Jump to content

False Positive mp3DirectCut


digmorcrusher
 Share

Recommended Posts

  • digmorcrusher changed the title to False Positive mp3DirectCut

Hello @cli:

The following VT detection analysis is derived from the user's posting at Wilders:

https://www.virustotal.com/gui/file/da6fdd972d4f1bcc21c70f4fc610c51d001af83ada8c6909c9ae23643191464e/detection

Quote

File: 2
Malware.Heuristic.1003, C:\USERS\XIII\APPDATA\ROAMING\Microsoft\Windows\Start Menu\Apps\MP3 Direct Cut.lnk, No Action By User, 1000001, 0, , , , , ,
Malware.Heuristic.1003, C:\PROGRAM FILES (X86)\MP3DIRECTCUT\MP3DIRECTCUT.EXE, No Action By User, 1000001, 0, 1.0.44526, 0000000000000000000003EB, dds, 01404724, 21BD1D99F890218F0C0E358EA6A1A5AF, DA6FDD972D4F1BCC21C70F4FC610C51D001AF83ADA8C6909C9AE23643191464E

Since the above VT analysis implies version 2.3.3.0, the following is a Fosshub download URL for the mp3DirectCut v2.3.3.0 installer only and not the installed executable in question:

https://www.fosshub.com/mp3DirectCut.html?dwl=mp3DC233.exe

HTH

 

Edited by 1PW
Link to post
Share on other sites

  • Staff

this file has been whitelisted. 

Suggest they turn off expert system algorithms. This is off by default. Its designed to catch zero day malformed files but sometimes packers malform them and cause fps. This is only to be turned on if there is an active infection that is cleaned up and want to scan to make sure there isnt any unknown zero days. Its assumed when you turn this on you can tell the difference between a fp and a legit detection. 

 

  • Thanks 1
Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
 Share

  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.