# Wondershare Video Converter (false positives)

## Recommended Posts

Hello,

I am a registered and paid user of MWB Premium

I purchased legal software from Wondershare, their Video Download Converter 7.1.3 and I get 46 "Non-Malware" hits with MWB which I believe are false positives.

http://www.wondershare.com/

Can confirm that their software is not malware and why do I get the hits from MWB if it is false positives. This is a reputable software company that is highly rated.

Either you need to fix MWB to non-detect for their software or communicate with them as to why their software is getting these hits.

I've attached the MWB log on the hits.

Thanks,

Mr. Hunter

##### Share on other sites

It appears you don't allow attachments, here's the log:

Malwarebytes Anti-Malware
www.malwarebytes.org

Scan Date: 7/18/2014
Scan Time: 11:30:25 PM
Logfile: WVDC Log.txt

Version: 2.00.2.1012
Malware Database: v2014.07.19.02
Rootkit Database: v2014.07.17.01
Malware Protection: Enabled
Malicious Website Protection: Enabled
Self-protection: Enabled

OS: Windows 8.1
CPU: x64
File System: NTFS
User: John

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 330344
Time Elapsed: 10 min, 20 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Enabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

Processes: 0
(No malicious items detected)

Modules: 0
(No malicious items detected)

Registry Keys: 0
(No malicious items detected)

Registry Values: 0
(No malicious items detected)

Registry Data: 0

And the screenshot:

##### Share on other sites

This is the full text file:

Malwarebytes Anti-Malware
www.malwarebytes.org

Scan Date: 7/18/2014
Scan Time: 11:30:25 PM
Logfile: Text File.txt

Version: 2.00.2.1012
Malware Database: v2014.07.19.02
Rootkit Database: v2014.07.17.01
Malware Protection: Enabled
Malicious Website Protection: Enabled
Self-protection: Enabled

OS: Windows 8.1
CPU: x64
File System: NTFS
User: John

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 330344
Time Elapsed: 10 min, 20 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Enabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

Processes: 0
(No malicious items detected)

Modules: 0
(No malicious items detected)

Registry Keys: 0
(No malicious items detected)

Registry Values: 0
(No malicious items detected)

Registry Data: 0
(No malicious items detected)

Folders: 7

Files: 39

Physical Sectors: 0
(No malicious items detected)

(end)

If no malicious items are detected then why does MWB give me these scare tactics?

##### Share on other sites

• Staff

Hi,

We don't detect as Malware here, but as PUP (Potentially Unwanted Program). This because this is bundled with a Toolbar (by Mindspark), which is Adware.

Thanks

##### Share on other sites

• Staff

Hi,

No, it's not malware. That's also displayed in the alert you received: San Completed - Non-Malware detected.

I can't find the "video download converter" on the site you have given.

What you have installed here, or what malwarebytes detects is this one: http://www.videodownloadconverter.com/index.jhtml

Unsure if this was bundled with your main "video download converter", or if this is a seperate one you installed, not related with the one from Wondershare.

You can safely ignore this in the detection, or add to your whitelist, or alternatively, select to not detect PUP in the scan settings.

##### Share on other sites

Thanks for the response, Mieke.

Here is the correct site and purchase area:

http://www.wondershare.net/pro/video-converter-ultimate.html?gclid=CM6j7rT80b8CFRJk7AodWAIAeg

Here is the response from Wondershare:

Dear Customer,

Thank you for your e-mail. This is Bob from Wondershare Support, I am pleased to assist you.

I am very sorry for any possible inconvenience caused to you. With reference to the issue, I regret to learn that your anti-virus software thought our program has a virus. However, this program is safe for your computer, some firewall or anti-virus software will design some downloaded file as unsafe from non-approved sites, so please trust us.

If you need any further assistance please don't hesitate in contacting me.

Have a nice day.

Best regards,
Bob
Support Team

Best

##### Share on other sites

• Staff

Hi,

I cannot reproduce any detection for above software. As I expected, what was detected by malwarebytes isn't the software by Wondershare, but a seperate program which is a toolbar only that is called video download converter.

##### Share on other sites

He's mincing words "...thought our program has a virus...".

At no time was there a virus declaration.  Malwarebytes' Anti-Malware (MBAM) isn't even an anti virus application.

PUP.Optional.MindSpark.A  is a detection for Possibly Unwanted Program (PUP) so he can get away with saying "no virus".

Detecting a PUP, a non-malware detection, is another story all together.

If they are bundling MindSpark, that's the issue.

One problem I see in this thread is you haven't actually supplied the files being detected.  You are pointing to the web site.  What Malwarebytes' researchers download may not be what you have on your PC or what you downloaded.  Thus the water is muddied.

##### Share on other sites

He's mincing words "...thought our program has a virus...".

At no time was there a virus declaration.  Malwarebytes' Anti-Malware (MBAM) isn't even an anti virus application.

PUP.Optional.MindSpark.A  is a detection for Possibly Unwanted Program (PUP) so he can get away with saying "no virus".

Detecting a PUP, a non-malware detection, is another story all together.

If they are bundling MindSpark, that's the issue.

One problem I see in this thread is you haven't actually supplied the files being detected.  You are pointing to the web site.  What Malwarebytes' researchers download may not be what you have on your PC or what you downloaded.  Thus the water is muddied.

I most certainly did show the files being detected! See posts two and three, which shows the "files being detected." I only pointed to the website since he asked me where it came from. The water is only muddied if you don't even look at the water...

##### Share on other sites

Showing detection log(s) is only half the information.  Personnel need the actual files uploaded to the forum (those being detected and/or those used to install the software) for Malware Researcher's inspection or re-inspection to either negate a False Positive or to affirm a righteous detection.

There were no files attached in Post #2 and Post #3.

Make sure it is in ZIP or RAR format.

##### Share on other sites

Showing detection log(s) is only half the information.  Personnel need the actual files uploaded to the forum (those being detected and/or those used to install the software) for Malware Researcher's inspection or re-inspection to either negate a False Positive or to affirm a righteous detection.

There were no files attached in Post #2 and Post #3.

I can't even attach a file in this forum, what's with that?

http://www.wondershare.com/pro/video-converter-ultimate.html

Quite honestly, as a paying customer, I would expect more cooperation on this forum! Rather than disparage the software developer and me, wouldn't it be better to be courteous and anxious to help? Doesn't seem that way to me! If the link above is not enough, I, quite frankly, don't know what more to do. Download it yourself and see what you get with MWB.

##### Share on other sites

BTW, posters can't even edit their posts here. Again, what's with that? No attachments allowed, no editing. Not too professional...

##### Share on other sites

Yes, new members can't edit posts.

Yes, all members can attach files to a post.  In fact they provide more than ample space to do so.

1. Take the files and put them in a ZIP or RAR archive file.
2. Create a new post.
3. Choose "More Reply Options" on the bottom Right of the Web Form
4. Now choose "Attach Files" on the bottom Left of the Web Form.
5. Browse and find your ZIP or RAR file.

Nobody is disparaging anybody.. You say you have a False Positive.  You need to help Malwarebytes help you prove it if it is indeed a False Positive.

The file(s) you downloaded from the web site can be very different than what someone else downloads.  The fact you sent them an email means the site owner could have changed what is being downloaded subsequent to that communication.  I am not saying that happened but that is a possible outcome of the feedback loop.  A site can also download a different file to a visitor based upon the visitor's IP address and the location it comes from (aka; GeoIP).  For example a Greek language version of a program if your IP is from Greece.

Don't you think that if Malwarebytes provides a statement such as Please read before reporting a false positive with directions one how to submit a False Positive and in those directions they ask you to upload the files that had been detected that they would provide a facility to actually perform the upload ?

Cooperation is a a two-way streak.  Not just an operation, a cooperation.

BTW:  The acronym for Malwarebytes' Anti-Malware is, and has always been, MBAM.

##### Share on other sites

• Staff

Please reread above. What we are detecting as per miekemoes testing is not related to wondershare. This is a totally separate software from that we are detecting.

##### Share on other sites

• Staff

i have also verified that the detections you list do not come from any of the wondershare links you provided for their software. please zip the folder that is listed and attach here and i can verify.

##### Share on other sites

video-converter-ultimate_setup_full495.rar

##### Share on other sites

• Staff

Hi,

As I said already, we don't detect anything from the installer you posted or the installer from the Wondershare software. What we do detect on your pc is not what wondershare installed, but came from another source.

Also,

I am sure Bob from Wondershare can confirm that Malwarebytes doesn't detect any components from their software and what is listed in your log is not by Wondershare at all.

## Create an account

Register a new account

×

• Back
• Learn