False Positive with avast on a program that i trust?

hello there is an alert i got from avast when scanned my computer’s downloads folder. the program is called PenguinStorm11.1 It is made by the owner of cpcheats.info
(see picture for the Scan results i got)
What do i do if i want to run this program? :-\

I uploaded the Program to Virustotal to see if avast is the only one and there is more dectecting this program as a virus http://www.virustotal.com/file-scan/report.html?id=811d3ff8728d40344bbbf6b4d1d90832068812eac06c66c998f56506109ab797-1284373137

Should i turn off the Shield that is dectecting this when i try to run it? :-\

I dont know anything about this program, but from where did you download it ?
Have you tried to download from another place and then scan it at VT ?
When i google the name there is a newer version 12.4

i downloaded it from cpcheats.info
And i know about the newer version of it but i like the old version it loads a little faster.

Btw:cpcheats.info is the site is where i downloaded it at. and this isn’t the first time avast has had a FP with this program :-\

With 17 detections on VT there is no way I would be considering stopping a shield that is alerting on this just to play a game.

I would be pointing out this VT results URL to the game makers and ask why this is.

Whilst a lot of the detections are generic or heuristic it is hard to imagine that they are all wrong. So it needs further investigation.

i did that scan http://anubis.iseclab.org/?action=result&task_id=10c76dfa33eafa3d4f522acc8b55393de&format=html there is the results.

i don’t understand why it is just a third party program that will let me go to a game without going to the game’s website

I see that on the link i posted above it says that the program is a Trojan-Downloader.Win32.Banload (Sig-Id:42020488)

Presumably the reason for games web site is legit rather than trying to get round some form of validation ?

I have to say the name of the site you got it from cpcheats.info makes me wonder why it is called cpcheats.info. When I see something like that I think cracks/hacks, etc. but I’m a trusting sort (NOT).

The Anubis analysis only makes me more suspicious because of the number of changes it makes in the registry and security setting changes it makes in IE, see image summary, even Anubis believes it a risk.

The changes it makes in Internet Explorer how do i change it back to the way it was before i downloaded this program?

Notice:Cpcheats.info tells everybody something before they download see picture below

Sorry but a) I would never trust a statement like that and b) the Anubis analysis says changed IE security settings could seriously effect safety surfing the Web. That kind of contradicts that guarantee, ‘guaranteed not to harm your computer.’

I told you I was a trusting sort didn’t I.

Your system your choice, I know what I would do

how do i make sure it didn’t change the Security Settings of internet explorer?

I don’t know, but the analysis report of Anubis indicates that it does and also shows which ones, so you have to manually check, but you also need to know what the default values were. It isn’t a case of if it didn’t change the security settings as Anubis says that is part of the actions it takes.

There’s a sucker born every minute
http://en.wikipedia.org/wiki/There’s_a_sucker_born_every_minute

I agree with DavidR

i let avast move it to the virus chest for now. :slight_smile:

At the very least I would also open the Internet Options, Security and use the Reset all zones to default level.

i Already did that :slight_smile: and before i move that program to the virus chest internet explorer 8 kept on freezing up and going non responding on me. now internet explorer 8 is responding for me :slight_smile:

FALSE POSITIVE IS FIXED :slight_smile:

BTW i asked the maker and owner of cpcheats.info he told me that the coding of the program that Anubis website will say it isn’t safe cause it is the way he coded it. but he also said that the program will Not change internet explorer’s settings :slight_smile: