Jump to content
newswatcher

Wondershare Video Converter (false positives)

Recommended Posts

Hello,

 

I am a registered and paid user of MWB Premium

 

I purchased legal software from Wondershare, their Video Download Converter 7.1.3 and I get 46 "Non-Malware" hits with MWB which I believe are false positives.

http://www.wondershare.com/

Can confirm that their software is not malware and why do I get the hits from MWB if it is false positives. This is a reputable software company that is highly rated.

Either you need to fix MWB to non-detect for their software or communicate with them as to why their software is getting these hits.

 

I've attached the MWB log on the hits.

 

Advise,

 

Thanks,

 

Mr. Hunter

Share this post


Link to post
Share on other sites

It appears you don't allow attachments, here's the log:

 

Malwarebytes Anti-Malware
www.malwarebytes.org

Scan Date: 7/18/2014
Scan Time: 11:30:25 PM
Logfile: WVDC Log.txt
Administrator: Yes

Version: 2.00.2.1012
Malware Database: v2014.07.19.02
Rootkit Database: v2014.07.17.01
License: Premium
Malware Protection: Enabled
Malicious Website Protection: Enabled
Self-protection: Enabled

OS: Windows 8.1
CPU: x64
File System: NTFS
User: John

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 330344
Time Elapsed: 10 min, 20 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Enabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

Processes: 0
(No malicious items detected)

Modules: 0
(No malicious items detected)

Registry Keys: 0
(No malicious items detected)

Registry Values: 0
(No malicious items detected)

Registry Data: 0

 

 

And the screenshot:

 

WYN0G7p.jpg

Share this post


Link to post
Share on other sites

This is the full text file:

 

Malwarebytes Anti-Malware
www.malwarebytes.org

Scan Date: 7/18/2014
Scan Time: 11:30:25 PM
Logfile: Text File.txt
Administrator: Yes

Version: 2.00.2.1012
Malware Database: v2014.07.19.02
Rootkit Database: v2014.07.17.01
License: Premium
Malware Protection: Enabled
Malicious Website Protection: Enabled
Self-protection: Enabled

OS: Windows 8.1
CPU: x64
File System: NTFS
User: John

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 330344
Time Elapsed: 10 min, 20 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Enabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

Processes: 0
(No malicious items detected)

Modules: 0
(No malicious items detected)

Registry Keys: 0
(No malicious items detected)

Registry Values: 0
(No malicious items detected)

Registry Data: 0
(No malicious items detected)

Folders: 7
PUP.Optional.MindSpark.A, C:\Users\John\AppData\LocalLow\VideoDownloadConverter_4z, No Action By User, [1b864957f98290a62bbc229141c1659b],
PUP.Optional.MindSpark.A, C:\Users\John\AppData\LocalLow\VideoDownloadConverter_4z\bar, No Action By User, [1b864957f98290a62bbc229141c1659b],
PUP.Optional.MindSpark.A, C:\Users\John\AppData\LocalLow\VideoDownloadConverter_4z\bar\Cache, No Action By User, [1b864957f98290a62bbc229141c1659b],
PUP.Optional.MindSpark.A, C:\Users\John\AppData\LocalLow\VideoDownloadConverter_4z\bar\History, No Action By User, [1b864957f98290a62bbc229141c1659b],
PUP.Optional.MindSpark.A, C:\Users\John\AppData\LocalLow\VideoDownloadConverter_4z\bar\Message, No Action By User, [1b864957f98290a62bbc229141c1659b],
PUP.Optional.MindSpark.A, C:\Users\John\AppData\LocalLow\VideoDownloadConverter_4z\bar\Message\COMMON, No Action By User, [1b864957f98290a62bbc229141c1659b],
PUP.Optional.MindSpark.A, C:\Users\John\AppData\LocalLow\VideoDownloadConverter_4z\bar\Settings, No Action By User, [1b864957f98290a62bbc229141c1659b],

Files: 39
PUP.Optional.MindSpark.A, C:\Users\John\AppData\LocalLow\VideoDownloadConverter_4z\bar\Cache\01DEFC7B, No Action By User, [1b864957f98290a62bbc229141c1659b],
PUP.Optional.MindSpark.A, C:\Users\John\AppData\LocalLow\VideoDownloadConverter_4z\bar\Cache\01DEFF0C, No Action By User, [1b864957f98290a62bbc229141c1659b],
PUP.Optional.MindSpark.A, C:\Users\John\AppData\LocalLow\VideoDownloadConverter_4z\bar\Cache\01DF0073.bmp, No Action By User, [1b864957f98290a62bbc229141c1659b],
PUP.Optional.MindSpark.A, C:\Users\John\AppData\LocalLow\VideoDownloadConverter_4z\bar\Cache\01DF00E0.bmp, No Action By User, [1b864957f98290a62bbc229141c1659b],
PUP.Optional.MindSpark.A, C:\Users\John\AppData\LocalLow\VideoDownloadConverter_4z\bar\Cache\01DF0286.bmp, No Action By User, [1b864957f98290a62bbc229141c1659b],
PUP.Optional.MindSpark.A, C:\Users\John\AppData\LocalLow\VideoDownloadConverter_4z\bar\Cache\01DF02C5.bmp, No Action By User, [1b864957f98290a62bbc229141c1659b],
PUP.Optional.MindSpark.A, C:\Users\John\AppData\LocalLow\VideoDownloadConverter_4z\bar\Cache\01DF0390.bmp, No Action By User, [1b864957f98290a62bbc229141c1659b],
PUP.Optional.MindSpark.A, C:\Users\John\AppData\LocalLow\VideoDownloadConverter_4z\bar\Cache\01DF0545.cab, No Action By User, [1b864957f98290a62bbc229141c1659b],
PUP.Optional.MindSpark.A, C:\Users\John\AppData\LocalLow\VideoDownloadConverter_4z\bar\Cache\01DF0620.bmp, No Action By User, [1b864957f98290a62bbc229141c1659b],
PUP.Optional.MindSpark.A, C:\Users\John\AppData\LocalLow\VideoDownloadConverter_4z\bar\Cache\01DF06AD.cab, No Action By User, [1b864957f98290a62bbc229141c1659b],
PUP.Optional.MindSpark.A, C:\Users\John\AppData\LocalLow\VideoDownloadConverter_4z\bar\Cache\01DF0A66.bmp, No Action By User, [1b864957f98290a62bbc229141c1659b],
PUP.Optional.MindSpark.A, C:\Users\John\AppData\LocalLow\VideoDownloadConverter_4z\bar\Cache\01DF0B02.bmp, No Action By User, [1b864957f98290a62bbc229141c1659b],
PUP.Optional.MindSpark.A, C:\Users\John\AppData\LocalLow\VideoDownloadConverter_4z\bar\Cache\01DF0B50.bmp, No Action By User, [1b864957f98290a62bbc229141c1659b],
PUP.Optional.MindSpark.A, C:\Users\John\AppData\LocalLow\VideoDownloadConverter_4z\bar\Cache\01DF0D25.cab, No Action By User, [1b864957f98290a62bbc229141c1659b],
PUP.Optional.MindSpark.A, C:\Users\John\AppData\LocalLow\VideoDownloadConverter_4z\bar\Cache\files.ini, No Action By User, [1b864957f98290a62bbc229141c1659b],
PUP.Optional.MindSpark.A, C:\Users\John\AppData\LocalLow\VideoDownloadConverter_4z\bar\Cache\PopupProperties221584466.html, No Action By User, [1b864957f98290a62bbc229141c1659b],
PUP.Optional.MindSpark.A, C:\Users\John\AppData\LocalLow\VideoDownloadConverter_4z\bar\History\search3, No Action By User, [1b864957f98290a62bbc229141c1659b],
PUP.Optional.MindSpark.A, C:\Users\John\AppData\LocalLow\VideoDownloadConverter_4z\bar\Message\COMMON\8_step1.gif, No Action By User, [1b864957f98290a62bbc229141c1659b],
PUP.Optional.MindSpark.A, C:\Users\John\AppData\LocalLow\VideoDownloadConverter_4z\bar\Message\COMMON\anemone.js, No Action By User, [1b864957f98290a62bbc229141c1659b],
PUP.Optional.MindSpark.A, C:\Users\John\AppData\LocalLow\VideoDownloadConverter_4z\bar\Message\COMMON\bd_grad.gif, No Action By User, [1b864957f98290a62bbc229141c1659b],
PUP.Optional.MindSpark.A, C:\Users\John\AppData\LocalLow\VideoDownloadConverter_4z\bar\Message\COMMON\hpguard.js, No Action By User, [1b864957f98290a62bbc229141c1659b],
PUP.Optional.MindSpark.A, C:\Users\John\AppData\LocalLow\VideoDownloadConverter_4z\bar\Message\COMMON\hpguard1.htm, No Action By User, [1b864957f98290a62bbc229141c1659b],
PUP.Optional.MindSpark.A, C:\Users\John\AppData\LocalLow\VideoDownloadConverter_4z\bar\Message\COMMON\hpguard2.htm, No Action By User, [1b864957f98290a62bbc229141c1659b],
PUP.Optional.MindSpark.A, C:\Users\John\AppData\LocalLow\VideoDownloadConverter_4z\bar\Message\COMMON\hpp_ok.png, No Action By User, [1b864957f98290a62bbc229141c1659b],
PUP.Optional.MindSpark.A, C:\Users\John\AppData\LocalLow\VideoDownloadConverter_4z\bar\Message\COMMON\hpp_x.png, No Action By User, [1b864957f98290a62bbc229141c1659b],
PUP.Optional.MindSpark.A, C:\Users\John\AppData\LocalLow\VideoDownloadConverter_4z\bar\Message\COMMON\hpp_x2.png, No Action By User, [1b864957f98290a62bbc229141c1659b],
PUP.Optional.MindSpark.A, C:\Users\John\AppData\LocalLow\VideoDownloadConverter_4z\bar\Message\COMMON\index.htm, No Action By User, [1b864957f98290a62bbc229141c1659b],
PUP.Optional.MindSpark.A, C:\Users\John\AppData\LocalLow\VideoDownloadConverter_4z\bar\Message\COMMON\localizedStrings.js, No Action By User, [1b864957f98290a62bbc229141c1659b],
PUP.Optional.MindSpark.A, C:\Users\John\AppData\LocalLow\VideoDownloadConverter_4z\bar\Message\COMMON\mid_dots.gif, No Action By User, [1b864957f98290a62bbc229141c1659b],
PUP.Optional.MindSpark.A, C:\Users\John\AppData\LocalLow\VideoDownloadConverter_4z\bar\Message\COMMON\mws_logo.gif, No Action By User, [1b864957f98290a62bbc229141c1659b],
PUP.Optional.MindSpark.A, C:\Users\John\AppData\LocalLow\VideoDownloadConverter_4z\bar\Message\COMMON\protect.htm, No Action By User, [1b864957f98290a62bbc229141c1659b],
PUP.Optional.MindSpark.A, C:\Users\John\AppData\LocalLow\VideoDownloadConverter_4z\bar\Message\COMMON\rebut4b.htm, No Action By User, [1b864957f98290a62bbc229141c1659b],
PUP.Optional.MindSpark.A, C:\Users\John\AppData\LocalLow\VideoDownloadConverter_4z\bar\Message\COMMON\shield.png, No Action By User, [1b864957f98290a62bbc229141c1659b],
PUP.Optional.MindSpark.A, C:\Users\John\AppData\LocalLow\VideoDownloadConverter_4z\bar\Message\COMMON\stop.gif, No Action By User, [1b864957f98290a62bbc229141c1659b],
PUP.Optional.MindSpark.A, C:\Users\John\AppData\LocalLow\VideoDownloadConverter_4z\bar\Message\COMMON\systrayp.htm, No Action By User, [1b864957f98290a62bbc229141c1659b],
PUP.Optional.MindSpark.A, C:\Users\John\AppData\LocalLow\VideoDownloadConverter_4z\bar\Message\COMMON\tbguard1.htm, No Action By User, [1b864957f98290a62bbc229141c1659b],
PUP.Optional.MindSpark.A, C:\Users\John\AppData\LocalLow\VideoDownloadConverter_4z\bar\Message\COMMON\tbguard2.htm, No Action By User, [1b864957f98290a62bbc229141c1659b],
PUP.Optional.MindSpark.A, C:\Users\John\AppData\LocalLow\VideoDownloadConverter_4z\bar\Message\COMMON\tp_grad.gif, No Action By User, [1b864957f98290a62bbc229141c1659b],
PUP.Optional.MindSpark.A, C:\Users\John\AppData\LocalLow\VideoDownloadConverter_4z\bar\Settings\prevcfg2.htm, No Action By User, [1b864957f98290a62bbc229141c1659b],

Physical Sectors: 0
(No malicious items detected)

(end)

 

If no malicious items are detected then why does MWB give me these scare tactics?

Share this post


Link to post
Share on other sites

Hi,

 

We don't detect as Malware here, but as PUP (Potentially Unwanted Program). This because this is bundled with a Toolbar (by Mindspark), which is Adware.

Share this post


Link to post
Share on other sites

So, it is malware or not? And, yes, it has a toolbar and extension for FireFox, of which FF has had no problem with this software nor have I. This is not a potentially unwanted program that I downloaded from some suriptitious site or software I generated access to with a keygen, this is legal software with an excellent reputation. I have not noticed any added toolbars nor any adware from this legal software. I think you should reconsider how you diagnose legal software so that the buyer/purchaser is not frightened away from legal software. I've used MWB for some time now and have never had this problem. Answer my question please: Should I ignore your MWB warnings or not?

 

Thanks

Share this post


Link to post
Share on other sites

Hi,

 

No, it's not malware. That's also displayed in the alert you received: San Completed - Non-Malware detected.

I can't find the "video download converter" on the site you have given.

What you have installed here, or what malwarebytes detects is this one: http://www.videodownloadconverter.com/index.jhtml

Unsure if this was bundled with your main "video download converter", or if this is a seperate one you installed, not related with the one from Wondershare.

You can safely ignore this in the detection, or add to your whitelist, or alternatively, select to not detect PUP in the scan settings.

Share this post


Link to post
Share on other sites

Thanks for the response, Mieke.

 

Here is the correct site and purchase area:

http://www.wondershare.net/pro/video-converter-ultimate.html?gclid=CM6j7rT80b8CFRJk7AodWAIAeg

Here is the response from Wondershare:

 

Dear Customer,

Thank you for your e-mail. This is Bob from Wondershare Support, I am pleased to assist you.

I am very sorry for any possible inconvenience caused to you. With reference to the issue, I regret to learn that your anti-virus software thought our program has a virus. However, this program is safe for your computer, some firewall or anti-virus software will design some downloaded file as unsafe from non-approved sites, so please trust us.

If you need any further assistance please don't hesitate in contacting me.

Have a nice day.

Best regards,
Bob
Support Team

 

 

Best

Share this post


Link to post
Share on other sites

Hi,

 

I cannot reproduce any detection for above software. As I expected, what was detected by malwarebytes isn't the software by Wondershare, but a seperate program which is a toolbar only that is called video download converter.

Share this post


Link to post
Share on other sites

He's mincing words "...thought our program has a virus...".

 

At no time was there a virus declaration.  Malwarebytes' Anti-Malware (MBAM) isn't even an anti virus application.

 

PUP.Optional.MindSpark.A  is a detection for Possibly Unwanted Program (PUP) so he can get away with saying "no virus". 

Detecting a PUP, a non-malware detection, is another story all together.

 

If they are bundling MindSpark, that's the issue.

 

One problem I see in this thread is you haven't actually supplied the files being detected.  You are pointing to the web site.  What Malwarebytes' researchers download may not be what you have on your PC or what you downloaded.  Thus the water is muddied.

 

 

Please see the following: Please read before reporting a false positive

Share this post


Link to post
Share on other sites

He's mincing words "...thought our program has a virus...".

 

At no time was there a virus declaration.  Malwarebytes' Anti-Malware (MBAM) isn't even an anti virus application.

 

PUP.Optional.MindSpark.A  is a detection for Possibly Unwanted Program (PUP) so he can get away with saying "no virus". 

Detecting a PUP, a non-malware detection, is another story all together.

 

If they are bundling MindSpark, that's the issue.

 

One problem I see in this thread is you haven't actually supplied the files being detected.  You are pointing to the web site.  What Malwarebytes' researchers download may not be what you have on your PC or what you downloaded.  Thus the water is muddied.

 

 

Please see the following: Please read before reporting a false positive

I most certainly did show the files being detected! See posts two and three, which shows the "files being detected." I only pointed to the website since he asked me where it came from. The water is only muddied if you don't even look at the water...

Share this post


Link to post
Share on other sites

Showing detection log(s) is only half the information.  Personnel need the actual files uploaded to the forum (those being detected and/or those used to install the software) for Malware Researcher's inspection or re-inspection to either negate a False Positive or to affirm a righteous detection. 

 

There were no files attached in Post #2 and Post #3.

 

Reference:  Please read before reporting a false positive

 

 

Additionally, please also attach the detected file with your post.

Make sure it is in ZIP or RAR format.

Share this post


Link to post
Share on other sites

Showing detection log(s) is only half the information.  Personnel need the actual files uploaded to the forum (those being detected and/or those used to install the software) for Malware Researcher's inspection or re-inspection to either negate a False Positive or to affirm a righteous detection. 

 

There were no files attached in Post #2 and Post #3.

 

Reference:  Please read before reporting a false positive

I can't even attach a file in this forum, what's with that?

 

Here's the link (direct):

http://www.wondershare.com/pro/video-converter-ultimate.html

Quite honestly, as a paying customer, I would expect more cooperation on this forum! Rather than disparage the software developer and me, wouldn't it be better to be courteous and anxious to help? Doesn't seem that way to me! If the link above is not enough, I, quite frankly, don't know what more to do. Download it yourself and see what you get with MWB.

Share this post


Link to post
Share on other sites

BTW, posters can't even edit their posts here. Again, what's with that? No attachments allowed, no editing. Not too professional...

Share this post


Link to post
Share on other sites

Yes, new members can't edit posts.

 

Yes, all members can attach files to a post.  In fact they provide more than ample space to do so.

 

  1. Take the files and put them in a ZIP or RAR archive file.
  2. Create a new post.
  3. Choose "More Reply Options" on the bottom Right of the Web Form
  4. Now choose "Attach Files" on the bottom Left of the Web Form.
  5. Browse and find your ZIP or RAR file.
  6. Choose "Add Reply" and there's your post with your attachment(s)

 

Nobody is disparaging anybody.. You say you have a False Positive.  You need to help Malwarebytes help you prove it if it is indeed a False Positive. 

 

The file(s) you downloaded from the web site can be very different than what someone else downloads.  The fact you sent them an email means the site owner could have changed what is being downloaded subsequent to that communication.  I am not saying that happened but that is a possible outcome of the feedback loop.  A site can also download a different file to a visitor based upon the visitor's IP address and the location it comes from (aka; GeoIP).  For example a Greek language version of a program if your IP is from Greece. 

 

Don't you think that if Malwarebytes provides a statement such as Please read before reporting a false positive with directions one how to submit a False Positive and in those directions they ask you to upload the files that had been detected that they would provide a facility to actually perform the upload ?

 

Cooperation is a a two-way streak.  Not just an operation, a cooperation.

 

BTW:  The acronym for Malwarebytes' Anti-Malware is, and has always been, MBAM.

 

 

 

 

 

 

Share this post


Link to post
Share on other sites

Please reread above. What we are detecting as per miekemoes testing is not related to wondershare. This is a totally separate software from that we are detecting.

Share this post


Link to post
Share on other sites

i have also verified that the detections you list do not come from any of the wondershare links you provided for their software. please zip the folder that is listed and attach here and i can verify. 

Share this post


Link to post
Share on other sites

Hi,

 

As I said already, we don't detect anything from the installer you posted or the installer from the Wondershare software. What we do detect on your pc is not what wondershare installed, but came from another source.

What is detected in your log is VideoDownloadConverter_4z which can be downloaded from here: hxxp://www.videodownloadconverter.com/index.jhtml - This is NOT by Wondershare. In that case, our detection is correct, because it's adware.

 

Also,

https://www.google.com/search?name=f&hl=en&q=%22VideoDownloadConverter_4z%22&gws_rd=ssl - this is for what is detected in your log - which is not by wondershare, but by mindspark.

I am sure Bob from Wondershare can confirm that Malwarebytes doesn't detect any components from their software and what is listed in your log is not by Wondershare at all.

Share this post


Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

  • Recently Browsing   0 members

    No registered users viewing this page.

×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.