Assigned Zemana False Positive Report Thread

  • Thread starter Deleted Member 333v73x
  • Start date
This thread is being handled by a member of the staff.

KevinYu0504

Level 5
Verified
Well-known
Mar 10, 2017
228

Hi , bro , sorry to tell you the wrong information before ,
but TwinHeadedEagle already confirm that he is not working for Zemana anymore ,
so if you had any false alert want to report ,
i will suggest you to send a email to official .

you can find their email address at official website ,
and feel free to contact them , you can just type a easy title with " false alert report " ,
than Zemana will handle it .
 

Mops21

Level 36
Verified
Honorary Member
Content Creator
Oct 25, 2014
2,503
Hi all

I have 2 False Positives for you

shellfile.exe
Status : Gescannt
Object : %programfiles%\xvirus anti-malware\shellfile.exe
MD5 : D291CD2D33AD06E8A85C8539DC8BF08B
Publisher : -
Size : 50688
Version : 7.0.0.0
Detection : Adware:Win32/Droon.A!Tttm
Cleaning Action : Quarantäne
Related Objects :
Datei - %programfiles%\xvirus anti-malware\shellfile.exe
Registry Eintrag - HKLM\Software\Classes\*\shell\xvirus_context\Command\@ = C:\Program Files (x86)\Xvirus Anti-Malware\shellfile.exe %1

Antivirus scan for 0e520551c75b61fc9b25ceb55b81d78d3a0a906491fe1a2ee8ce1b8b877d755d at 2017-06-14 16:41:59 UTC - VirusTotal

xvirusstart.exe
Status : Gescannt
Object : %programfiles%\xvirus anti-malware\xvirusstart.exe
MD5 : 3BD1D71482C05A466AD251F2A51E1734
Publisher : -
Size : 82944
Version : 7.0.0.8
Detection : Adware:Win32/Fortif!Ekrk
Cleaning Action : Quarantäne
Related Objects :
Datei - %programfiles%\xvirus anti-malware\xvirusstart.exe
Planmäßige Aufgabe - C:\WINDOWS\System32\Tasks\Xvirus Startup

Antivirus scan for 2907720a31faf7bacfc571e60a39b32d52609c81800675cb9fec9dd5bf56fbde at 2017-06-14 16:55:19 UTC - VirusTotal

With best Regards
Mops21
 

Attachments

  • Zemana Anti-Malware 2.73.2.2 FPs 01.jpg
    Zemana Anti-Malware 2.73.2.2 FPs 01.jpg
    293.7 KB · Views: 518
Last edited:

KevinYu0504

Level 5
Verified
Well-known
Mar 10, 2017
228
Hi all

I have 2 False Positives for you

shellfile.exe
Status : Gescannt
Object : %programfiles%\xvirus anti-malware\shellfile.exe
MD5 : D291CD2D33AD06E8A85C8539DC8BF08B
Publisher : -
Size : 50688
Version : 7.0.0.0
Detection : Adware:Win32/Droon.A!Tttm
Cleaning Action : Quarantäne
Related Objects :
Datei - %programfiles%\xvirus anti-malware\shellfile.exe
Registry Eintrag - HKLM\Software\Classes\*\shell\xvirus_context\Command\@ = C:\Program Files (x86)\Xvirus Anti-Malware\shellfile.exe %1

Antivirus scan for 0e520551c75b61fc9b25ceb55b81d78d3a0a906491fe1a2ee8ce1b8b877d755d at 2017-06-14 16:41:59 UTC - VirusTotal

xvirusstart.exe
Status : Gescannt
Object : %programfiles%\xvirus anti-malware\xvirusstart.exe
MD5 : 3BD1D71482C05A466AD251F2A51E1734
Publisher : -
Size : 82944
Version : 7.0.0.8
Detection : Adware:Win32/Fortif!Ekrk
Cleaning Action : Quarantäne
Related Objects :
Datei - %programfiles%\xvirus anti-malware\xvirusstart.exe
Planmäßige Aufgabe - C:\WINDOWS\System32\Tasks\Xvirus Startup

Antivirus scan for 679a2e65317168123538082fb1abfc3977ccfcfd07b4ca172206c967b5c440fc at 2017-06-14 16:48:07 UTC - VirusTotal

With best Regards
Mops21

@Mert Can ALICI

Please help ;)
 

Mops21

Level 36
Verified
Honorary Member
Content Creator
Oct 25, 2014
2,503

Attachments

  • Zemana AntiMalware 2.74.2.76 FP 01.jpg
    Zemana AntiMalware 2.74.2.76 FP 01.jpg
    307.5 KB · Views: 538
  • Zemana AntiMalware 2.74.2.76 FP 02.jpg
    Zemana AntiMalware 2.74.2.76 FP 02.jpg
    308 KB · Views: 512

Mops21

Level 36
Verified
Honorary Member
Content Creator
Oct 25, 2014
2,503
Hi @TwinHeadedEagle and Hi @Dani Santos

I have 2 Files for you

shellfile.exe
Status : Gescannt
Object : %programfiles%\xvirus anti-malware\shellfile.exe
MD5 : D291CD2D33AD06E8A85C8539DC8BF08B
Publisher : -
Size : 50688
Version : 7.0.0.0
Detection : Adware:Win32/Droon.A!Tttm
Cleaning Action : Quarantäne
Related Objects :
Datei - %programfiles%\xvirus anti-malware\shellfile.exe
Registry Eintrag - HKLM\Software\Classes\*\shell\xvirus_context\Command\@ = C:\Program Files (x86)\Xvirus Anti-Malware\shellfile.exe %1

xvirusstart.exe
Status : Gescannt
Object : %programfiles%\xvirus anti-malware\xvirusstart.exe
MD5 : 3BD1D71482C05A466AD251F2A51E1734
Publisher : -
Size : 82944
Version : 7.0.0.8
Detection : Adware:Win32/Fortif!Ekrk
Cleaning Action : Quarantäne
Related Objects :
Datei - %programfiles%\xvirus anti-malware\xvirusstart.exe
Planmäßige Aufgabe - C:\WINDOWS\System32\Tasks\Xvirus startup

shellfile.exe

Antivirus scan for 0e520551c75b61fc9b25ceb55b81d78d3a0a906491fe1a2ee8ce1b8b877d755d at 2017-07-29 14:24:30 UTC - VirusTotal

VirusTotal

xvirusstart.exe

Antivirus scan for 2907720a31faf7bacfc571e60a39b32d52609c81800675cb9fec9dd5bf56fbde at 2017-07-29 14:26:08 UTC - VirusTotal

VirusTotal

With best Regards
Mops21
 

Attachments

  • Zemana AntiMalware 2.74.2.76 FPs 01.jpg
    Zemana AntiMalware 2.74.2.76 FPs 01.jpg
    290.9 KB · Views: 548

pistol22cal

New Member
Jul 29, 2017
1
Zemana reports aeroadmin as malware and will not allow the application to run and automatically deletes the exe when downloaded.

aeroadmin is not malware at all
 

KevinYu0504

Level 5
Verified
Well-known
Mar 10, 2017
228
Zemana reports aeroadmin as malware and will not allow the application to run and automatically deletes the exe when downloaded.

aeroadmin is not malware at all

If you use automatically , usually Zemana only quarantine the files ,
But if your Zemana deletes the files , you can change in the setting ,
using quarantine still can save back the files .

By the way ,
I think Zemana official won't come here and see this post ,
if you are sure there is a false alert , you can send a email to them :)
 

catspc

New Member
Sep 28, 2017
1
Today the Windows Store on my Win 10 x64 machine updated the built-in MS "Mail & Calendar" app. After it had installed, I launched the mail app and my Zemana Antimalware (Premium) flagged it as malware. So I tried the calendar app and the same thing happened. Both apps were quarantined.

I could not find an option within the Zemana software to report a false positive, and I was unable to upload the file to virustotal or jotti's as the files are in the WindowsApps folder which does not permit access. So I took a screen snip to show the file paths from the quarantine. I imagine this is a FP as the app is Microsoft's own software and was updated via the Windows Store. It hasn't flagged any other version of this app - just the one released today (version 17.8500.40955.0). I did try contacting Zemana via their support page using the bug report form, but I'm not sure it went through OK (the page it redirected to after submitting didn't finish loading). Here is the snip from my quarantine.

If Zemana monitor this thread, would they be able to advise me if this is a genuine detection or a false positive? If it's a FP I'd like to restore it as I do use both. Thanks.
 

Attachments

  • ZAM detections mail and calendar app.jpg
    ZAM detections mail and calendar app.jpg
    98.2 KB · Views: 507

Valinorum

Removal Expert
Verified
Staff Member
Apr 21, 2014
2
This is indeed an FP. I will ask the dev to whitelist the latest files. In the meantime, restore them from Quarantine and exclude them.
Thank you for reporting.
 
  • Like
Reactions: GonzitoVir

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top