Jump to content


Photo

Rising pc doctor

ip blocks

  • Please log in to reply
10 replies to this topic

#1 BlairWitch

BlairWitch

    banned

  • Banned
  • PipPipPipPip
  • 257 posts
  • Gender:Male
  • Location:Atlantis

Posted 10 June 2012 - 02:34 AM

Hello. I installed the Rising pc doctor today
http://www.rising-global.com/products/rising-pc-doctor.html
Since then malwarebytes have popped up some boxes about blocked ip addressess, like these: IP-BLOCK 204.188.205.14 (Type: outgoing) IP-BLOCK 222.76.95.78 (Type: outgoing)

So i scanned the rising pc doctor installer with virustotal it was detected by clamav as W32.Trojan.Genome-14 https://www.virustot...sis/1339313054/

My question really is that is it safe to use this program? Many say that it's a good program.

#2 BlairWitch

BlairWitch

    banned

  • Banned
  • PipPipPipPip
  • 257 posts
  • Gender:Male
  • Location:Atlantis

Posted 10 June 2012 - 02:38 AM

218.10.190.10 (Type: incoming)
Server Location:

Harbin, Heilongjiang in China

#3 BlairWitch

BlairWitch

    banned

  • Banned
  • PipPipPipPip
  • 257 posts
  • Gender:Male
  • Location:Atlantis

Posted 10 June 2012 - 04:40 AM

Now there is more development in this case. Malwarebytes detected the rising pc doctor updater as downloader trojan:
DETECTION C:\Program Files\Rising\RSD\Backup\RSD\RSSetup\updater.exe Trojan.Downloader QUARANTINE

This detection happened twice when the program was installed and also after i uninstalled the program and rebooted the computer.

#4 BornSlippy

BornSlippy

    Iconoclast

  • Malware Hunters
  • PipPipPipPipPipPip
  • 1,822 posts
  • Gender:Male
  • Location:London & Lincoln

Posted 10 June 2012 - 10:57 AM

The detections are False Positives. The software is safe.
Posted Image

#5 BlairWitch

BlairWitch

    banned

  • Banned
  • PipPipPipPip
  • 257 posts
  • Gender:Male
  • Location:Atlantis

Posted 10 June 2012 - 11:07 AM

View PostBornSlippy, on 10 June 2012 - 10:57 AM, said:

The detections are False Positives. The software is safe.

That's good to know. I dumped the memory of the rising pc doctor driver protreg.sys and then uploaded it to virustotal and antivir detected it as rootkit.gen https://www.virustot...sis/1339343777/

I am so paranoid. Maybe i should quit using computer.

#6 Ibrad

Ibrad

    True Member

  • Honorary Members
  • PipPipPipPip
  • 351 posts

Posted 17 June 2012 - 10:33 PM

I use this software, its safe I don't know why the IP range is blocked. Nothing seems suspious on my machine since installing it. Its Anti-Trojan is cloud based so that is why you see it. It has no real time protection but has cloud task manager, and cloud software updater. I reported to MBAM FP to Rising so we shall see if MBAM fixes it.
My Security Setup: Panda Cloud Antivirus, ClearCloud DNS, Malwarebytes FREE, CounterSpy

#7 miekiemoes

miekiemoes

    Forum Deity

  • Administrators
  • PipPipPipPipPipPip
  • 7,360 posts
  • Gender:Female
  • Location:Belgium

Posted 18 June 2012 - 03:52 AM

Hi,

I can't reproduce this detection. Just installed Rising PC Doctor and no detection here though. Can you verify this if mbam still detects? If so, please attach (zipped) the files to this thread that mbam detects.

Thanks.
Mieke Verburgh
Director of Research

Posted Image

Follow us: Twitter, Become a fan: Facebook

#8 DarkSnakeKobra

DarkSnakeKobra

    May the penguin be with you!

  • Honorary Members
  • PipPipPipPipPipPip
  • 5,180 posts
  • Gender:Male
  • Location:~
  • Interests:Security, scripting, GNU/Linux, photography

Posted 18 June 2012 - 04:54 PM

View PostBlairWitch, on 10 June 2012 - 02:34 AM, said:

Hello. I installed the Rising pc doctor today
http://www.rising-global.com/products/rising-pc-doctor.html
Since then malwarebytes have popped up some boxes about blocked ip addressess, like these: IP-BLOCK 204.188.205.14 (Type: outgoing) IP-BLOCK 222.76.95.78 (Type: outgoing)

So i scanned the rising pc doctor installer with virustotal it was detected by clamav as W32.Trojan.Genome-14 https://www.virustot...sis/1339313054/

My question really is that is it safe to use this program? Many say that it's a good program.

ClamAV is known for it's fp's on Windows files as it's a UNIX antivirus scanner. Detection rate isn't the best out there and certainly others have much better detection.

Computer Specs given when asked.
Bleeping Computer Malware Study Hall Junior


Advice: Hug your dog, cat etc everyday! :)


#9 noknojon

noknojon

    you know why ---

  • Honorary Members
  • PipPipPipPipPipPip
  • 6,008 posts
  • Gender:Male

Posted 18 June 2012 - 07:58 PM

Quote

I installed the Rising pc doctor
There are many better A/virus programs, unless you are stuck in China and have limited internet.
As BornSlippery said "It is safe" but it is not regarded as a "Good" A/virus program in general -
If you run anything except a Linux system, I would choose one of the better known brands available -
Just another private helper .......................... The answer is always 42, or Reboot
If you are waiting for an answer Press F5 ................. you may have one waiting for you ........

#10 BlairWitch

BlairWitch

    banned

  • Banned
  • PipPipPipPip
  • 257 posts
  • Gender:Male
  • Location:Atlantis

Posted 13 July 2012 - 04:16 AM

View Postmiekiemoes, on 18 June 2012 - 03:52 AM, said:

Hi,

I can't reproduce this detection. Just installed Rising PC Doctor and no detection here though. Can you verify this if mbam still detects? If so, please attach (zipped) the files to this thread that mbam detects.

Thanks.

Hello i just installed Rising pc doctor again and the file that was detected did not come with rising pc doctor installer that i downloaded yesterday. The one file that is in the quarantine is still detected by malwarebytes it was originally in the folder C:\Program Files\Rising\RSD\Backup\RSD\RSSetup which does not exist in this new installation.
Here is the detected file Attached File  updater.zip   268.22KB   1 downloads

https://www.virustot...sis/1342170882/

Let me know if that file contains anything malicious. Thanks.

#11 miekiemoes

miekiemoes

    Forum Deity

  • Administrators
  • PipPipPipPipPipPip
  • 7,360 posts
  • Gender:Female
  • Location:Belgium

Posted 13 July 2012 - 05:02 AM

Hi,

Thanks, I can reproduce detection on this and it's indeed a false positive here. This will be fixed in next update.
Mieke Verburgh
Director of Research

Posted Image

Follow us: Twitter, Become a fan: Facebook





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users