Page 1 of 4

Adware detected in installer

PostPosted: Tue May 19, 2009 3:45 am
by pelle
Doing a manual scan of the installer (v0.7.0.4399 - Full Edition) gives this with Eset NOD AV 4.0.424. Installer was downloaded from Sourceforge.

Number of scanned objects: 507
Number of infected objects: 1
Number of cleaned objects: 0

D:\Downloads\MediaCoder-0.7.0.4399.exe » NSIS » rkinstall.exe - Win32/Adware.Agent.NMA application

The v0.7.0.4395 installer gives no such warning.

Extracting the v0.7.0.4399 installer with UniExtract. VirusTotal gives this result (20/40 (50.00%))for the rkinstall.exe located here (\MediaCoder-0.7.0.4399\$TEMP\$TEMP\rkinstall.exe)

Report form VirusTotal:
http://www.virustotal.com/analisis/cde3bd74533204d2e8bab4583338a5e7

Most likely a false postive but can you verify the validity of the file rkinstall.exe contained in the installer?

Re: Adware detected in installer

PostPosted: Tue May 19, 2009 6:48 pm
by LoudThunder
I had the same answer for the same file.
Hope someone can tell us if rkinstall.exe is safe.

RkInstall.exe is truly a adware, but I don't understand why Mediacoder has it.
Someone can tell me what is going on?

Re: Adware detected in installer

PostPosted: Sat May 23, 2009 1:58 am
by stanley
It will not be installed by default.

Re: Adware detected in installer

PostPosted: Sat May 23, 2009 7:52 pm
by jbkeh
It won't be installed BECAUSE IT WON'T BE (SUCCESSFULLY) DOWNLOADED!

Most people sane enough to use a virus checker have it set to scan anything being downloaded and to reject anything containing undesirable material.

Suggest you QUICKLY RETHINK this action - once the software package (and you) garner a reputation for inappropriate conduct, it will be irreparable.

You are killing the goose - I doubt you will find a collection of golden eggs.

Re: Adware detected in installer

PostPosted: Sun May 24, 2009 1:13 am
by stanley
The 4399 installer is repackaged and uploaded.

Here is the scanning report of VirtusTotal:
http://www.virustotal.com/analisis/5d8229b50f6e4829d98ebc1e4b26ddbabf8f3a3c4ae4d8af1c37c5ed0aaacab9-1243101200

TrendMicro's detection of PAK_Generic.001 is obviusly a mis-reporting.

Re: Adware detected in installer

PostPosted: Sun May 24, 2009 4:29 am
by Placio74
Hmm...

New installer from SourceForge does not contain RelevantKnowledge Survey.

But new installer from Google Code contain RelevantKnowledge Survey and unfortunately... is running before choose components. :!: (Which means the lock installation by many antivirus and antimalware apps, also can't install MC without RK.)