 posts
  • Gender:Male
thank you man

#8
daftcrack31

    New Member

  • Members
  • Pip
  • 6 posts
Hello,

I don't speak english enough, so a friend helped me to translate your answer.

The detection was due to a parameter of Visual Studio : "Compagny : Hewlett Packard" . Thus it was really a false positive.

Then I modified the "compagny" parameter, and there's no longer detection.

Thanks for your quick answer ! ;)

#9
shadowwar

    Forum Deity

  • Moderators
  • PipPipPipPipPipPip
  • 2,680 posts
Glad you understood! Siri will be present tomorrow and he speaks french if there are further questions.
Rich Matteo
Research Engineer

Posted Image

Follow us: Twitter, Become a fan: Facebook

#10
daftcrack31

    New Member

  • Members
  • Pip
  • 6 posts
thanks ;)





1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users

Follow Us