Heads up warning
There has been a FP in the regnow downloader for MBAM & most probably all regnow sold products via affiliate links
I have been in touch with the AV companies to get it fixed & expect a speedy resolution, but watch out for a few complaints for the next couple of hours
It isn't the actual MBAM file but in the system that regnow use where they download a download manager first and it is the download manager that is the problem
---[ www.virustotal.com ]---------------------------
File Download_mbam-setup.exe received on 03.14.2008 09:15:31 (CET)
Antivirus Version Last Update Result
AhnLab-V3 2008.3.14.0 2008.03.14 no virus found
AntiVir 7.6.0.73 2008.03.13 no virus found
Authentium 4.93.8 2008.03.13 no virus found
Avast 4.7.1098.0 2008.03.13 no virus found
AVG 7.5.0.516 2008.03.13 no virus found
BitDefender 7.2 2008.03.14 no virus found
CAT-QuickHeal 9.50 2008.03.13 Downloader.Keylogger.a (Not a Virus)
ClamAV 0.92.1 2008.03.14 no virus found
DrWeb 4.44.0.09170 2008.03.14 no virus found
eSafe 7.0.15.0 2008.03.09 no virus found
eTrust-Vet 31.3.5614 2008.03.14 no virus found
Ewido 4.0 2008.03.13 no virus found
FileAdvisor 1 2008.03.14 no virus found
Fortinet 3.14.0.0 2008.03.14 Download/Keylogger
F-Prot 4.4.2.54 2008.03.13 no virus found
F-Secure 6.70.13260.0 2008.03.14 no virus found
Ikarus T3.1.1.20 2008.03.14 no virus found
Kaspersky 7.0.0.125 2008.03.14 not-a-virus:Downloader.Win32.Keylogger.a
McAfee 5251 2008.03.13 no virus found
Microsoft 1.3301 2008.03.13 no virus found
NOD32v2 2946 2008.03.14 no virus found
Norman 5.80.02 2008.03.13 no virus found
Panda 9.0.0.4 2008.03.13 no virus found
Prevx1 V2 2008.03.14 no virus found
Rising 20.35.40.00 2008.03.14 no virus found
Sophos 4.27.0 2008.03.14 no virus found
Sunbelt 3.0.963.0 2008.03.14 no virus found
Symantec 10 2008.03.14 no virus found
TheHacker 6.2.92.245 2008.03.14 no virus found
VBA32 3.12.6.2 2008.03.13 Downloader.Win32.Keylogger.a
VirusBuster 4.3.26:9 2008.03.13 no virus found
Webwasher-Gateway 6.6.2 2008.03.13 no virus found
Additional information
File size: 128368 bytes
MD5: 4971a5730dc3fb83d66935578f0cd388
SHA1: 69c1143c716a2261dbb6fe5411d6f1b03ae61fee
PEiD: Armadillo v1.71
#1
Posted 14 March 2008 - 09:06 AM
Derek Microsoft MVP/Windows - Security Thespykiller | Security & Privacy
I am helping you, please help me by donating to help keep the Hedgehog Rescue Centre running
I am helping you, please help me by donating to help keep the Hedgehog Rescue Centre running
#2
Posted 14 March 2008 - 12:31 PM
Derek, I will have to either contact each of these vendors, or RegNow to stop using silly packers.
#3
Posted 14 March 2008 - 03:50 PM
I have just heard back from KAV and after a bit of a s=discussion with one analyst I have bypassed & gone to a higher level who is getting it fixed
Derek Microsoft MVP/Windows - Security Thespykiller | Security & Privacy
I am helping you, please help me by donating to help keep the Hedgehog Rescue Centre running
I am helping you, please help me by donating to help keep the Hedgehog Rescue Centre running
#4
Posted 14 March 2008 - 04:50 PM
Good to hear .. unfortunately I believe it is unacceptable that RegNow is using these types of packers. I will have a talk with them tonight.
#5
Posted 14 March 2008 - 06:10 PM
it isn't the packer they are detecting or worried about this time but th actual downloader
Regnow don't put an actual download on the site BUT when you follow an affiliate link you get a small downloader which acts as a download manager and the downloader downloads the actual file
I can see why they do it as it makes it easier for them to track and for the developer to upload new versions more easily
The downloader contains the affiliate code which on contacting the main file injects the affiliate code into the actual program that is downloaded
I can see why the antivirus companies consider it a risk as it would not be difficult to alter the downloader to inject malicious code
Regnow don't put an actual download on the site BUT when you follow an affiliate link you get a small downloader which acts as a download manager and the downloader downloads the actual file
I can see why they do it as it makes it easier for them to track and for the developer to upload new versions more easily
The downloader contains the affiliate code which on contacting the main file injects the affiliate code into the actual program that is downloaded
I can see why the antivirus companies consider it a risk as it would not be difficult to alter the downloader to inject malicious code
Derek Microsoft MVP/Windows - Security Thespykiller | Security & Privacy
I am helping you, please help me by donating to help keep the Hedgehog Rescue Centre running
I am helping you, please help me by donating to help keep the Hedgehog Rescue Centre running
#6
Posted 14 March 2008 - 07:56 PM
Any ideas to get the file whitelisted?
#7
Posted 14 March 2008 - 08:51 PM
fixed in Kaspersky now
I haven't heard from the others who did detect it but as they all seem to follow or use KAV detections in some way they should hopefully soon fix it
I haven't heard from the others who did detect it but as they all seem to follow or use KAV detections in some way they should hopefully soon fix it
Derek Microsoft MVP/Windows - Security Thespykiller | Security & Privacy
I am helping you, please help me by donating to help keep the Hedgehog Rescue Centre running
I am helping you, please help me by donating to help keep the Hedgehog Rescue Centre running
#8
Posted 14 March 2008 - 08:54 PM
#9
Posted 05 April 2008 - 09:42 AM
dvk01, on Mar 14 2008, 11:51 PM, said:
fixed in Kaspersky now
I haven't heard from the others who did detect it but as they all seem to follow or use KAV detections in some way they should hopefully soon fix it
I haven't heard from the others who did detect it but as they all seem to follow or use KAV detections in some way they should hopefully soon fix it
This time it's NOT a keylogger detection from Kaspersky, but a Winfixer
http://www.virustotal.com/analisis/1a94c96...3a72756fe3fb6c1
I'm sure you can appreciate my surprise when, while doing some maintenance on my brother's laptop, I decided to check it with MBAM. Lo and behold, KAV jumps into action when I downloaded via MajorGeeks - 'Authors site' link.
#10
Posted 05 April 2008 - 03:34 PM
Grr .. anybody have any ideas on how to whitelist this?
#11
Posted 10 April 2008 - 02:05 PM
I have emailed Kaspersky again today as it is still detecting it
detected: riskware not-a-virus:Downloader.Win32.WinFixer.fs File: C:\Documents and Settings\Derek Knight\Desktop\mbam\Download_mbam-setup.exe
If no response I will speak direct to someone high up who has the power to deal with
the problem seems to be with regnow using a stupid download system & not downloading the file itself but the detection is for the regnow downloader for the download
detected: riskware not-a-virus:Downloader.Win32.WinFixer.fs File: C:\Documents and Settings\Derek Knight\Desktop\mbam\Download_mbam-setup.exe
If no response I will speak direct to someone high up who has the power to deal with
the problem seems to be with regnow using a stupid download system & not downloading the file itself but the detection is for the regnow downloader for the download
Derek Microsoft MVP/Windows - Security Thespykiller | Security & Privacy
I am helping you, please help me by donating to help keep the Hedgehog Rescue Centre running
I am helping you, please help me by donating to help keep the Hedgehog Rescue Centre running
#12
Posted 10 April 2008 - 04:47 PM
I am in talks with Regnow as of yesterday to help solve this issue.
#13
Posted 13 April 2008 - 05:01 PM
I had one yesterday where Zone Alarm id'd MBAM as Winfixer too.
#14
Posted 15 April 2008 - 08:41 PM
#15
Posted 16 April 2008 - 10:08 PM
This is becoming RIDICULOUS. I am personally contacting each of these companies right now. Let's see who is worthy enough to call themselves an Anti-Virus.
CAT-QuickHeal 9.50 2008.04.16 Downloader.Keylogger.a (Not a Virus)
DrWeb 4.44.0.09170 2008.04.16 Adware.Winfixer
Kaspersky 7.0.0.125 2008.04.16 not-a-virus:Downloader.Win32.WinFixer.fs
Norman 5.80.02 2008.04.16 W32/DLoader.GBVM
TheHacker 6.2.92.280 2008.04.16 Aplicacion/Keylogger.a
VirusBuster 4.3.26:9 2008.04.16 Adware.WinFixer.AH
Wish me luck.
CAT-QuickHeal 9.50 2008.04.16 Downloader.Keylogger.a (Not a Virus)
DrWeb 4.44.0.09170 2008.04.16 Adware.Winfixer
Kaspersky 7.0.0.125 2008.04.16 not-a-virus:Downloader.Win32.WinFixer.fs
Norman 5.80.02 2008.04.16 W32/DLoader.GBVM
TheHacker 6.2.92.280 2008.04.16 Aplicacion/Keylogger.a
VirusBuster 4.3.26:9 2008.04.16 Adware.WinFixer.AH
Wish me luck.
#16
Posted 16 April 2008 - 10:19 PM
All companies have been contacted. The e-mail to Kaspersky bounced back as undeliverable, great!
. Now I contact RegNow and yell at them.
#17
Posted 16 April 2008 - 11:11 PM
I will sort Kaspersky tomorrow morning UK time
Derek Microsoft MVP/Windows - Security Thespykiller | Security & Privacy
I am helping you, please help me by donating to help keep the Hedgehog Rescue Centre running
I am helping you, please help me by donating to help keep the Hedgehog Rescue Centre running
#18
Posted 17 April 2008 - 06:10 PM
RubbeR DuckY, on Apr 16 2008, 10:19 PM, said:
All companies have been contacted. The e-mail to Kaspersky bounced back as undeliverable, great!
. Now I contact RegNow and yell at them.
Hi Marcin,
I tried to send e-mail to Kaspersky Techincal Support with no response , Ithink the only way to get in touch with them consists in subscribing to their forum.
#19
Posted 18 April 2008 - 05:47 PM
leofelix, on Apr 17 2008, 08:10 PM, said:
Ithink the only way to get in touch with them consists in subscribing to their forum.
#20
Posted 18 April 2008 - 05:51 PM
I am speaking to Kaspersky about it but my contact is away at the moment but he will deal when he comes back
he fixed it last time but another submission must have been done & a more junior one must have not seen it properly
I will see if he can do a permanent whitelisting for it
he fixed it last time but another submission must have been done & a more junior one must have not seen it properly
I will see if he can do a permanent whitelisting for it
Derek Microsoft MVP/Windows - Security Thespykiller | Security & Privacy
I am helping you, please help me by donating to help keep the Hedgehog Rescue Centre running
I am helping you, please help me by donating to help keep the Hedgehog Rescue Centre running
1 user(s) are reading this topic
0 members, 1 guests, 0 anonymous users
Sign In
Create Account
This topic is locked

Back to top










