RSK-HIDE.SAA.~B@18001662

RKill - iExplore.exe is possible a F/P after to execute this program and sandboxed

Hi GOA,

We are going to check these and if it confirms as false-positive, detection will be removed.

Thanks and regards,
Ionel

Hi GOA,

The false-positive was fixed with CIS virus database version 8217. You can check and confirm.

Thanks and regards,
Ionel

Hello, sorry but it is a new false-positiv after Update database 8221
and RKill ist sandboxed

TrojWare.Win32.Agent2.crpw[at]183928559
TrojWare.Win32.Agent2.crpw[at]1
c:\users\1234\appdata\local\temp\rarsfx0[b]userinit.exe[/b]

nircmd.exe
userinit.exe
winlogon.exe
iexplore.exe
|Unsfx|winlogon.exe

http://www.virustotal.com/file-scan/report.html?id=27c7ffd8367aaa73155fbb287a7df1f157f2d0c3323dbb176d02b36ff616fca5-1301947648

[attachment deleted by admin]

Hi GOA,

We’ll verify the issue. Thanks for reporting it!

Regards,
Ionel

OK tanks, is fixed, but sandboxed.