ZoneAlarm User Community
ZoneAlarm User Community
 

Go Back   ZoneAlarm User Community > ZoneAlarm Forums > Malware Discussion

Reply
 
Thread Tools Display Modes
  #1  
Old November 2nd, 2009, 10:18 PM
craig123456 craig123456 is offline
Junior Member
 
Join Date: Nov 2009
Posts: 1
Default info on RarePacker.Multi.Generic

Zonealarm has found the following when unpacking an exe file: "RarePacker.Multi.Generic was found" and quarantined the file.
(it's the old DVD Shink application)

Do you have any information on what rarepacker is and why it was quarantined? Is it safe to use, or what does it do?

regards
craig
Reply With Quote
  #2  
Old November 4th, 2009, 02:28 PM
findley's Avatar
findley findley is offline
Senior Member
 
Join Date: Aug 2007
Posts: 1,307
Default Re: info on RarePacker.Multi.Generic

Quote:
Originally Posted by craig123456 View Post
Zonealarm has found the following when unpacking an exe file: "RarePacker.Multi.Generic was found" and quarantined the file.
(it's the old DVD Shink application)

Do you have any information on what rarepacker is and why it was quarantined? Is it safe to use, or what does it do?

regards
craig
Craig,

To check this out, you could upload the DVD shrink files to Virus Total Virustotal is a free service which will analyze the suspicious files. The files will be checked out against thirty-nine antivirus engines.

There was a thread on false positives, DVD shrink and RarePacker.Multi.Generic
a couple months back. Here is the link: ZASS False Positives

Best regards,
Findley
Reply With Quote
  #3  
Old November 17th, 2009, 02:09 PM
atinalee atinalee is offline
Junior Member
 
Join Date: Jul 2006
Posts: 44
Default Re: info on RarePacker.Multi.Generic

I just did a scan because I just installed the new 9.1.008 program.

It foudn rarepacker.multi generic in this codestuffstarter program I have used for years. I am not sure what to do now? I really dont think they would have a trojan in this program.

Can you tell me if this is a false positive and if I should restore it. It put it in the quarantine file.

Thanks

Anita
Reply With Quote
  #4  
Old November 22nd, 2009, 08:52 AM
findley's Avatar
findley findley is offline
Senior Member
 
Join Date: Aug 2007
Posts: 1,307
Default Re: info on RarePacker.Multi.Generic

Quote:
Originally Posted by atinalee View Post
I just did a scan because I just installed the new 9.1.008 program.

It foudn rarepacker.multi generic in this codestuffstarter program I have used for years. I am not sure what to do now? I really dont think they would have a trojan in this program.

Can you tell me if this is a false positive and if I should restore it. It put it in the quarantine file.

Thanks

Anita
Hi Anita,
Suggest you follow the same advice as previously given to craig in post #2.
Upload any suspicious file to Virus Total or to Jotti's malware scan You'll get your answer as to whether this is a false positive.
best regards and enjoy the weekend,
Findley
Reply With Quote
  #5  
Old December 23rd, 2009, 09:28 AM
gramps gramps is offline
Junior Member
 
Join Date: May 2005
Posts: 1
Smile Re: info on RarePacker.Multi.Generic

Quote:
Originally Posted by findley View Post
Craig,

To check this out, you could upload the DVD shrink files to Virus Total Virustotal is a free service which will analyze the suspicious files. The files will be checked out against thirty-nine antivirus engines.

There was a thread on false positives, DVD shrink and RarePacker.Multi.Generic
a couple months back. Here is the link: ZASS False Positives

Best regards,
Findley
Thanks for the very helpful information Findley. I'm sure you've seen that both of these services ( Virus Total or to Jotti's malware scan ) give differing results and their Kaspersky may be different from ZA's (odd).

Would you agree that if Kaspersky, AVG, NOD32 agree on the status, and the rest show different threats; I can say ZA gave a false alarm?

Thanks again,
Gramps

Last edited by gramps; December 23rd, 2009 at 09:37 AM. Reason: add two sites I failed to mention
Reply With Quote
  #6  
Old December 31st, 2009, 05:38 AM
findley's Avatar
findley findley is offline
Senior Member
 
Join Date: Aug 2007
Posts: 1,307
Default Re: info on RarePacker.Multi.Generic

Quote:
Originally Posted by gramps View Post
Thanks for the very helpful information Findley. I'm sure you've seen that both of these services ( Virus Total or to Jotti's malware scan ) give differing results and their Kaspersky may be different from ZA's (odd).

Would you agree that if Kaspersky, AVG, NOD32 agree on the status, and the rest show different threats; I can say ZA gave a false alarm?

Thanks again,
Gramps
Gramps,
The differing results for Virus Total and Jotti's reflect that these free file analyzing services for suspicious malware run different versions of av engines with Jotti's service ususally being behind, date-wise, the virus total services. But there can be comparative value in using both.

With the DVD Shrink files there are malware versions and clean versions. These files can be downloaded and installed from legitimate sources and downloaded and installed from dubious sources. It has been noted in previous threads on DVD Shrink that ZA has in the past flagged these files and users have reported them as false positives as noted in the threads referenced previously.

My habit and practice on any thing flagged by zone alarm or any other malware scanner is to run multiple online scanners to verify whether or not this is a threat or false positive. If there is any doubt, further investigation can be done by running hijackthis and posting the hijackthis log to the HJT forum at bleepingcomputer or spywarehammer or another malware removal forum where experts will evaluate and walk you through the running of malware removal tools, if necessary.
Findley
Reply With Quote
  #7  
Old November 22nd, 2009, 10:11 AM
atinalee atinalee is offline
Junior Member
 
Join Date: Jul 2006
Posts: 44
Default Re: info on RarePacker.Multi.Generic

Thanks I found out from the site with this program that it is not a trojan but the way they do their exe file. Zone alarm keeps telling me every day I have a trojan and every day I tell it to restore it. It is a real pain. I might look for a different program or uninstall it. Too much of a problem.
Thanks

Anita
Reply With Quote
  #8  
Old November 22nd, 2009, 10:49 AM
findley's Avatar
findley findley is offline
Senior Member
 
Join Date: Aug 2007
Posts: 1,307
Arrow Re: info on RarePacker.Multi.Generic

Quote:
Originally Posted by atinalee View Post
Thanks I found out from the site with this program that it is not a trojan but the way they do their exe file. Zone alarm keeps telling me every day I have a trojan and every day I tell it to restore it. It is a real pain. I might look for a different program or uninstall it. Too much of a problem.
Thanks

Anita
Anita,

In the advanced options of the antivirus section, have you tried adding the files to the Zone Alarm exception list so they are not scanned and identified as an issue?
hope this helps
Findley
Reply With Quote
  #9  
Old November 23rd, 2009, 07:24 AM
atinalee atinalee is offline
Junior Member
 
Join Date: Jul 2006
Posts: 44
Default Re: info on RarePacker.Multi.Generic

Thanks so much. I didnt know you could do this. This has solved my problem.

Anita
Reply With Quote
  #10  
Old November 24th, 2009, 05:03 AM
findley's Avatar
findley findley is offline
Senior Member
 
Join Date: Aug 2007
Posts: 1,307
Default Re: info on RarePacker.Multi.Generic

Quote:
Originally Posted by atinalee View Post
Thanks so much. I didnt know you could do this. This has solved my problem.

Anita
Glad to hear it and thanks for the feedback
Reply With Quote
Reply

Bookmarks


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off



All times are GMT -8. The time now is 12:28 PM.


Powered by vBulletin® Version 3.8.2
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
©2003-2010 Check Point Software Technologies Ltd. All Rights Reserved.