Author Topic: Avast 4.7.1043 finds freerip296.exe "infected"  (Read 3583 times)

0 Members and 1 Guest are viewing this topic.

the Tester

  • Guest
Avast 4.7.1043 finds freerip296.exe "infected"
« on: September 08, 2007, 08:44:00 PM »
During a thorough scan with Avast it alerted me that freerip296.exe was infected with Win32:SearchCol...
FreeRip is a cd ripper freeware that I installed months ago.As far as I know it is a clean program.
I sent a copy of that file to AlWil thru the Virus Chest.
I'm going to upload the file to VirusTotal and see what that shows for results.

Rafel

  • Guest
Re: Avast 4.7.1043 finds freerip296.exe "infected"
« Reply #1 on: September 08, 2007, 08:53:16 PM »
I downloades FreeRIPmp3 3.01 from download.com, unpacked with Universal extractor and scanned the unpacked files with AVAST, SA free, AVG AS free and ST and it's clean.
I think you have installed and old version.

the Tester

  • Guest
Re: Avast 4.7.1043 finds freerip296.exe "infected"
« Reply #2 on: September 08, 2007, 09:08:57 PM »
I think you have installed and old version.

You are right.

the Tester

  • Guest
Re: Avast 4.7.1043 finds freerip296.exe "infected"
« Reply #3 on: September 08, 2007, 09:22:04 PM »
Results form VT scan:
BitDefender and Ikarus also identified Adware:BD found MyWay,Ikarus found NewDotNet.

There may something to this.
I used FreeRip only once.Now looking at it closely I see a "My $earch" button in the control panel.That is probably Adware.Off it goes!

It's up to the virus analysers to look at the file I sent and decide what it is or isn't.

*Edit-FYI.
I see Free Rip 3.01 is available at MajorGeeks.It is classified as "Adware" there.
My mistake as I don't normally use adware/spyware programs at all!
« Last Edit: September 08, 2007, 11:11:35 PM by the Tester »

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89336
  • No support PMs thanks
Re: Avast 4.7.1043 finds freerip296.exe "infected"
« Reply #4 on: September 08, 2007, 11:26:24 PM »
Some like to say that they are add supported for their free use and that is what myway, etc. would be doing monitoring your activity to serve the adverts relevant to your browsing habits.

Though the same as you no way I would use this c*ap delivering ads when there are probably other tools to do the same job without the adware.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.5.6116 (build 24.5.9153.762) UI 1.0.808/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Rafel

  • Guest
Re: Avast 4.7.1043 finds freerip296.exe "infected"
« Reply #5 on: September 09, 2007, 12:07:23 AM »
There a lot of prorams.
I use AIMP classic player to listen to music and i used it for ripping all my CD's some times ago.

the Tester

  • Guest
Re: Avast 4.7.1043 finds freerip296.exe "infected"
« Reply #6 on: September 09, 2007, 05:02:04 AM »
Thanks for the tip Rafel.
I'll look at AIMP classic player.
I found Media Monkee but I haven't tried it yet.Maybe i can compare the two. ;)

Rafel

  • Guest
Re: Avast 4.7.1043 finds freerip296.exe "infected"
« Reply #7 on: September 09, 2007, 03:58:29 PM »
If you like more Media monkey. You can use it. With media monkey problems with adaware are out too.  ;)

Offline Maxx_original

  • Avast team
  • Super Poster
  • *
  • Posts: 1479
Re: Avast 4.7.1043 finds freerip296.exe "infected"
« Reply #8 on: September 10, 2007, 10:11:22 AM »
the tester: the file is Inno setup i guess.. can you post the scan result here? i want to see which underlaying file is detected..

the Tester

  • Guest
Re: Avast 4.7.1043 finds freerip296.exe "infected"
« Reply #9 on: September 11, 2007, 10:00:49 PM »
I had two files detected.
The one that I uploaded successfully was found in system volume information\_restore.It's identified as A0045447.exe.Win32:Stealth-H.
I have that in quarantine yet.

The FreeRip exe file was too large to upload to Alwil.
I haven't been able to compress it to a small enough size to upload.I do have a copy of the file but I did uninstall FreeRip.
I copied and pasted the "Warning" log as I couldn't find the upload link.

9/7/2007   10:50:14 PM   1189223414   XXXX   232   Sign of "Win32:Trojan-gen. {Other}" has been found in "C:\Documents and Settings\All Users\Documents\freerip296.exe\{app}\s4Setp.exe\[Embedded#040d0]\[Embedded#453d8]" file. 
9/7/2007   10:52:30 PM   1189223550   XXXX   232   Sign of "Win32:SearchColor-C [Adw]" has been found in "C:\Documents and Settings\All Users\Documents\freerip296.exe\{app}\s4Setp.exe\[Embedded#870d0]\[Embedded#040d0]" file. 
9/7/2007   10:52:33 PM   1189223553   XXXX   232   Sign of "Win32:SearchColor-C [Adw]" has been found in "C:\Documents and Settings\All Users\Documents\freerip296.exe\{app}\s4Setp.exe\[Embedded#870d0]" file. 
9/7/2007   10:52:40 PM   1189223560   XXXX   232   Sign of "Win32:SearchColor-C [Adw]" has been found in "C:\Documents and Settings\All Users\Documents\freerip296.exe\{app}\s4Setp.exe" file. 
9/7/2007   11:16:20 PM   1189224980   XXXX   232   Sign of "Win32:Stealth-H [Trj]" has been found in "C:\System Volume Information\_restore{2786A773-52E3-4420-B7EE-47CCCC5C4BA3}\RP70\A0045447.exe\[ASPack]\[Embedded#1fe218]" file. 
9/7/2007   11:43:58 PM   1189226638   XXXX   232   Sign of "Win32:SearchColor-C [Adw]" has been found in "C:\Documents and Settings\All Users\Documents\freerip296.exe\{app}\s4Setp.exe" file.