CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

False Positive?

 
Post new topic   Reply to topic       All -> FavForums -> AntiVir Personal Edition Classic [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
HappyShiner

General
General
Premium Member

Joined: Jul 02, 2004
Posts: 7205
Location: Uk
Premium Team F@H

PostPosted: Thu Jul 14, 2005 5:39 pm    Post subject: False Positive?
Reply with quote

Hi,

One of my favourite programs is HostsMan, having just updated it to the new release HostMan 2.01 Antivir is going bananas and keeps badgering me to deny acces to or delete a pargticular file in HostsMan called hm.exe. It is a reputable program and has built up a good name for being so, proud of it's status of containing no spyware or viruses. Therefore, I was convinced this must be a false positive within Antivir. To check it out further I subjected to file with Jotti's online scanner and the report is as follows:

Quote:
File: hm.exe
Status:
POSSIBLY INFECTED/MALWARE (Note: this file has been scanned before. Therefore, this file's scan results will not be stored in the database) (Note: this file was only flagged as malware by heuristic detection(s). This might be a false positive. Therefore, results of this scan will not be stored in the database)
MD5 21eb12f6cf40693c9095ce8feb10148f
Packers detected:
UPX
Scanner results
AntiVir
Found Heuristic/Trojan.PwdStealer (probable variant)
ArcaVir
Found nothing
Avast
Found nothing
AVG Antivirus
Found nothing
BitDefender
Found nothing
ClamAV
Found nothing
Dr.Web
Found nothing
F-Prot Antivirus
Found nothing
Fortinet
Found nothing
Kaspersky Anti-Virus
Found nothing
NOD32
Found nothing
Norman Virus Control
Found nothing
UNA
Found nothing
VBA32
Found nothing


As I suspected, no other AV's detected the file as malware. Please advise.

HS


_________________
[img]http://serve.dynasig.net/926.gif[/img]
DynaSig: Free Dynamic Forum Signatures

"Dogs are Running wild in the street...I just can't take it anymore!"
Back to top
View users profile Send private message
mav1976

Sergeant
Sergeant


Joined: May 22, 2005
Posts: 116


PostPosted: Thu Jul 14, 2005 8:31 pm    Post subject:
Reply with quote

Hi happyshiner,

how did you configured your Heuristic settings?

Send this file as an attachment to heuristik@antivir.de. This should be packed with WinZip or WinRar etc. Don't forget to give this attachment a password and tell it in your email.


_________________
gruß mav
Back to top
View users profile Send private message
TopperID

Captain
Captain


Joined: Oct 14, 2004
Posts: 375
Location: UK

PostPosted: Thu Jul 14, 2005 9:33 pm    Post subject:
Reply with quote

HappyShiner,

This clearly looks like a false positive, so you should do as mav suggests above.

In the meantime though, there are a couple of things you can try. If it is the Guard finding this file you could try configuring the settings to reduce or switch off Heuristics. Alternatively, if this program has a process listed as running in Task Manager, you can enter the process in the Guard's 'filter' so that AntiVir will exclude it from realtime scanning.

You can also exclude the relevant file from demand scans with the main program; though in this case it will be the file you exclude and not the running process.

Let us know if the above works and also what H+BEDV have to say when you submit the file to them - they are usually quite quick to remedy this sort of thing.

Back to top
View users profile Send private message
HappyShiner

General
General
Premium Member

Joined: Jul 02, 2004
Posts: 7205
Location: Uk
Premium Team F@H

PostPosted: Thu Jul 14, 2005 10:28 pm    Post subject:
Reply with quote

Hi there and thanks for all the advice Smile

It's not the real time scanner that's the issue by the way, rather the guard. It pops up over and over waring me of the file, but selecting 'allow file' never seemed to make a difference so in the end I had to select 'Deny Access'. In the event Antivir didn't like it and it crashed twice and twice I was left with no other option then to cold boot as everything had froze solid.

I'll try fiddling with the settings as you've suggested and see if that helps, I'll also get that file zipped off to the email you've supplied.

Incidentally my Heuristics were set to medium (although I may switch that to low for the time being).

I'll get back to you on whether that works and whether I'm then able to run HostsMan. Also I'll let you know about the reply to my email Smile

Big Smiles

HS


_________________
[img]http://serve.dynasig.net/926.gif[/img]
DynaSig: Free Dynamic Forum Signatures

"Dogs are Running wild in the street...I just can't take it anymore!"
Back to top
View users profile Send private message
TopperID

Captain
Captain


Joined: Oct 14, 2004
Posts: 375
Location: UK

PostPosted: Thu Jul 14, 2005 11:20 pm    Post subject:
Reply with quote

Good luck HappyShiner!

If I remember correctly, the default setting for the Guard is to have Win32 Heuristics disabled - so you should not feel too bad about switching it off, if you need to do that. Smile

Back to top
View users profile Send private message
HappyShiner

General
General
Premium Member

Joined: Jul 02, 2004
Posts: 7205
Location: Uk
Premium Team F@H

PostPosted: Thu Jul 14, 2005 11:27 pm    Post subject:
Reply with quote

Hi there,


Ahh, I didn't know that, I'll do that right now. FYI I've also zipped the file and sent it off to Antivir Smile

Big Smiles

HS


_________________
[img]http://serve.dynasig.net/926.gif[/img]
DynaSig: Free Dynamic Forum Signatures

"Dogs are Running wild in the street...I just can't take it anymore!"
Back to top
View users profile Send private message
HappyShiner

General
General
Premium Member

Joined: Jul 02, 2004
Posts: 7205
Location: Uk
Premium Team F@H

PostPosted: Fri Jul 15, 2005 11:37 am    Post subject:
Reply with quote

Hi there,

Wow, you were right about them being quick on the ball. I've got a reply from Stefan already:

Quote:
Hi!

It is indeed a false positive. Strange enough, the program does process memory manipulation. I wonder why
a Hosts-file manager needs this piece of code?

Anyway, the heuristics & false positive will be fixed ASAP. Thanks for sending the file!

bye, Stefan Kurtzhals


I'm relieved that one of my favourite programs isn't bad and is going to get addressed in an AntiVir update.

But now I'm left with a new mystery. Do you think I ought to contact the authors of HostMan and ask them why memory manipulation is needed in the code?

Thanks for the help Smile

Big Smiles

HS


_________________
[img]http://serve.dynasig.net/926.gif[/img]
DynaSig: Free Dynamic Forum Signatures

"Dogs are Running wild in the street...I just can't take it anymore!"
Back to top
View users profile Send private message
TopperID

Captain
Captain


Joined: Oct 14, 2004
Posts: 375
Location: UK

PostPosted: Fri Jul 15, 2005 12:04 pm    Post subject:
Reply with quote

Good to hear H+BEDV are on the ball about this.

Quote:
But now I'm left with a new mystery. Do you think I ought to contact the authors of HostMan and ask them why memory manipulation is needed in the code?

Well you can certainly ask them, but whether you get a satisfactory response is another matter; no harm in trying though for piece of mind. However if there was anything undesirable going on I would have expected the heuristics of some of the other scanners at Jotti's to have been triggered, which was not the case. So perhaps no need to worry too much!

Back to top
View users profile Send private message
HappyShiner

General
General
Premium Member

Joined: Jul 02, 2004
Posts: 7205
Location: Uk
Premium Team F@H

PostPosted: Fri Jul 15, 2005 1:11 pm    Post subject:
Reply with quote

Hi there,

I suppose it's more curiosity rather then fear of any problem Smile

But I'm happy now anyway and everything has been resolved as far as I'm concerned Smile

Big Smiles

HS


_________________
[img]http://serve.dynasig.net/926.gif[/img]
DynaSig: Free Dynamic Forum Signatures

"Dogs are Running wild in the street...I just can't take it anymore!"
Back to top
View users profile Send private message
mav1976

Sergeant
Sergeant


Joined: May 22, 2005
Posts: 116


PostPosted: Fri Jul 15, 2005 3:21 pm    Post subject:
Reply with quote

Hi,

good to hear that this false positive have been fixed so fast.


_________________
gruß mav
Back to top
View users profile Send private message
HappyShiner

General
General
Premium Member

Joined: Jul 02, 2004
Posts: 7205
Location: Uk
Premium Team F@H

PostPosted: Fri Jul 15, 2005 4:33 pm    Post subject:
Reply with quote

Thanks Mav,

and today's Antivir update has fixed the issue Smile

Big Smiles

HS


_________________
[img]http://serve.dynasig.net/926.gif[/img]
DynaSig: Free Dynamic Forum Signatures

"Dogs are Running wild in the street...I just can't take it anymore!"
Back to top
View users profile Send private message
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> AntiVir Personal Edition Classic All times are GMT
Page 1 of 1

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer