<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic False positive - Legitmate installer/game launcher &amp;quot;Generic.Ml&amp;quot; in VirusTotal</title>
    <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-legitmate-installer-game-launcher-quot-generic-ml/m-p/272907#M1106</link>
    <description>&lt;P&gt;&lt;A href="https://www.virustotal.com/gui/file/cb9643dd7796807339ad294842b905b5a7698b67b60ee1ef9d9eda769f2accee/detection" target="_blank"&gt;https://www.virustotal.com/gui/file/cb9643dd7796807339ad294842b905b5a7698b67b60ee1ef9d9eda769f2accee/detection&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"Generic.Ml"&lt;/P&gt;&lt;P&gt;Distribution URL is &lt;A href="http://cloud.quicksnooker.com/qsLaunch3.exe" target="_blank"&gt;http://cloud.quicksnooker.com/qsLaunch3.exe&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hi&lt;BR /&gt;&lt;BR /&gt;I am the author of this program - which is the legitimate launcher/installer for Quick Snooker - an on-line Snooker game, running for nearly 20 years and with 100,000+ installs.&lt;BR /&gt;&lt;BR /&gt;The summary on the (VirusTotal) 'behavior' tab is accurate - the program makes no attempt to disguise what is does.&lt;BR /&gt;It downloads a location from quicksnooker.com, and then downloads and unzip files from &lt;A href="http://cloud.quicksnooker.com" target="_blank"&gt;http://cloud.quicksnooker.com&lt;/A&gt; (our content delivery network hosted in the 'google cloud'.)&lt;BR /&gt;The files containing the main executable QuickSnooker.exe, and a set of resources (images, textures, sound and geometry files).&lt;BR /&gt;The program also creates a folder (%LocalAppdata%\qs8) , a desktop shortcut, and the appropriate registry keys to uninstall Quick Snooker program when requested.&lt;BR /&gt;&lt;BR /&gt;Of course it *looks* very Trojan like - but it is harmless and complies with industry standard clean guidelines.&lt;BR /&gt;&lt;BR /&gt;See our terms or help sections at &lt;A href="http://quicksnooker.com" target="_blank"&gt;http://quicksnooker.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please remove ASAP&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hopefully your "ML" will be smart about future versions ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks in advance&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Nick Axworthy&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 25 Jun 2019 13:49:15 GMT</pubDate>
    <dc:creator>quicksnooker</dc:creator>
    <dc:date>2019-06-25T13:49:15Z</dc:date>
    <item>
      <title>False positive - Legitmate installer/game launcher "Generic.Ml"</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-legitmate-installer-game-launcher-quot-generic-ml/m-p/272907#M1106</link>
      <description>&lt;P&gt;&lt;A href="https://www.virustotal.com/gui/file/cb9643dd7796807339ad294842b905b5a7698b67b60ee1ef9d9eda769f2accee/detection" target="_blank"&gt;https://www.virustotal.com/gui/file/cb9643dd7796807339ad294842b905b5a7698b67b60ee1ef9d9eda769f2accee/detection&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"Generic.Ml"&lt;/P&gt;&lt;P&gt;Distribution URL is &lt;A href="http://cloud.quicksnooker.com/qsLaunch3.exe" target="_blank"&gt;http://cloud.quicksnooker.com/qsLaunch3.exe&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hi&lt;BR /&gt;&lt;BR /&gt;I am the author of this program - which is the legitimate launcher/installer for Quick Snooker - an on-line Snooker game, running for nearly 20 years and with 100,000+ installs.&lt;BR /&gt;&lt;BR /&gt;The summary on the (VirusTotal) 'behavior' tab is accurate - the program makes no attempt to disguise what is does.&lt;BR /&gt;It downloads a location from quicksnooker.com, and then downloads and unzip files from &lt;A href="http://cloud.quicksnooker.com" target="_blank"&gt;http://cloud.quicksnooker.com&lt;/A&gt; (our content delivery network hosted in the 'google cloud'.)&lt;BR /&gt;The files containing the main executable QuickSnooker.exe, and a set of resources (images, textures, sound and geometry files).&lt;BR /&gt;The program also creates a folder (%LocalAppdata%\qs8) , a desktop shortcut, and the appropriate registry keys to uninstall Quick Snooker program when requested.&lt;BR /&gt;&lt;BR /&gt;Of course it *looks* very Trojan like - but it is harmless and complies with industry standard clean guidelines.&lt;BR /&gt;&lt;BR /&gt;See our terms or help sections at &lt;A href="http://quicksnooker.com" target="_blank"&gt;http://quicksnooker.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please remove ASAP&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hopefully your "ML" will be smart about future versions ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks in advance&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Nick Axworthy&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jun 2019 13:49:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/false-positive-legitmate-installer-game-launcher-quot-generic-ml/m-p/272907#M1106</guid>
      <dc:creator>quicksnooker</dc:creator>
      <dc:date>2019-06-25T13:49:15Z</dc:date>
    </item>
    <item>
      <title>Re: False positive - Legitmate installer/game launcher "Generic.Ml"</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/false-positive-legitmate-installer-game-launcher-quot-generic-ml/m-p/276360#M1118</link>
      <description>&lt;P&gt;I have entered this file for further analysis&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jul 2019 16:58:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/false-positive-legitmate-installer-game-launcher-quot-generic-ml/m-p/276360#M1118</guid>
      <dc:creator>dparris</dc:creator>
      <dc:date>2019-07-12T16:58:55Z</dc:date>
    </item>
  </channel>
</rss>

