Jump to content

A28C4D.msi (= Hijackthis.msi)


sweidre

Recommended Posts

Hi, here is an email sent to support@samples.immunet.com :

--------------------Quote-------------------

Hello,My Immunet Protect v.3.0.2.6548 Public Beta 1 Free (with enabled ClamAV) quarantined C:\Windows\Installer\a28c4d.msi as a Malware! After restoration from quarantine I uploaded the file to Virus Total, where none of the 43 AVs/AMs reported the file as a Malware (see attachment 1). The VT report shows that the file was HiJackThis.msi! Result: 0/43 = 0.0% –>Goodware! The msi-file compressed into a zip-file is attached: a28c4d.zip (see attachment 2). It is evident, that HiJackThis.msi is clean = “False Positive”, but it must be reported to the Immunet Community Cloud!Comments:Previously I have set:Scan Archive Files ONScan Packed Files ON,but RobT told Mature on another thread, that scan of archives & packed files will only take place, if ClamAV has been enabled! So, now I have enabled ClamAV and the extremely long scan of archive & packed files qurantines files, that earlier scans have missed! So far, the quarantined files are probably clean = “False Postives” and not Malwares!

--------------------Unquote-------------------

Cheers,

sweidre

PS. The attachments 1-2 have been attached to the email only, not uploaded to this forum! DS

 

Link to comment
Share on other sites

It's clean, it will be whitelisted.

Orlando

How many days do I have to keep the path to "HiJackThis" on the Exclusion List? One week? Two weeks? = Until info about Malware is deducted from the Cloud!

Cheers,

sweidre

Link to comment
Share on other sites

Archived

This topic is now archived and is closed to further replies.

×
×
  • Create New...