Jump to content
Sign in to follow this  
robinb

I believe this is a false positive-gotomypc

Recommended Posts

I use gotomypc and malwarebytes is putting it as a trojan.fake

in c:/documents and settings/user/370_gotomypc.exe

c:/documents and settings/user/gotomypc.exe_370.exe

c:/documents and settings/user/gotomypc.exe_478.exe

I know this is a legitimate program so I put it in ignore

but you really need to fix this because many people use gotomypc

robin

Share this post


Link to post
Share on other sites
I use gotomypc and malwarebytes is putting it as a trojan.fake

in c:/documents and settings/user/370_gotomypc.exe

c:/documents and settings/user/gotomypc.exe_370.exe

c:/documents and settings/user/gotomypc.exe_478.exe

I know this is a legitimate program so I put it in ignore

but you really need to fix this because many people use gotomypc

robin

Here is the developers log file- I took out the username for security

Malwarebytes' Anti-Malware 1.30

Database version: 1446

Windows 5.1.2600 Service Pack 3

12/2/2008 12:18:16 PM

mbam-log-2008-12-02 (12-18-08).txt

Scan type: Quick Scan

Objects scanned: 69345

Time elapsed: 7 minute(s), 19 second(s)

Memory Processes Infected: 0

Memory Modules Infected: 0

Registry Keys Infected: 0

Registry Values Infected: 0

Registry Data Items Infected: 0

Folders Infected: 0

Files Infected: 3

Memory Processes Infected:

(No malicious items detected)

Memory Modules Infected:

(No malicious items detected)

Registry Keys Infected:

(No malicious items detected)

Registry Values Infected:

(No malicious items detected)

Registry Data Items Infected:

(No malicious items detected)

Folders Infected:

(No malicious items detected)

Files Infected:

C:\Documents and Settings\User\370_gotomypc.exe (Trojan.FakeAlert) -> No action taken. [3857535134305383807566791539667670347770838513013627613780688678707985840166796

90152708585747972846151806774796111641115708970]

C:\Documents and Settings\User\gotomypc_370.exe (Trojan.FakeAlert) -> No action taken. [3857535134305383807566791539667670347770838513013627613780688678707985840166796

90152708585747972846151806774796111641115708970]

C:\Documents and Settings\User\gotomypc_428.exe (Trojan.FakeAlert) -> No action taken. [3857535134305383807566791539667670347770838513013627613780688678707985840166796

90152708585747972846151806774796111641115708970]

Share this post


Link to post
Share on other sites

They are using executables in illegal locations named very close to known malware . I can whitelist to work around this .

Share this post


Link to post
Share on other sites
They are using executables in illegal locations named very close to known malware . I can whitelist to work around this .

explain how you can whitelist around this? do you do something in the program? will there be an update so I can take them out of ignore?

thanks

robin

Share this post


Link to post
Share on other sites
do you do something in the program?

You could say that , I'm the lead researcher for this project and have the most direct access to the database .

I have whitelisted around this application while keeping detection for the malware that behaves much the same way .

Share this post


Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
Sign in to follow this  

  • Recently Browsing   0 members

    No registered users viewing this page.

×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.