FP

AusUninst.exe (part of Auslogics Registry Cleaner’s upgrade function, presumably “old version uninstaller”?)

Name of detection: Heur.Packed.Unknown[at]4294967295
CIS database number: 18458

Download link:

http://downloads.auslogics.com/en/registry-cleaner/registry-cleaner-setup.exe

Thanks, REBOL. :slight_smile:

Hi,MorphOS REBOL

Thank you for reporting this.
We’ll check it and get back to you soon.

Best regards
Chunli.chen

Hi,MorphOS REBOL

Reported file(registry-cleaner-setup.exe) are not detected.
Please update to AV database Version <18458> of Comodo Internet Security Version<7.0.317799.4142> and confirm it.

Regards
Chunli.chen

@Chunli
I think you need to change something in the Settings to get Heur.Packed.Unknown detections.

Hi Chunli, as stated above, CIS database version indeed WAS <18458> of Comodo Internet Security Version <7.0.317799.4142>, so yes, again “confirmed”.

Update: Just been removing the file from my exclusion list for testing purposes, and it instantly got flagged again as Heur.Packed.Unknown[at]4294967295.
Database version 18470.

Second update:
Did a re-check using database version 18472.

AusUninst.exe is still being flagged as malicious.

I guess you’re right with that assumption, malware1. :slight_smile:

Just to make sure, I re-uploaded the file at Virustotal a few minutes ago:

Kind regards, REBOL. :slight_smile:

Funny thing is, this thing is even digitally signed by

COMODO Code Signing CA 2 Status: Valid Valid from: 1:00 AM 8/24/2011 Valid to: 11:48 AM 5/30/2020 Valid usage: Code Signing Algorithm: SHA1 Thumbrint: B64771392538D1EB7A9281998791C14AFD0C5035 Serial number: 10 70 9D 4F F5 54 08 D7 30 60 01 D8 EA 91 75 BB

Kind regards, REBOL. :wink:

Hi,MorphOS REBOL

Thank you for reporting this.
We’ll check it and get back to you soon.

Best regards
Chunli.chen

Hi MorphOS REBOL,

This is to inform you that false-positive has been fixed.
You can update to AV database Version <18477> of Comodo Internet Security
Version <7.0.317799.4142> and confirm it.

Regards,
Yuvaraj M

FP detection now fixed, thank you.

Kind regards, REBOL. :slight_smile: