<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: TotalVirus False-Positive  EZhelp in VirusTotal</title>
    <link>https://live.paloaltonetworks.com/t5/virustotal/totalvirus-false-positive-ezhelp/m-p/314228#M1368</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I heard back from our malware team, we have decided to keep this as malware based on their analysis.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best Regards,&lt;/P&gt;&lt;P&gt;Himani&lt;/P&gt;</description>
    <pubDate>Tue, 03 Mar 2020 17:56:07 GMT</pubDate>
    <dc:creator>hisingh</dc:creator>
    <dc:date>2020-03-03T17:56:07Z</dc:date>
    <item>
      <title>TotalVirus False-Positive  EZhelp</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/totalvirus-false-positive-ezhelp/m-p/313358#M1357</link>
      <description>&lt;P&gt;As of 2/27/2020&amp;nbsp; TotalVirus is reporting EZhelp.20.exe as &lt;SPAN class="individual-detection"&gt;Generic.ml&lt;/SPAN&gt;&amp;nbsp; for Palo Alto Networks&lt;/P&gt;&lt;P&gt;Please help.&lt;/P&gt;&lt;P&gt;I updated EZhelp20.exe to include the latest winvnc.exe released this week by ultravnc.com&amp;nbsp; version 1.2.3.0 updated to 1.2.4.0 for security and features update.&amp;nbsp; This small change is triggering a false positive.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;EZhelp is not a virus, malware, hacker tool or trojan and is not misleading in any way. Ezhelp does exactly what our users expect it to do and nothing more. It is a private helpdesk support program that uses ultravnc. Ezhelp is a portable program, that when ran by the user, puts its files in the user’s temp folder and it removes them when the user closes the program. The included files are SecureVNCPlugin.dsm, VNChooks.dll and winvnc.exe which can be found at the widely popular &lt;A href="http://www.uvnc.com" target="_blank"&gt;www.uvnc.com&lt;/A&gt; website. The included ultravnc.ini file increases security by preventing the user from accidentally allowing incoming connections into their own PC and only allows an outgoing secure encrypted connection to our helpdesk upon the user’s request. Those evaluating the software can look in the temp file and verify all of this. I am the author of the program and have been using it for two decades. Occasionally, EZhelp is updated to include the latest winvnc.exe from &lt;A href="http://www.utravnc.com" target="_blank"&gt;www.utravnc.com&lt;/A&gt; for its feature and security updates.&amp;nbsp; Compiled with the popular Autoit default settings using UPX compression to reduce the file size by 30%&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The virustotal link is for this detection is here &lt;A href="https://www.virustotal.com/gui/file/48bb201df975b6b34380a3a1805707b12cf55ee1f4e22a83de3c46c6445cbd4d/detection" target="_blank"&gt;https://www.virustotal.com/gui/file/48bb201df975b6b34380a3a1805707b12cf55ee1f4e22a83de3c46c6445cbd4d/detection&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;EZhelp20.exe&amp;nbsp; can be downloaded directly from here &lt;A href="http://ezhelp.github.io/software/EZhelp20.exe" target="_blank"&gt;http://ezhelp.github.io/software/EZhelp20.exe&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you in advance&lt;/P&gt;&lt;P&gt;CPC&lt;/P&gt;</description>
      <pubDate>Thu, 27 Feb 2020 18:36:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/totalvirus-false-positive-ezhelp/m-p/313358#M1357</guid>
      <dc:creator>CantrellPC</dc:creator>
      <dc:date>2020-02-27T18:36:48Z</dc:date>
    </item>
    <item>
      <title>Re: TotalVirus False-Positive  EZhelp</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/totalvirus-false-positive-ezhelp/m-p/313981#M1362</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have submitted the re-check request based on the hash. We could not download the file because the file was not zipped by a password, and will be blocked by the firewalls.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best&lt;/P&gt;&lt;P&gt;Himani&lt;/P&gt;</description>
      <pubDate>Mon, 02 Mar 2020 18:56:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/totalvirus-false-positive-ezhelp/m-p/313981#M1362</guid>
      <dc:creator>hisingh</dc:creator>
      <dc:date>2020-03-02T18:56:35Z</dc:date>
    </item>
    <item>
      <title>Re: TotalVirus False-Positive  EZhelp</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/totalvirus-false-positive-ezhelp/m-p/314228#M1368</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I heard back from our malware team, we have decided to keep this as malware based on their analysis.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best Regards,&lt;/P&gt;&lt;P&gt;Himani&lt;/P&gt;</description>
      <pubDate>Tue, 03 Mar 2020 17:56:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/totalvirus-false-positive-ezhelp/m-p/314228#M1368</guid>
      <dc:creator>hisingh</dc:creator>
      <dc:date>2020-03-03T17:56:07Z</dc:date>
    </item>
    <item>
      <title>Re: TotalVirus False-Positive  EZhelp</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/totalvirus-false-positive-ezhelp/m-p/314236#M1370</link>
      <description>&lt;P&gt;Thanks for your effort.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Who and how do I contact someone to correct this?&lt;/P&gt;&lt;P&gt;I can review the source code with them line by line if needed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The program does exactly what our clients expect it to do and nothing more.&amp;nbsp; It provides a secure reverse connection to only our helpdesk support using the popular winvnc. More secure then winvnc alone.&amp;nbsp; It does nothing more then it should and I not misleading in any way.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;CPC&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Mar 2020 18:05:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/totalvirus-false-positive-ezhelp/m-p/314236#M1370</guid>
      <dc:creator>CantrellPC</dc:creator>
      <dc:date>2020-03-03T18:05:53Z</dc:date>
    </item>
    <item>
      <title>Re: TotalVirus False-Positive  EZhelp</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/totalvirus-false-positive-ezhelp/m-p/314237#M1371</link>
      <description>&lt;P&gt;I will also add...&amp;nbsp; I few weeks ago when I submitted this, you did not consider it malware.&amp;nbsp; It then included winvnc version 1.2.3.0.&amp;nbsp; The only change in the program since is then it includes the updated opensoruce. winvnc.exe 1.2.4.0 from &lt;A href="http://www.ultravnc.com" target="_blank"&gt;www.ultravnc.com&lt;/A&gt; instead of 1.2.3.0&lt;/P&gt;</description>
      <pubDate>Tue, 03 Mar 2020 18:20:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/totalvirus-false-positive-ezhelp/m-p/314237#M1371</guid>
      <dc:creator>CantrellPC</dc:creator>
      <dc:date>2020-03-03T18:20:37Z</dc:date>
    </item>
    <item>
      <title>Re: TotalVirus False-Positive  EZhelp</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/totalvirus-false-positive-ezhelp/m-p/314284#M1372</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for the new info, l will check again and update.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best&lt;/P&gt;&lt;P&gt;Himani&lt;/P&gt;</description>
      <pubDate>Tue, 03 Mar 2020 23:26:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/totalvirus-false-positive-ezhelp/m-p/314284#M1372</guid>
      <dc:creator>hisingh</dc:creator>
      <dc:date>2020-03-03T23:26:16Z</dc:date>
    </item>
    <item>
      <title>Re: TotalVirus False-Positive  EZhelp</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/totalvirus-false-positive-ezhelp/m-p/314468#M1373</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you zip this file "EZhelp20.exe " with password "infected" and host somewhere we can download? Also, include the previous file that was not considered as malicious.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;kind regards&lt;/P&gt;</description>
      <pubDate>Wed, 04 Mar 2020 18:26:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/totalvirus-false-positive-ezhelp/m-p/314468#M1373</guid>
      <dc:creator>hisingh</dc:creator>
      <dc:date>2020-03-04T18:26:12Z</dc:date>
    </item>
    <item>
      <title>Re: TotalVirus False-Positive  EZhelp</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/totalvirus-false-positive-ezhelp/m-p/314518#M1375</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is a link for you.&amp;nbsp; This zip includes several other zip files including the current version and previous version and a readme file for more information..&lt;/P&gt;&lt;P&gt;&lt;A href="https://1drv.ms/u/s!AvUqD-bsZBOogaAbHgzQPF2_UBNZEQ?e=UrRa1G" target="_blank"&gt;https://1drv.ms/u/s!AvUqD-bsZBOogaAbHgzQPF2_UBNZEQ?e=UrRa1G&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If this information does not help get the program whitelisted.. please let me know how to escalate this issue ASAP.&amp;nbsp; Again, I can walk someone line by line through the source code step by step as needed. &amp;nbsp; I would think you have my email and phone number already via my profile if needed.&amp;nbsp; It is very important, for us to use this program to support remote workers, especially now with corvid 19 and more workers working remotely from their homes.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;P&gt;CPC&lt;/P&gt;</description>
      <pubDate>Wed, 04 Mar 2020 22:08:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/totalvirus-false-positive-ezhelp/m-p/314518#M1375</guid>
      <dc:creator>CantrellPC</dc:creator>
      <dc:date>2020-03-04T22:08:05Z</dc:date>
    </item>
    <item>
      <title>Re: TotalVirus False-Positive  EZhelp</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/totalvirus-false-positive-ezhelp/m-p/314938#M1377</link>
      <description>&lt;P&gt;Hello.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are rechecking this file on your request and I will update you.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 06 Mar 2020 16:05:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/totalvirus-false-positive-ezhelp/m-p/314938#M1377</guid>
      <dc:creator>hisingh</dc:creator>
      <dc:date>2020-03-06T16:05:20Z</dc:date>
    </item>
    <item>
      <title>Re: TotalVirus False-Positive  EZhelp</title>
      <link>https://live.paloaltonetworks.com/t5/virustotal/totalvirus-false-positive-ezhelp/m-p/315221#M1378</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The file is rechecked based on the information provided by you, we have marked this file as clean. I hope this helps.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Mar 2020 07:22:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/virustotal/totalvirus-false-positive-ezhelp/m-p/315221#M1378</guid>
      <dc:creator>hisingh</dc:creator>
      <dc:date>2020-03-09T07:22:49Z</dc:date>
    </item>
  </channel>
</rss>

