Wilders Security Forums  

Go Back   Wilders Security Forums > Security Software > other anti-virus software
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old December 6th, 2005, 08:27 AM
rdsu's Avatar
rdsu rdsu is offline
Massive Poster
 
Join Date: Jun 2003
Location: pt
Posts: 4,045
Default RemoveIT Pro

Hi,

did someone tried this free malware removal program?
http://www.incodesolutions.com/removeit.htm

Quote:
Remove many viruses that other popular antivirus software cannot discover like file
mouse.exe etc...
If you can't clean your computer from worms & viruses, addwares & spywares
try with this software.

I run it and it found 3 virus, but I think they are fp...
http://img232.imageshack.us/img232/7...results6qi.png

I also run NOD32, ewido, CounterSpy and Spybot-S&D and they found nothing...
  #2  
Old December 6th, 2005, 08:57 AM
kjempen kjempen is offline
Frequent Poster
 
Join Date: May 2004
Posts: 360
Default Re: RemoveIT Pro

It doesn't show which files it claims to be infected?

Never tried this program before, but I'm interested in trying it.

EDIT: By looking at their web site, it seems a bit this tool identifies "threats" based on the filename and location of a file? Doesn't seem like a very trustworthy tool to me. Someone correct me if I'm wrong.
  #3  
Old December 6th, 2005, 09:02 AM
ErikAlbert ErikAlbert is offline
Incredibly Massive Poster
 
Join Date: Jun 2005
Posts: 9,456
Default Re: RemoveIT Pro

This is from their website :
Quote:
Q - How can i clean worms like conime.exe and wupdmgr.exe?
A - Restart computer in safe mode then manually delete this files conime.exe
and wupdmgr.exe from this directories

You do a scan and you find BOTH files on your computer. Weird coincidence LOL.
I don't trust this one.
__________________
ErikAlbert
Security = WinXPproSP3 Firewall + Anti-Executable + DefenseWall HIPS * Recovery = ShadowProtect + FirstDefense-ISR
Malware Survival Rate = 0.00%, but each malware has my sympathy.
  #4  
Old December 6th, 2005, 09:08 AM
Texcritter Texcritter is offline
Very Frequent Poster
 
Join Date: May 2005
Location: Teesside, North East England
Posts: 1,985
Default Re: RemoveIT Pro

Hi Vamp

Tried it and got exactly the same 3 warnings as you did, seems a bit fishy to me
__________________
Tex
  #5  
Old December 6th, 2005, 09:12 AM
kjempen kjempen is offline
Frequent Poster
 
Join Date: May 2004
Posts: 360
Default Re: RemoveIT Pro

Quoted from their web site:

"Q - How can i clean worms like conime.exe and wupdmgr.exe?


A - Restart computer in safe mode then manually delete this files conime.exe
and wupdmgr.exe from this directories
c:\Windows\System32\dllcache
c:\Windows\System32"

I tried the scanner, and it told me I had these infections: "Sys32.conime" and "Sys32.wupdmgr". I went and looked in the folders as described in the answer given above, tried scanning them at jotti's and VirusTotal - the files came out clean. So I'm guessing that these are false positives.
  #6  
Old December 6th, 2005, 09:15 AM
ErikAlbert ErikAlbert is offline
Incredibly Massive Poster
 
Join Date: Jun 2005
Posts: 9,456
Default Re: RemoveIT Pro

Quote:
Q - How can i end some active process and delete they source file?
Is that English ? they = their IMHO.

Their website hasn't even a professional look. Amateurs !!!
__________________
ErikAlbert
Security = WinXPproSP3 Firewall + Anti-Executable + DefenseWall HIPS * Recovery = ShadowProtect + FirstDefense-ISR
Malware Survival Rate = 0.00%, but each malware has my sympathy.
  #7  
Old December 6th, 2005, 09:26 AM
Happy Bytes
 
Posts: n/a
Default Re: RemoveIT Pro

  #8  
Old December 6th, 2005, 09:32 AM
auriell auriell is offline
Regular Poster
 
Join Date: Feb 2005
Location: Warsaw, Poland
Posts: 105
Default Re: RemoveIT Pro

wupdmgr.exe - windows update manager

conime.exe - (Console IME) is an executable from the software Microsoft® Windows® Operating System version 5.2.0 by Microsoft Corporation

But if you google for the files, firts result you will see the files are trojans (but they surely not). Maybe some trojans can replace the files with themselves.

This program and the site look like one big crap.
  #9  
Old December 6th, 2005, 09:35 AM
Happy Bytes
 
Posts: n/a
Default Re: RemoveIT Pro

Quote:
Our team was formed in the year 1999, and till now we have developed highly integrated system software
for The Windows Platform.


Ridiculous! This crap is almost more dangerous than any of the malware i've seen in the past 3 weeks (if the user really does what it suggests)
  #10  
Old December 6th, 2005, 09:44 AM
rdsu's Avatar
rdsu rdsu is offline
Massive Poster
 
Join Date: Jun 2003
Location: pt
Posts: 4,045
Default Re: RemoveIT Pro

Seems a rogue program...

I like to test programs and this is one I will never try it again...
  #11  
Old December 6th, 2005, 09:52 AM
Happy Bytes
 
Posts: n/a
Default Re: RemoveIT Pro

Once Again:

There's NO valid AV Vendor who's in the business and nobody heard something about him - nor they claim to find things which "normal" AV programs couldn't detect.

It's by far MORE DANGEROUS to install such unknown "Security Applications" just for the sake that they are called "Antivirus", "Firewall", "Antispyware" or whatsoever than ignoring such crap!
  #12  
Old December 6th, 2005, 09:53 AM
auriell auriell is offline
Regular Poster
 
Join Date: Feb 2005
Location: Warsaw, Poland
Posts: 105
Default Re: RemoveIT Pro

If you want to avoid such situations in the future look at this list of crap or at least suspicious apps:

http://www.searchengines.pl/phpbb203...7&#entry196097
  #13  
Old December 6th, 2005, 09:59 AM
ErikAlbert ErikAlbert is offline
Incredibly Massive Poster
 
Join Date: Jun 2005
Posts: 9,456
Default Re: RemoveIT Pro

Quote:
Originally Posted by VaMPiRiC_CRoW
Seems a rogue program...
It's the first time, I see a free rogue software, usually they ask money for it.
I learn something new every day.
__________________
ErikAlbert
Security = WinXPproSP3 Firewall + Anti-Executable + DefenseWall HIPS * Recovery = ShadowProtect + FirstDefense-ISR
Malware Survival Rate = 0.00%, but each malware has my sympathy.
  #14  
Old December 9th, 2005, 08:48 AM
ri008
 
Posts: n/a
Default Re: RemoveIT Pro

Some information for conime.exe

Conime.exe is a process which is registered as the BFGhost 1.0.
Remote administration backdoor tool.
This backdoor application can allow attackers to access your computer,
stealing passwords and personal data.
It is a registered security risk and should be removed immediately.
  #15  
Old December 9th, 2005, 09:54 AM
Happy Bytes
 
Posts: n/a
Default Re: RemoveIT Pro

Quote:
Originally Posted by ri008
Some information for conime.exe

Conime.exe is a process which is registered as the BFGhost 1.0.
Remote administration backdoor tool.
This backdoor application can allow attackers to access your computer,
stealing passwords and personal data.
It is a registered security risk and should be removed immediately.

You cannot make conclusion if something is malware or not based on a filename! Even if a trojan uses some "common" names, doesn't mean that there are not other valid programs which could use the same name!

Rename Notepad.exe into Conime.exe and add a registry autostart entry for it, because you would like to have Notepad opened during every system start.
Does it automatically become malware because of this?!
 

Wilders Security Forums > Security Software > other anti-virus software « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -5. The time now is 01:59 PM.


Powered by vBulletin® Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2010, Wilders Security Forums