![]() |
|
#1
|
||||
|
||||
|
Here's a new one to me, RemoveIT Pro 2.1 SE
. . . Quote:
StevieO Last edited by snapdragin : March 31st, 2006 at 06:33 PM. Reason: Added appropriate Quote Tags |
|
#2
|
||||
|
||||
|
Only $15 or the free version.
It's also pretty new on the market, because the forum has no posts, no members at present. ![]()
__________________
Brabantse leeuw | Eendracht maakt macht Vista HP SP1 | KIS 2009 | Malware Defender | SUPERAntiSpyware Opera & Firefox | Barca Pro | Sandboxie | FirstDefense-ISR | ShadowProtect Rogue/Suspect Anti-Spyware Products & Web Sites |
|
#3
|
|||
|
|||
|
Quote:
__________________
http://www.av-comparatives.org AV-Comparatives WEBLOG / FORUM Not speaking here on behalf of AV-Comparatives. Post questions in our forum. |
|
#4
|
|||
|
|||
|
Sure, all have to try it - it deletes valid SYSTEM FILES!
|
|
#5
|
|||
|
|||
|
I pressed stop after the first false postive - there are a lot of more system files detected.
By the way this is a valid Microsoft XML Parser DLL. The guy who develops this bullshit application (It's nothing else) does not even know what is malware and what not and all people are happy that such "new antivirus" finding things which other AV's are missing. Go, make a donation for screwing up your system ![]() |
|
#6
|
|||
|
|||
|
RemoveIT Pro could be classified as Trojan Horse.
__________________
http://www.av-comparatives.org AV-Comparatives WEBLOG / FORUM Not speaking here on behalf of AV-Comparatives. Post questions in our forum. |
|
#7
|
|||
|
|||
|
That's not but we would need another Class like "Idiotware"
|
|
#8
|
|||
|
|||
|
I really cannot understand that people start using software which they don't know just because of the sake for having a "security software" name.
I said it already MANY TIMES in this forum - With unknown and untrustworthy Security Applications you can do more harm to your machine than having no programs at all installed! And this has nothing to do with "bashing products" or "not giving the author any chance" - it's insane to develop such applications without any expertise. You can really badly screwup a machine with this. |
|
#9
|
||||
|
||||
|
I for sure am not going to try this one out.
Best stick to the trusted ones. Thanks for the warning and the test Happy Bytes. ![]()
__________________
Brabantse leeuw | Eendracht maakt macht Vista HP SP1 | KIS 2009 | Malware Defender | SUPERAntiSpyware Opera & Firefox | Barca Pro | Sandboxie | FirstDefense-ISR | ShadowProtect Rogue/Suspect Anti-Spyware Products & Web Sites |
|
#10
|
||||
|
||||
|
Oh great i never liked that Microsoft XML Parser anyway. Maybe it could eliminate XP activation as well, along with a few other things hey !
Nice looking GUI though, worth getting just for that. I suppose it might be better to choose an AV that misses things, rather than one that produces FP's ! StevieO |
|
#11
|
|||
|
|||
|
I disassembled it to bring some light into the dark. It's indeed "dangerous".
It scans for fixed filenames! That means if there is a malware which uses for example 123.dll in the systemfolder it will detect and delete ANY FILE - regardingless what it is - with the name 123.dll. I just tryed it as follows: i renamed the own install log ( a normal text file ) of this pumpkin-application into "msxml3a.dll" and copied it into system32. Voila: Detected! It detects it's own files if it has the matching name to the malware! That's also the reason why there is no proper virus name. The author only collects files where he ASSUMES that they are malicious. then he adds this filename in a database (simple encrypted) and scans for this filenames. I cannot believe what crap people developing - thats really the worst i saw so far and just believe me i saw a lot of weird things |
|
#12
|
||||
|
||||
|
Quote:
|
|
#13
|
||||
|
||||
|
Happy bytes you do know it's Very naughty to disassemble or reverse engineer software ?
I've heard of self repairing Apps, but self destructing ! Maybe they could turn it into a nice little shredder App instead. StevieO |
|
#14
|
|||
|
|||
|
Quote:
That's my daily work. ![]() |
|
#15
|
|||
|
|||
|
an analysts needs to disassemble malware, good thing he did
.btw, nice trojan definition which could apply can be found on http://www.research.ibm.com/antiviru...y/inwVB99.html Quote:
etc. ![]()
__________________
http://www.av-comparatives.org AV-Comparatives WEBLOG / FORUM Not speaking here on behalf of AV-Comparatives. Post questions in our forum. |
|
#16
|
|||
|
|||
|
Well it is NOT a trojan. The author does not even know that he's that bad. So basically it becomes a dangerous application based on unexpirience from the author, but not on purpose. A trojan always has a purpose to disguest something. Here we have a new kind of malware - i would name it "Idiotware" but unfortunately there isn't such a category now
Or "PDA" Potentially dangerous Application ![]() |
|
#17
|
|||
|
|||
|
Quote:
Dave |
|
#18
|
|||
|
|||
|
Quote:
If you donate 5 bucks to me i can send you a copy of DEL-Command ![]() |
|
#19
|
|||
|
|||
|
Gotta love Happy Bytes and his 'bullshit walks' attitude!
![]() |
|
#20
|
|||
|
|||
|
Quote:
I don't know you, but i love you too ![]() |
|
#21
|
||||
|
||||
|
Now whom is realy in the know?
Interesting young thread. http://www.dslreports.com/forum/remark,15734965 SOunds pretty nasty to me. Happy B, when you dissembled this did you find a rootkit? |
|
#22
|
|||
|
|||
|
The worm has nothing to do with this app.
|
|
#23
|
||||
|
||||
|
Ok sorry this must be a different version.
"There is virus Win32.Alcra.F that has name RemoveIT Pro 2.4 SE.zip and it spreads it self via sharing networks. So please beware if you downloading this zip file or some other zip file via sharing network and keep your antivirus up to date." ( »www.incodesolutions.com/index2.html )" con |
|
#24
|
|||
|
|||
|
What is so difficult to understand? The worm has nothing to do with this version what you can download on their website.
|
|
#25
|
||||
|
||||
|
Was just wondering why this post over on Dslreports mentioned this and the link to ( »www.incodesolutions.com/index2.html )" is all.
|
| « Previous Thread | Next Thread » |
| Thread Tools | Search this Thread |
|
|