Author Topic: FP in Registry Easy Cleaner  (Read 3174 times)

0 Members and 1 Guest are viewing this topic.

malberto

  • Guest
FP in Registry Easy Cleaner
« on: December 18, 2009, 03:32:47 AM »
Hello, yesterday when I was downloading Registry Easy Cleaner from http://www.regeasycleaner.com/RegistryEasy.exe I received a notification from avast saying that it contains traces of Win32: Malware-gen. It is really a malware or a false positive?

Greetings.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89029
  • No support PMs thanks
Re: FP in Registry Easy Cleaner
« Reply #1 on: December 18, 2009, 03:49:35 AM »
You could also check the offending/suspect file at: VirusTotal - Multi engine on-line virus scanner and report the findings here the URL in the Address bar of the VT results page. You can't do this with the file securely in the chest, you need to extract it to a temporary (not original) location first, see below.

Create a folder called Suspect in the C:\ drive, e.g. C:\Suspect. Now exclude that folder in the Standard Shield, Customize, Advanced, Add, type (or copy and paste) C:\Suspect\* That will stop the standard shield scanning any file you put in that folder. You should now be able to export any file in the chest to this folder and upload it to VirusTotal without avast alerting.

Check this forum as I believe this "Registry Easy Cleaner" has been in a topic recently.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Jtaylor83

  • Guest
Re: FP in Registry Easy Cleaner
« Reply #2 on: December 18, 2009, 08:54:51 AM »
This site is bad.

http://www.mywot.com/en/scorecard/regeasycleaner.com

hpHosts found that this site is used for fake security applications. So the detections are correct.

Please disable the download link by replacing http with hxxp.

YoKenny

  • Guest
Re: FP in Registry Easy Cleaner
« Reply #3 on: December 18, 2009, 11:40:12 AM »
This site is bad.

http://www.mywot.com/en/scorecard/regeasycleaner.com

hpHosts found that this site is used for fake security applications. So the detections are correct.

Please disable the download link by replacing http with hxxp.

Note: forum.hosts-file.net is down for maintenance:
http://hphosts.blogspot.com/2009/12/hphosts-forums-and-fspamlist-blog.html