View Full Version : FP - again, please fix
Medank
October 19th, 2008, 12:05 PM
http://en.wikipedia.org/wiki/MP3_Rocket
and the download link is: hxxp://baixaki.ig.com.br/download/mp3-rocket.htm
~Virus Total screenshot removed per Policy. - Ron (http://www.wilderssecurity.com/showthread.php?t=180057)~
jmc777
October 19th, 2008, 12:33 PM
It's been flagged as a 'potentially unsafe application'.
-{ Quote: "
Potentially unsafe applications
There are many legitimate programs which serve to simplify the administration of networked computers. However, in the wrong hands, they may be misused for malicious purposes. This is why ESET has created this special category. Our clients now have the option to choose whether the antivirus system should or should not detect such threats.
"Potentially unsafe applications” is the classification used for commercial, legitimate software. This classification includes programs such as remote access tools, password-cracking applications, and keyloggers (a program recording each keystroke a user types).
If you find that there is a potentially unsafe application present and running on your computer (and you did not install it), please consult your network administrator or remove the application.
" }-
Medank
October 19th, 2008, 01:58 PM
what is all this :D wow
the file is safe it's not a virus or anything . eset detected as FP when will this file be removed ?
jmc777
October 19th, 2008, 02:05 PM
-{ Quote: "what is all this :D wow
the file is safe it's not a virus or anything ." }-
It's not being flagged as a virus. If you don't want warnings about that program, untick 'Potentially unsafe applications' in your Threatsense settings.
proactivelover
October 19th, 2008, 03:43 PM
scan only MP3Rocket.exe then see result on virustotal
Medank
October 19th, 2008, 03:59 PM
-{ Quote: "scan only MP3Rocket.exe then see result on virustotal" }-
i did, i scaned again and it flagged as: a variant of Win32/AdInstaller application
Marcos
October 19th, 2008, 04:53 PM
I've downloaded it and the result was as follows:
File MP3Rocket.exe received on 10.18.2008 16:22:43 (CET)
Current status: finished
Result: 1/36 (2.78%)
NOD32 3534 2008.10.18 -
Additional information
File size: 116224 bytes
MD5...: 9fc505e6ad29c4909ab35cfadfd9e9c4
SHA1..: 152849e3534f103e9ff623fbe8cec7fb7ff70c27
SHA256: 6d3f91ca0b2d751f45019be57d1a4fc1ca446a5dc6c612f32e38dbf64fbc489a
SHA512: 3371fb170922b187be07a2e80d0044e0005e90499f1e67d1178bad42ffacec7f
bdff3567273d219d38acfe6d807c86d30b7be3921d65f9f8ce1febe97bdcbdf5
PEiD..: -
TrID..: File type identification
Win32 Executable Generic (38.4%)
Win32 Dynamic Link Library (generic) (34.1%)
Win16/32 Executable Delphi generic (9.3%)
Generic Win/DOS Executable (9.0%)
DOS Executable Generic (9.0%)
proactivelover
October 19th, 2008, 05:17 PM
file apbarSp.MP3Rocket.exe is ad installer so it's not a FP
i extract the installer with Universal Extractor v1.6
Medank
October 19th, 2008, 05:24 PM
-{ Quote: "I've downloaded it and the result was as follows:
File MP3Rocket.exe received on 10.18.2008 16:22:43 (CET)
Current status: finished
Result: 1/36 (2.78%)
NOD32 3534 2008.10.18 -
Additional information
File size: 116224 bytes
MD5...: 9fc505e6ad29c4909ab35cfadfd9e9c4
SHA1..: 152849e3534f103e9ff623fbe8cec7fb7ff70c27
SHA256: 6d3f91ca0b2d751f45019be57d1a4fc1ca446a5dc6c612f32e38dbf64fbc489a
SHA512: 3371fb170922b187be07a2e80d0044e0005e90499f1e67d1178bad42ffacec7f
bdff3567273d219d38acfe6d807c86d30b7be3921d65f9f8ce1febe97bdcbdf5
PEiD..: -
TrID..: File type identification
Win32 Executable Generic (38.4%)
Win32 Dynamic Link Library (generic) (34.1%)
Win16/32 Executable Delphi generic (9.3%)
Generic Win/DOS Executable (9.0%)
DOS Executable Generic (9.0%)" }-
I just downloaded mp3rocket from same website as i mention above and scanned and result:
-
File MP3Rocket-Win.exe recived on 10.19.2008 23:18:36
Current status: finished
Resultat: 2/36 (5.56%)
NOD32 3536 2008.10.19 - a variant of Win32/AdInstaller
Additional Information
File size: 3715432 bytes
MD5...: 687d2ba0528f6f95b808d3c084db2898
SHA1..: 580b174b6839beeb7e2a4404aef905f39db64a7e
SHA256: 2e691587d6419cae0def80179d0f95bf28cece4fb5ba6c2a726869e61e644ed5
SHA512: b4c87404867c0e746eed6181a1630eb447d40c386423e6a0b711c10030b55dd5
1db1a117e809330a9a6ac89f4ee82a1904bd13688a28703d280164c75df37fbd
PEiD..: -
TrID..: File type identification
Win64 Executable Generic (59.6%)
Win32 Executable MS Visual C++ (generic) (26.2%)
Win32 Executable Generic (5.9%)
Win32 Dynamic Link Library (generic) (5.2%)
Generic Win/DOS Executable (1.3%)
NOD32 user
October 19th, 2008, 05:33 PM
-{ Quote: "I just downloaded mp3rocket from same website as i mention above and scanned and result:
-
File MP3Rocket-Win.exe recived on 10.19.2008 23:18:36
Current status: finished
Resultat: 2/36 (5.56%)
NOD32 3536 2008.10.19 - a variant of Win32/AdInstaller
Additional Information
File size: 3715432 bytes
MD5...: 687d2ba0528f6f95b808d3c084db2898
SHA1..: 580b174b6839beeb7e2a4404aef905f39db64a7e
SHA256: 2e691587d6419cae0def80179d0f95bf28cece4fb5ba6c2a726869e61e644ed5
SHA512: b4c87404867c0e746eed6181a1630eb447d40c386423e6a0b711c10030b55dd5
1db1a117e809330a9a6ac89f4ee82a1904bd13688a28703d280164c75df37fbd
PEiD..: -
TrID..: File type identification
Win64 Executable Generic (59.6%)
Win32 Executable MS Visual C++ (generic) (26.2%)
Win32 Executable Generic (5.9%)
Win32 Dynamic Link Library (generic) (5.2%)
Generic Win/DOS Executable (1.3%)" }-That's what I got earlier - the file Marcos scanned was smaller?
-{ Quote: "file apbarSp.MP3Rocket.exe is ad installer so it's not a FP
i extract the installer with Universal Extractor v1.6" }-Saw that too:
C:\Documents and Settings\xxxxxx\Desktop\MP3Rocket-Win.exe » NSIS » apbarSp.MP3Rocket.exe - a variant of Win32/AdInstaller application - was a part of the deleted object
Cheers :)
djohn
October 19th, 2008, 06:59 PM
-{ Quote: "I've downloaded it and the result was as follows:
File MP3Rocket.exe received on 10.18.2008 16:22:43 (CET)
Current status: finished
Result: 1/36 (2.78%)
NOD32 3534 2008.10.18 -
Additional information
File size: 116224 bytes
MD5...: 9fc505e6ad29c4909ab35cfadfd9e9c4
SHA1..: 152849e3534f103e9ff623fbe8cec7fb7ff70c27
SHA256: 6d3f91ca0b2d751f45019be57d1a4fc1ca446a5dc6c612f32e38dbf64fbc489a
SHA512: 3371fb170922b187be07a2e80d0044e0005e90499f1e67d1178bad42ffacec7f
bdff3567273d219d38acfe6d807c86d30b7be3921d65f9f8ce1febe97bdcbdf5
PEiD..: -
TrID..: File type identification
Win32 Executable Generic (38.4%)
Win32 Dynamic Link Library (generic) (34.1%)
Win16/32 Executable Delphi generic (9.3%)
Generic Win/DOS Executable (9.0%)
DOS Executable Generic (9.0%)" }-
hey Marcos just curious is that 1/36 of VT and Not a FP.Disregard get my question answered and loving it.
LowWaterMark
October 19th, 2008, 07:27 PM
Marcos appears to have tested the actual MP3Rocket.exe application file, versus what other have tested - i.e. the installer kit named MP3Rocket-Win.exe. It looks like NOD32 is not detecting the MP3Rocket.exe program itself once installed. It's just detecting the installer kit which contains a lot more than just the MP3Rocket.exe file. If it is a bundle containing adware among the other contents, then the detection isn't a FP, which is what proactivelover said above.
djohn
October 19th, 2008, 07:42 PM
I guess it safe to say Nod was the first on the job.Time to signature watch.LOL
vBulletin® Copyright ©2000-2012, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2012, Wilders Security Forums