Protection

Discussion in 'General Returnil discussions' started by Rico, Oct 8, 2009.

Thread Status:
Not open for further replies.
  1. Rico

    Rico Registered Member

    Joined:
    Aug 19, 2004
    Posts:
    1,693
    Location:
    Texas
    Hi Guys,

    I waited for the final release of 'Returnil' for my 64-bit Vista box, and I'm pleased with 'Returnil's defense.

    This AM after booting '"Returnil' immediately quarantined the following:

    1. Tweakvi.exe, which contained "W32/Themida_Packed!ElDorado <note> Virus Total only listed a handful of AV companies which ID this threat. Perhaps Returnil should be added to AV totals list. Anyway my AV "AntiVir Personal" slept, while 'Returnil' nailed it.

    2. Not sure about this one threat "1248573747.ini" this seems to be associated with my "HP Printer" I've printed fine with this file in quarantine. So I guess it OK to delete.

    Excellent software 'Returnil', perhaphs when I'm more comfortable with 'Returnil', I can delete Avira

    Thanks
    Rico
     

    Attached Files:

  2. Coldmoon

    Coldmoon Returnil Moderator

    Joined:
    Sep 18, 2006
    Posts:
    2,981
    Location:
    USA
    Hi Rico,
    That is a generic PUP (potentially unwanted program) detection and we are working to adjust this feature as soon as possible. We suggest the following work-around until this is adjusted:

    1. Open the RVS interface
    2. Click preferences > Virus Guard Tab
    3. Change the Real-Time Advanced malware analysis mode option to "Do not use advanced rules analysis"

    This should stop the detection on Tweakvi.exe. If it does not, please let me know and will flag this to the development and research teams.

    Thanks
    Mike
     
  3. Rico

    Rico Registered Member

    Joined:
    Aug 19, 2004
    Posts:
    1,693
    Location:
    Texas
    Hi Coldmoon,

    Got this, with these settings see pic's:
     

    Attached Files:

  4. Coldmoon

    Coldmoon Returnil Moderator

    Joined:
    Sep 18, 2006
    Posts:
    2,981
    Location:
    USA
  5. Rico

    Rico Registered Member

    Joined:
    Aug 19, 2004
    Posts:
    1,693
    Location:
    Texas
    Hi I get this with this ver. Still! & switched back virus guard protection to recommended.

    Thanks
    Rico
     

    Attached Files:

    • r1.png
      r1.png
      File size:
      66.2 KB
      Views:
      142
    • r2.png
      r2.png
      File size:
      13.6 KB
      Views:
      145
  6. Coldmoon

    Coldmoon Returnil Moderator

    Joined:
    Sep 18, 2006
    Posts:
    2,981
    Location:
    USA
    Hi Rico,
    Can you send us a copy of the file for analysis? If yes, send it to support (dash) tech (at) returnil (dot) com

    Thanks
    Mike
     
Thread Status:
Not open for further replies.