False positive: winapiexec

File:
http://rammichael.com/downloads/winapiexec.rar

Website:
http://rammichael.com/winapiexec

Detected as:
Win32:MDE-B [Susp]

Have you tested the file at www.virustotal.com

when done, post the scan link here do we can see the result

https://www.virustotal.com/file/d1e414ff407819075dbb761fe51a787c3749c393b2e36b68060ecfba875a0d88/analysis/1344012445/

You can report a possible false positive here: http://www.avast.com/contact-form.php

Only avast and GData detect: http://rammichael.com/downloads/winapiexec.rar (probably FP because of Real basic code)
See no SpyEye alert on the url scan: http://urlquery.net/report.php?id=113654 or a Generic Backdoor alert of any sort,
and most phishes for yhe IP general are dead. See: http://hosts-file.net/default.asp?s=facepoker.us
Analysis, see: http://anubis.iseclab.org/?action=result&task_id=10b10b5cca992dff4c933d0fcfb756aeb&format=html
Probably bad download site for this: http://www.mywot.com/en/scorecard/65.39.72.142?utm_source=addon&utm_content=popup-donuts,

polonus

First seen by VirusTotal
2012-03-19 20:14:50 UTC ( 4 måneder, 2 uker ago )

I’ve used the contact form, and the detection was removed, thanks.

https://www.virustotal.com/file/d1e414ff407819075dbb761fe51a787c3749c393b2e36b68060ecfba875a0d88/analysis/1344369332/

Your welcome. :slight_smile: