Discussion about everything RO and OpenKore related. This place is NOT for ANY kind of support questions.
Moderator: Moderators
help_us
Testers Team
Posts: 106 Joined: 04 Apr 2008, 21:53
Noob?: No
Location: Asia
#1
Post
by help_us » 23 Jun 2011, 18:10
i download start.rar on misc.openkore.com and i scan that file.
i got -
Code: Select all
AhnLab-V3 2011.06.24.00 2011.06.23 -
AntiVir 7.11.10.82 2011.06.23 -
Antiy-AVL 2.0.3.7 2011.06.23 -
Avast 4.8.1351.0 2011.06.23 -
Avast5 5.0.677.0 2011.06.23 -
AVG 10.0.0.1190 2011.06.23 -
BitDefender 7.2 2011.06.23 -
CAT-QuickHeal 11.00 2011.06.23 -
ClamAV 0.97.0.0 2011.06.24 -
Commtouch 5.3.2.6 2011.06.23 -
Comodo 9169 2011.06.23 -
DrWeb 5.0.2.03300 2011.06.23 -
eSafe 7.0.17.0 2011.06.23 Win32.MalBehav
eTrust-Vet 36.1.8403 2011.06.23 -
F-Prot 4.6.2.117 2011.06.23 -
F-Secure 9.0.16440.0 2011.06.24 -
Fortinet 4.2.257.0 2011.06.23 -
GData 22 2011.06.24 -
Ikarus T3.1.1.104.0 2011.06.23 -
Jiangmin 13.0.900 2011.06.23 TrojanDropper.Agent.avmi
K7AntiVirus 9.106.4837 2011.06.23 -
Kaspersky 9.0.0.837 2011.06.23 -
McAfee 5.400.0.1158 2011.06.23 -
McAfee-GW-Edition 2010.1D 2011.06.23 -
Microsoft 1.7000 2011.06.23 -
NOD32 6234 2011.06.23 -
Norman 6.07.10 2011.06.23 -
nProtect 2011-06-23.01 2011.06.23 -
Panda 10.0.3.5 2011.06.23 -
PCTools 8.0.0.5 2011.06.23 -
Prevx 3.0 2011.06.24 -
Rising 23.63.03.03 2011.06.23 -
Sophos 4.66.0 2011.06.23 -
SUPERAntiSpyware 4.40.0.1006 2011.06.23 -
Symantec 20111.1.0.186 2011.06.23 -
TheHacker 6.7.0.1.239 2011.06.23 -
TrendMicro 9.200.0.1012 2011.06.23 -
TrendMicro-HouseCall 9.200.0.1012 2011.06.24 -
VBA32 3.12.16.2 2011.06.23 -
VIPRE 9672 2011.06.23 -
ViRobot 2011.6.23.4529 2011.06.23 -
VirusBuster 14.0.92.1 2011.06.23 -
link
this is really safe? i scan it twice
VashTheStampede
Plain Yogurt
Posts: 68 Joined: 11 Jun 2011, 01:47
Noob?: No
#2
Post
by VashTheStampede » 25 Jun 2011, 06:12
I've used it off and on for 4 years, no lost accounts, no stolen credit cards.
False positives on AVs are common.
I wrote the world's simplest file downloader like 10+ years ago(as a learning project) and five different AVs tell me it's a virus. It's like, I wrote the whole thing myself, and did so in about an hour. It's not a virus dummy >_>
Btw "malware behavior" is probably because XKore can hook into other programs and redirect internet traffic. Honestly, I'm surprised more AVs don't flag it. XKore exhibits tons of malware behavior(from an I/O stand point).
kLabMouse
Administrator
Posts: 1301 Joined: 24 Apr 2008, 12:02
#3
Post
by kLabMouse » 26 Jun 2011, 04:12
I had a Very long Conversation with AV Vendor Companies before 2.0.7 was released.
And Every company agreed that the Application should be White Listed.
The Only thing that they will Block/Ask User is the DLL Inject into non own Process.
Thus 3 AV's return False Positive. So it's nothing there to check.
help_us
Testers Team
Posts: 106 Joined: 04 Apr 2008, 21:53
Noob?: No
Location: Asia
#4
Post
by help_us » 26 Jun 2011, 12:22
thank you for responding to my question, its really relieve after know this is only false positive
kLabMouse
Administrator
Posts: 1301 Joined: 24 Apr 2008, 12:02
#5
Post
by kLabMouse » 26 Jun 2011, 14:43
help_us wrote: thank you for responding to my question, its really relieve after know this is only false positive
Anyway. I wanna be in Contact with thus AV vendors.
Can anybody post info about them?
VashTheStampede
Plain Yogurt
Posts: 68 Joined: 11 Jun 2011, 01:47
Noob?: No
#6
Post
by VashTheStampede » 27 Jun 2011, 05:45
Jiangmin is here
http://global.jiangmin.com/contact.htm
Never heard of "eSafe" before.