Jump to content
IObit Forum
Top Free Driver Updater Tools Best 25 PC Optimization Software Best 22 Antimalware Best 22 Uninstaller Software IObit Coupons & Discount Offers PC Optimizer Mac Boost Advice IObit Coupons A Good Utility Program From IObit IObit Promo Codes IObit Coupon Codes IObit Coupons and Deals FAQs Driver Booster Pro Review

False detection or not - wvs.exe ? [SOLVED by db 1268]


Recommended Posts

It looks like Malware Fighter sees something but what !?

I'm so glad that I didn't set on automatic..

 

I looks like an old problem with I had with an Firewall. Well that Firewall had detected in war3.exe an invisible behaviour.. and for that reason I couldn't play my game. It name was great.. the best firewall ever, but I was so mad, because still with the help of its experts, I couldn't find and set something, to eradicate that. So I said to myself.. I wanna play, so I choose playing.

 

Well, that was happened 8-9 years ago, and now your Malware Fighter had detected a infected file ( exe file ) attached to my game. The name of the "package" is "All-In-One-WVS-by-DotA-Utilities". Well I have this "package" for more than 8 years on my pc.. and in the meantime I had many, many AV's on pc, and no one ( no AV ) said-detected that the "package" or a file, exe is infected. More than that... after the second scan your "fighter" detected another "exe" infected with the same virus :neutral: , not to mention that NOW I have an AV (pro one) on my pc..

So this is the first "IObit Malware Fighter Report"

 

IObit Malware Fighter

 

OS: Windows XP

Version: 2.0.1.12

Define Version: 1251

Time Elapsed: 00:07:05

Objects Scanned: 59935

Threats Found: 1

Save Time: 7/12/2013 3:30:12 PM

 

|Name|Type|Description|ID|

Trojan.Generic, FILE, C:\Program Files\Warcraft III\All-In-One-WVS-by-DotA-Utilities\wvs.exe, 4115509

 

PS : I can send you to your lab, the infected file.. to check it, if you want to

 

 

For now

Link to comment
Share on other sites

I see that nobody answer to my problem... witch actually is YOURS. :twisted:

 

I looked to that section where the admin moved my post, and I realized that you don't have an own lab (or you do:?:). So I uploaded the "infected" file to VIRUSTOTAL.. and surprise, 0/43

 

https://www.virustotal.com/en/file/67df22801d88683ac18b21676b02bac63101ad0e6afd9b7866d9f0132adad525/analysis/1378439618/

 

I still want to mention that at the first scan, the third AV.. aka "Antivir" detected a virus called TR/Yakes.cwaoa . I supose that... that is a "name" of it.

After the file was reanalyzed the result was zero.

Now who's wrong ? :roll: I told you from the beginning..

I admit that ANY file can be infected(almost any)

 

After that analysis(virus total) I scanned again the file with Malware Fighter and the result was the same "Trojan.Generic" :idea:

 

 

Now... what shell I do now.. because I looked into Malware Fighter "sand box aka quarantine" and I sow that another 2 files(exe) are infected with the same "Troian.Generic" and one more(again exe file) with another type of virus.. :shock: called "Trojan.Agent"

 

You better do something... :-| because regarding to your scan-module, it all look's like a spread, and in the near future, all the files will be infected.

 

Tell me what.. Do you want to analyze those infected files :?::idea: in order to modified your module, or should I uninstall it.

 

For now

Link to comment
Share on other sites

Hi Borgo,

 

Please, take all the files out of quatantine and note the location of the files, and you can either Scan All again, or use the Right-Click Menu Scan by IMF for each of those files.

 

Please post the IMF report for all of them, plus, VirusTotal reports of the others, and zip them and upload them to Wikisend and give the download links here for IObit to further investigate.

 

You can also upload them to IObit Cloud to see the results in IObit's own backyard!!! You can even upload them through IMF by clicking the cloud icon on the GUI at the right side. Just click Upload a file to cloud.

 

Cheers.

Link to comment
Share on other sites

Please, take all the files out of quatantine and note the location of the files

 

I don't need to note the location.. because all of them are exe files.

An audio recording application

A game

And a game version switcher

 

The IMF reports :

 

 

IObit Malware Fighter

 

OS: Windows XP

Version: 2.0.1.12

Define Version: 1251

Time Elapsed: 00:00:00

Objects Scanned: 1

Threats Found: 1

Save Time: 9/9/2013 6:46:56 AM

 

|Name|Type|Description|ID|

Trojan.Generic, FILE, C:\Program Files\Warcraft III\All-In-One-WVS-by-DotA-Utilities\wvs.exe, 4115509

 

IObit Malware Fighter

 

OS: Windows XP

Version: 2.0.1.12

Define Version: 1251

Time Elapsed: 00:00:00

Objects Scanned: 1

Threats Found: 1

Save Time: 9/9/2013 6:55:13 AM

 

 

|Name|Type|Description|ID|

Trojan.Generic, FILE, C:\Documents and Settings\Cargo\Desktop\quake3.exe, 4105390

 

IObit Malware Fighter

 

OS: Windows XP

Version: 2.0.1.12

Define Version: 1251

Time Elapsed: 00:00:01

Objects Scanned: 28

Threats Found: 1

Save Time: 9/9/2013 6:56:43 AM

 

|Name|Type|Description|ID|

Trojan.Agent, FILE, C:\Program Files\Audio Recorder for Free\filemerger.exe, 4058286

 

The IOBitCloud is not working, more exactly... when I click to upload the file, it said in a small window "Network error! Please check your Internet connection and try again". So I uploaded those 3 files to Wikisend in a zip file.

 

coconuts.zip

 

The ather 3 url scans from virustotal are :

 

https://www.virustotal.com/en/file/67df22801d88683ac18b21676b02bac63101ad0e6afd9b7866d9f0132adad525/analysis/1378439618/

 

https://www.virustotal.com/en/file/e77bb95456dacd0063b24d5f938dfcd99537f1a0110f564c341013735ce70083/analysis/

 

https://www.virustotal.com/en/file/6fdf112eafde1ad2c625d4c64933514b4fc1bd79cf28dd858d99d89bbd4d3a33/analysis/

 

It look's that you have a problem, if 47 AV's said NO VIRUSES ! :twisted:

 

Now what ! :mrgreen:

Link to comment
Share on other sites

Archived

This topic is now archived and is closed to further replies.

×
×
  • Create New...