PDA

View Full Version : VirusTotal Analysis for SB8 #4063 compiled apps (2013/05/24)



NewsArchive
05-24-2013, 05:47 AM
SetupBuilder 8.0 #4063 test install images submitted to VirusTotal, a
subsidiary of Google, for analysis.

File name: sb8virustotal_4063.exe
Detection ratio: 1 / 47
Analysis date: 2013-05-24 11:25:11 UTC

https://www.virustotal.com/en/file/078a5aaee929ead45610eeb8710186d1e316bd2602ac8741e2 8f2206b123e643/analysis/1369394711/

-> Panda reports a "Suspicious file" false-positive. Bug in the Panda
Security product.


File name: sb8virustotalex_4063.exe
Detection ratio: 1 / 47
Analysis date: 2013-05-24 11:28:49 UTC

https://www.virustotal.com/en/file/d5cf26f3e318816aea59dd9e4b6e48826fb389740452c8b468 4af03873f10145/analysis/1369394929/


-> Panda reports a "Suspicious file" false-positive. Bug in the Panda
Security product.


File name: sb80_4063_Dev.exe
Detection ratio: 0 / 47
Analysis date: 2013-05-24 11:42:26 UTC

https://www.virustotal.com/en/file/79957e44cbaca47568e6202ece7a37e9e07bd0b37fc98cafb1 97ae326a719afd/analysis/1369395746/


Friedrich

--
Friedrich Linder
Lindersoft
www.lindersoft.com
+1.954.252.3910

--Helping You Build Better Installations
--SetupBuilder "point. click. ship"
--Create Windows 8 ready installations in minutes
--Official Comodo Code Signing and SSL Certificate Partner

NewsArchive
05-24-2013, 06:02 AM
Update #1: Case opened with PandLabs (PANDA SECURITY, Bilbao, Spain)

"...This is to acknowledge the receipt of your mail which included
suspicious files. Your case is currently being studied. If we need any
additional information, we will contact you. Otherwise, once analysed, those
which have been classified as malware will be included in the next update of
our signature file..."

NewsArchive
05-25-2013, 04:06 AM
Still not fixed, PANDA SECURITY. Very bad job.

Friedrich

NewsArchive
05-28-2013, 01:25 AM
Update #2: We sent several emails to PANDA SECURITY, but not any feedback
from PandLabs (Bilbao, Spain).

Unfortunately, PANDA SECURITY seems to not care at all about
"false-positive" bugs in their software. SetupBuilder powers millions of
installations worldwide and they simply ignore any communication. We sent
example applications to demonstrate the false-positive bug.

If your customers get a "false-positive" from their Panda security software,
please ask them to send an email to Panda Security.

http://www.pandasecurity.com/usa/

--
Friedrich Linder
Lindersoft
www.lindersoft.com
+1.954.252.3910

--Helping You Build Better Installations
--SetupBuilder "point. click. ship"
--Create Windows 8 ready installations in minutes
--Official Comodo Code Signing and SSL Certificate Partner

NewsArchive
05-29-2013, 01:07 AM
Maybe this kind of thing would make a good tumblr.

Jeff Slarve
www.jssoftware.com
www.twitter.com/jslarve
I'll search help files & Google for you.

NewsArchive
05-29-2013, 03:44 AM
Update #3: Panda Tech Support contacted us today. We have a Case Number
now: 03682033

We submitted again two test EXE files to their Panda Laboratories for
analysis.

Friedrich

NewsArchive
05-29-2013, 06:32 AM
Always two olives with you! ;-)

--

Russ Eggen
RADFusion International, LLC

NewsArchive
05-29-2013, 08:54 AM
>
> Maybe this kind of thing would make a good tumblr.
>

Hehehehe :)

Friedrich

NewsArchive
05-29-2013, 08:54 AM
Let's hope they get it resolved soon...

Friedrich

NewsArchive
05-30-2013, 05:50 AM
Update #4: PANDA SECURITY fixed the false-positive bug. This was Case
Number: 03682033

File name: sb8virustotal_4063.exe (Test Application #1)
Detection ratio: 0 / 47
Analysis date: 2013-05-30 10:27:23 UTC

https://www.virustotal.com/en/file/078a5aaee929ead45610eeb8710186d1e316bd2602ac8741e2 8f2206b123e643/analysis/


File name: sb8virustotalex_4063.exe (Test Application #2)
Detection ratio: 1 / 47
Analysis date: 2013-05-30 10:30:19 UTC

https://www.virustotal.com/en/file/d5cf26f3e318816aea59dd9e4b6e48826fb389740452c8b468 4af03873f10145/analysis/


File name: sb80_4063_Dev.exe (Original SB8 Install Image)
Detection ratio: 0 / 47
Analysis date: 2013-05-30 10:35:31 UTC

https://www.virustotal.com/en/file/79957e44cbaca47568e6202ece7a37e9e07bd0b37fc98cafb1 97ae326a719afd/analysis/


Friedrich

--
Friedrich Linder
Lindersoft
www.lindersoft.com
+1.954.252.3910

--Helping You Build Better Installations
--SetupBuilder "point. click. ship"
--Create Windows 8 ready installations in minutes
--Official Comodo Code Signing and SSL Certificate Partner