Jump to content

Recommended Posts

Hello Team,

 
Your Anti-Virus (MalWareBytes) is reporting the severe alert to my product while Installation.
This product is of Very legitimate & Reliable company who works for a social cause.
 
Download URL: http://addoncommon.info/v830 / Exe is attached in zip format with password "infected"
Exe Name: Dira123.exe
Quarantine Reason: PUP.OPtional.InstalleRex
 

 

We will appreciate if you can remove this alert for this file.

Please let me know in case of any query.

 

--

Regards

Neesha

post-147628-0-51075700-1389696391_thumb.

post-147628-0-01096000-1389696394_thumb.

post-147628-0-96465000-1389696395_thumb.

post-147628-0-03613400-1389696397_thumb.

post-147628-0-01728600-1389696401_thumb.

Dira123.rar

Link to post
Share on other sites

  • Staff

Hi,

 

This is no false positive, this is detected as PUP (Potentially Unwanted Program) since it tracks user data without any additional value for the user itself.. the only gain here is to monetize via the BHO that is installed.

We won't remove detection for this one and it seems like we aren't the only ones detecting this one: https://www.virustotal.com/nl/file/319f3fadca9e59f540424ef5c600d700a83499f0eb7d6262da0940f8b60644fa/analysis/1389696704/

 

On top, this is a similar variant: http://blog.malwarebytes.org/online-security/2013/12/installers-customizing-your-needs/

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.