Postby boombastik » 2012-04-20 10:12

Windows 7 32 bits sp1 with all updates and anvisoft final.

1 Type:00000743 Name:Stolen.Data Path:C:\Users\ToiMoi\AppData\Roaming\ImgBurn
2 Type:0002357A Name:Hijack.StartMenu Path:HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced
3 Type:0002D930 Name:PSW.OnLineGames Path:C:\Program Files\Common Files\ATI Technologies\Multimedia\atimpenc.dll
4 Type:0002FC95 Name:Trojan.Generic Path:C:\Program Files\eMule\Uninstall.exe
5 Type:0002FDBD Name:TR/Dropper.Gen Path:C:\Program Files\Garena\BlackShotLauncher\UpdateMove.exe
6 Type:0002FDBD Name:TR/Dropper.Gen Path:C:\Program Files\Garena\BlackShotLauncher\UpdateMove1.exe
7 Type:00030498 Name:TR/Agent.Vitro Path:C:\Program Files\Warcraft III\World Editor.exe
8 Type:0003058B Name:W32/Expiro.AM Path:C:\Windows\System32\browserchoice.exe
9 Type:0003058B Name:W32/Expiro.AM Path:C:\Windows\winsxs\x86_microsoft-windows-browserballot_31bf3856ad364e35_6.1.7600.16526_none_62283b15ce321cd0\browserchoice.exe

1) The first one is a folder which is created by the legitame program imgburn. (http://www.imgburn.com/)
2) The second maybe it detects my start menu because i have modified it.
3) Part of Legitame ati drivers: https://www.virustotal.com/file/d0ed478b7daa417bbc20336da8f5c6f64e55ef5ad0ec638960d7d3634bc0b5ad/analysis/1334932782/ (0 detection rate)
4) Part of Legitame emule p2p program: https://www.virustotal.com/file/268bf5ffc58ec8a3671def0dfd886b4f22caab1313fc961583db77ad99c4b2d6/analysis/1334932963/ (0 detection rate)
5) Part of the garena : https://www.virustotal.com/file/111169c123b91bae577d4800cc572caf4a1f31e9c314bc5c977b5320f6e1a35f/analysis/1334933263/ (0 detection rate)
6) Part of the Garena: https://www.virustotal.com/file/9e728b8944329be02a81dc9db446d1a5e1249f2f8393b7036690cab5cd5e91ab/analysis/1334933406/ (0 detection rate)
7) Part of the original game warcraft 3: https://www.virustotal.com/file/c705fa48099f3b4416a6d6a31d691b1a55c09007efa9292663f2c16f56353e27/analysis/1334933961/ (0 detection rate)
8) Part of the Windows sp1 (kb976002) : https://www.virustotal.com/file/4c5fb3c35ca7c2e10ae2920afd40e854c123219901c15a80941ac9f53eef97d7/analysis/1334933654/ (detection rate 1/42----> false positive this is a legitame file of part OS)
9) Same as 8 (same file in the winsxs folder)

If u want them i upload all the false positives there:

