FP Vistumbler

I use Vistumbler to seek other wireless accesspoints in the neighberhood, it’s like Netstumbler but working on Vista.

Avast gives a warning on opening Vistumbler. From the Avast log:

30-1-2009 14:30:57 SYSTEEM 1800 Sign of "Win32:StartPage-697 [trj]" has been found in "C:\Program Files\Vistumbler\Vistumbler.exe" file.

Homepage of Vistumbler: http://www.vistumbler.net/

To know if it’s a false positive, upload the file to VirusTotal or VirScan and post the results.

If indeed an FP, send the file in a password-protected zip folder to virus@avast.com with “False Positive” in subject and the password mentioned in the email body.

6 out of 39 detect it according to VirusTotal
Antivirus Versie Laatst geüpdatet Resultaat

Avast 4.8.1281.0 2009.01.30Win32:StartPage-697
BitDefender 7.2 2009.01.30 Trojan.Generic.1405325
eSafe 7.0.17.0 2009.01.29 Suspicious File
GData 19 2009.01.30 Trojan.Generic.1405325
TheHacker 6.3.1.5.237 2009.01.30 Trojan/StartPage.dgp
VBA32 3.12.8.11 2009.01.30 Trojan.Win32.StartPage.dfd

Hi

DrWeb’s av link checker plug-in finds this…
Checking: http://downloads.sourceforge.net/vistumbler/Vistumbler9-0_Installer.exe
Engine version: 4.44.0.9170
File size: 2.53 MB

http://downloads.sourceforge.net/vistumbler/Vistumbler9-0_Installer.exe packed by UPX

http://downloads.sourceforge.net/vistumbler/Vistumbler9-0_Installer.exe packed by ZLIB

http://downloads.sourceforge.net/vistumbler/Vistumbler9-0_Installer.exe - archive BINARYRES

http://downloads.sourceforge.net/vistumbler/Vistumbler9-0_Installer.exe/data001 - Ok
http://downloads.sourceforge.net/vistumbler/Vistumbler9-0_Installer.exe/data002 - Ok
http://downloads.sourceforge.net/vistumbler/Vistumbler9-0_Installer.exe/data003 - Ok
http://downloads.sourceforge.net/vistumbler/Vistumbler9-0_Installer.exe/data004 - Ok
http://downloads.sourceforge.net/vistumbler/Vistumbler9-0_Installer.exe/data005 packed by UPX

http://downloads.sourceforge.net/vistumbler/Vistumbler9-0_Installer.exe/data005 - Ok
http://downloads.sourceforge.net/vistumbler/Vistumbler9-0_Installer.exe/data006 - Ok
http://downloads.sourceforge.net/vistumbler/Vistumbler9-0_Installer.exe/data007 packed by UPX
http://downloads.sourceforge.net/vistumbler/Vistumbler9-0_Installer.exe/data007 - Ok
http://downloads.sourceforge.net/vistumbler/Vistumbler9-0_Installer.exe/data008 - Ok
http://downloads.sourceforge.net/vistumbler/Vistumbler9-0_Installer.exe/data009 - Ok
http://downloads.sourceforge.net/vistumbler/Vistumbler9-0_Installer.exe/data010 - Ok
http://downloads.sourceforge.net/vistumbler/Vistumbler9-0_Installer.exe/data011 - Ok
http://downloads.sourceforge.net/vistumbler/Vistumbler9-0_Installer.exe/data012 - Ok
http://downloads.sourceforge.net/vistumbler/Vistumbler9-0_Installer.exe/data013 - Ok
http://downloads.sourceforge.net/vistumbler/Vistumbler9-0_Installer.exe/data014 - Ok
http://downloads.sourceforge.net/vistumbler/Vistumbler9-0_Installer.exe/data015 - Ok
http://downloads.sourceforge.net/vistumbler/Vistumbler9-0_Installer.exe/data016 - Ok
http://downloads.sourceforge.net/vistumbler/Vistumbler9-0_Installer.exe/data017 - Ok
http://downloads.sourceforge.net/vistumbler/Vistumbler9-0_Installer.exe/data018 - Ok
http://downloads.sourceforge.net/vistumbler/Vistumbler9-0_Installer.exe/data019 - Ok
http://downloads.sourceforge.net/vistumbler/Vistumbler9-0_Installer.exe/data020 - Ok
http://downloads.sourceforge.net/vistumbler/Vistumbler9-0_Installer.exe/data021 - Ok
http://downloads.sourceforge.net/vistumbler/Vistumbler9-0_Installer.exe/data022 - Ok
http://downloads.sourceforge.net/vistumbler/Vistumbler9-0_Installer.exe/data023 - Ok
http://downloads.sourceforge.net/vistumbler/Vistumbler9-0_Installer.exe/data024 - Ok
http://downloads.sourceforge.net/vistumbler/Vistumbler9-0_Installer.exe/data025 - Ok
http://downloads.sourceforge.net/vistumbler/Vistumbler9-0_Installer.exe/data026 - Ok
http://downloads.sourceforge.net/vistumbler/Vistumbler9-0_Installer.exe/data027 - Ok
http://downloads.sourceforge.net/vistumbler/Vistumbler9-0_Installer.exe/data028 - Ok
http://downloads.sourceforge.net/vistumbler/Vistumbler9-0_Installer.exe/data029 - Ok
http://downloads.sourceforge.net/vistumbler/Vistumbler9-0_Installer.exe/data030 - Ok
http://downloads.sourceforge.net/vistumbler/Vistumbler9-0_Installer.exe/data031 - Ok
http://downloads.sourceforge.net/vistumbler/Vistumbler9-0_Installer.exe/data032 - Ok
http://downloads.sourceforge.net/vistumbler/Vistumbler9-0_Installer.exe/data033 - Ok
http://downloads.sourceforge.net/vistumbler/Vistumbler9-0_Installer.exe/data034 - Ok
http://downloads.sourceforge.net/vistumbler/Vistumbler9-0_Installer.exe/data035 - Ok
http://downloads.sourceforge.net/vistumbler/Vistumbler9-0_Installer.exe/data036 - Ok
http://downloads.sourceforge.net/vistumbler/Vistumbler9-0_Installer.exe/data037 packed by UPX
http://downloads.sourceforge.net/vistumbler/Vistumbler9-0_Installer.exe/data037 - Ok
http://downloads.sourceforge.net/vistumbler/Vistumbler9-0_Installer.exe/data038 - Ok
http://downloads.sourceforge.net/vistumbler/Vistumbler9-0_Installer.exe/data039 - Ok
http://downloads.sourceforge.net/vistumbler/Vistumbler9-0_Installer.exe/data040 - Ok
http://downloads.sourceforge.net/vistumbler/Vistumbler9-0_Installer.exe/data041 - Ok
http://downloads.sourceforge.net/vistumbler/Vistumbler9-0_Installer.exe/data042 - Ok
http://downloads.sourceforge.net/vistumbler/Vistumbler9-0_Installer.exe/data043 - Ok
http://downloads.sourceforge.net/vistumbler/Vistumbler9-0_Installer.exe/data044 - Ok
http://downloads.sourceforge.net/vistumbler/Vistumbler9-0_Installer.exe/data045 packed by UPX
http://downloads.sourceforge.net/vistumbler/Vistumbler9-0_Installer.exe/data045 - Ok
http://downloads.sourceforge.net/vistumbler/Vistumbler9-0_Installer.exe/data046 - Ok
http://downloads.sourceforge.net/vistumbler/Vistumbler9-0_Installer.exe/data047 packed by UPX
http://downloads.sourceforge.net/vistumbler/Vistumbler9-0_Installer.exe/data047 - Ok
http://downloads.sourceforge.net/vistumbler/Vistumbler9-0_Installer.exe - Ok

And WOT has this: http://www.mywot.com/en/scorecard/vistumbler.net

polonus

Alarm comes from the exe file of the program itself. Installer gives no hit with Avast.
I’ll send a mail towards Alwil, we’ll wait and see.