PDA

View Full Version : False-positive detection



Andsov
22-05-2024, 02:57 AM
Sorry for the bad text, I'm using a translator.

* Reports:
- <b>You have to register to ba able to see this link</b>
- <b>You have to register to ba able to see this link</b>
- <b>You have to register to ba able to see this link</b>

Antivirus: NO

05/19/2024 there was a clean report, without detections. And many times before. There have never been any detections. For the last few days nothing has been installed on the computer. Only the RAR archive with the game was downloaded, but the archive itself did not even open.

Dump: <b>You have to register to ba able to see this link</b> 9t0d2g&st=rhi0ya97&dl=0

Tiger
22-05-2024, 09:22 PM
Search for a file called "loader.exe" (md5: 80945D018D428FA5A83199E192ECBD13) and upload it to me.

Andsov
22-05-2024, 10:19 PM
Search for a file called "loader.exe" (md5: 80945D018D428FA5A83199E192ECBD13) and upload it to me.

It turned out to be a Bandicam program file.
Added to the archive, here is the link: <b>You have to register to ba able to see this link</b>

Tiger
24-05-2024, 12:19 AM
I can't download the file.

There was an error downloading your file..


Please upload it to <b>You have to register to ba able to see this link</b>

Andsov
24-05-2024, 12:58 AM
I can't download the file.



Please upload it to <b>You have to register to ba able to see this link</b>

I couldn't use your service wetransfer .com because the service blocks my file every time and the link to the file is not valid every time.
Uploaded to another service: <b>You have to register to ba able to see this link</b>

P.S.For some reason my computer thinks loader.exe is bad and stops loading it. I need to force save the file. Perhaps it's the same for you.

Tiger
24-05-2024, 10:49 PM
Indeed, the file contains malicious code. I will verify tomorrow or the day after tomorrow to be sure it doesn't contains an injector.

Andsov
29-05-2024, 09:31 AM
Indeed, the file contains malicious code. I will verify tomorrow or the day after tomorrow to be sure it doesn't contains an injector.

Any news on my situation? maybe you forgot about me

Tiger
29-05-2024, 08:55 PM
I apologize, I had a lot of work to do and completely forgot to check it. I just analyzed it, and it is indeed malicious.

Make sure you delete it, install an antimalware product, and scan your computer.