FJ Software Foren-Übersicht  
 Homepage   •  Suchen   •  FAQ   •  Mitgliederliste   •  Registrieren   •  Login
 False positive? Nächstes Thema anzeigen
Vorheriges Thema anzeigen
Neues Thema eröffnenNeue Antwort erstellen
Autor Nachricht
Fréderique



Anmeldedatum: 30.10.2012
Beiträge: 26

BeitragVerfasst am: Fr Feb 27, 2015 13:49 Antworten mit ZitatNach oben

Hi, my antivirus program BullGuard just quarantined one of the files in MPE: mpeclient.apk => classes.dex. It says the file is infected.
Please comment. If it's a false positive I'll inform BG and get it out of quarantaine. I wanted to add a screenshot of the BG message but can't find out how to add it as an appendix.

FJ, if you see this, thanks again for making MPE. I use it all the time to save my text messages to my PC and to save my contacts. Great job! Very Happy

Fréderique
Benutzer-Profile anzeigenPrivate Nachricht senden
Fréderique



Anmeldedatum: 30.10.2012
Beiträge: 26

BeitragVerfasst am: Fr Feb 27, 2015 14:10 Antworten mit ZitatNach oben

I'm sorry, I said it wrong.

The infected and quarantined file is Android.Trojan.SMSSend.AAH.

The infected object was mpeclient.apk => classes.dex

The path where they found it was C:\Program Files (x86)\MyPhoneExplorer\mpeclient.apk => classes.dex.

The infected process was [3956] C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe.

To be clear, this Trojan was found on my desktop pc. Maybe I imported it to the desktop through my text messages in MPE?
I'm confused what this is about.
Can somebody help out?
Thanks.
Benutzer-Profile anzeigenPrivate Nachricht senden
RobertR



Anmeldedatum: 01.03.2015
Beiträge: 4

BeitragVerfasst am: So März 01, 2015 19:30 Antworten mit ZitatNach oben

Same on my pc
Emsisoft Anti-Malware found "Android.Trojan.SMSSend.AAH"
-----------------------------------------------
Scan-Beginn: 01.03.2015 17:12:42
C:\Program Files (x86)\MyPhoneExplorer\mpeclient.apk -> classes.dex gefunden: Android.Trojan.SMSSend.AAH (B)
-----------------------------------------------
I quarantined this file and MPE is still running.

MPE is free, but I need a lot of money for new safety programs when I want to use it Shocked
Benutzer-Profile anzeigenPrivate Nachricht senden
Fréderique



Anmeldedatum: 30.10.2012
Beiträge: 26

BeitragVerfasst am: Di März 03, 2015 14:12 Antworten mit ZitatNach oben

Hey RobertR,

I found info on this malware here, in German:

http://www.fjsoft.at/forum/viewtopic.php?t=23891

As far as I understand it, this problem is known and being handled by FJ but there seems to be confusion about what he is doing about it and other malware that have been detected in MPE.

What's going on exactly? Is MPE becoming untrustworthy as far as malware is concerned?

Do you think that by eliminating this malware I can just continue using MPE? I'm really very fond of this program.

Fréderique
Benutzer-Profile anzeigenPrivate Nachricht senden
Fréderique



Anmeldedatum: 30.10.2012
Beiträge: 26

BeitragVerfasst am: Di März 03, 2015 14:33 Antworten mit ZitatNach oben

Another interesting question:

I installed MPE on this pc on August 25 last year and I run all kinds of scans all the time. How come this trojan has only just been found??
Benutzer-Profile anzeigenPrivate Nachricht senden
RobertR



Anmeldedatum: 01.03.2015
Beiträge: 4

BeitragVerfasst am: Di März 03, 2015 20:45 Antworten mit ZitatNach oben

Hi Frederic,
seems to be a malware für android devices.
I scanned my smartphone with "TrustGo" which didn't find any suspicious things ...??!!
On my pc I do an automatic scan once a week with Emsisoft Anti-Malware.
The scan last sunday was the first to discover this Trojan. Very strange !! I've installed MPE a few months ago. After that I had a lot of work with "Yawtix" that had confused my browser even after the removal.
Too bad, but I have to think about an alternative to MPE (Google-Sync?) ...
Right now I trust more in Google than in this infested Software Sad
Benutzer-Profile anzeigenPrivate Nachricht senden
RobertR



Anmeldedatum: 01.03.2015
Beiträge: 4

BeitragVerfasst am: Di März 03, 2015 21:07 Antworten mit ZitatNach oben

Hi again,

... confused ...

5 minutes ago there was a popup of Emsisoft that my files in quarantine were rescanned with new signatures and some ot them were false alarms.
It concerned "mpeclient.apk"
I uploaded the file to Emsisoft on Sunday. Maybe they have checked it already - I've got no further Information.
Benutzer-Profile anzeigenPrivate Nachricht senden
Fréderique



Anmeldedatum: 30.10.2012
Beiträge: 26

BeitragVerfasst am: Di März 03, 2015 23:21 Antworten mit ZitatNach oben

Thanks for responding. You can post in German if you like. I'm Dutch and understand German, it's just easier and quicker for me to write in English.

Now I'm totally confused as well. I'm mailing with MBAM about this. Shall tell them your findings.

I've used MPE for some years now, never had a problem. MBAM said my pc was clean, just some adware left. I don't know yet which adware and whether it's related to MPE.

I've read a lot today on this forum and it all seems to be about malware/adware that is installed upon installation of MPE. I saw nothing about trojans. Did you?

I'll let you know if I know more, ok? Very Happy

And my name is Fréderique, I'm a girl. Very Happy
Benutzer-Profile anzeigenPrivate Nachricht senden
Fréderique



Anmeldedatum: 30.10.2012
Beiträge: 26

BeitragVerfasst am: Mi März 04, 2015 18:42 Antworten mit ZitatNach oben

RobertR,

Did you see this?
===================================

icke1954
Moderator

Joined: 19 Apr 2014
Posts: 1518

PostPosted: Tue Mar 03, 2015 17:51 Reply with quoteBack to top
Hallo,
Bitte diesen Post mal anschauen http://www.fjsoft.at/forum/viewtopic.php?p=110817#110817

Gruß icke
================================================

So it IS a false positive!! That is good news. Because if you install MPE without the additional optional software it is a GREAT program!

FJ, if you read this, thank you for telling Icke to post that.
I'm VERY relieved!! Very Happy
I'll tell BullGuard it's a false positive.
And I agree totally that TOO many people use software without spending a small amount. What is 5 or 10 euros for most people? You drink 2 beer or buy a packet of cigarettes and it's gone too.

Greed is destroying our world.

Don't let it get to you, FJ, all the bad comments. Keep on going! <3

Very Happy
Benutzer-Profile anzeigenPrivate Nachricht senden
RobertR



Anmeldedatum: 01.03.2015
Beiträge: 4

BeitragVerfasst am: Do März 05, 2015 20:03 Antworten mit ZitatNach oben

Good news Smile
Thank you Fréderique
Benutzer-Profile anzeigenPrivate Nachricht senden
Beiträge der letzten Zeit anzeigen:      
Neues Thema eröffnenNeue Antwort erstellen


 Gehe zu:   



Nächstes Thema anzeigen
Vorheriges Thema anzeigen
Du kannst keine Beiträge in dieses Forum schreiben.
Du kannst auf Beiträge in diesem Forum nicht antworten.
Du kannst deine Beiträge in diesem Forum nicht bearbeiten.
Du kannst deine Beiträge in diesem Forum nicht löschen.
Du kannst an Umfragen in diesem Forum nicht mitmachen.

Powered by phpBB © 2001, 2002 phpBB Group :: FI Theme :: Alle Zeiten sind GMT + 1 Stunde
Deutsche Übersetzung von phpBB.de