| View previous topic :: View next topic |
| Author |
Message |
HappyShiner
General
 Premium Member
 Joined: Jul 02, 2004 Posts: 7205 Location: Uk
|
Posted: Thu Jul 14, 2005 5:39 pm Post subject: False Positive? |
|
|
Hi,
One of my favourite programs is HostsMan, having just updated it to the new release HostMan 2.01 Antivir is going bananas and keeps badgering me to deny acces to or delete a pargticular file in HostsMan called hm.exe. It is a reputable program and has built up a good name for being so, proud of it's status of containing no spyware or viruses. Therefore, I was convinced this must be a false positive within Antivir. To check it out further I subjected to file with Jotti's online scanner and the report is as follows:
| Quote: | File: hm.exe
Status:
POSSIBLY INFECTED/MALWARE (Note: this file has been scanned before. Therefore, this file's scan results will not be stored in the database) (Note: this file was only flagged as malware by heuristic detection(s). This might be a false positive. Therefore, results of this scan will not be stored in the database)
MD5 21eb12f6cf40693c9095ce8feb10148f
Packers detected:
UPX
Scanner results
AntiVir
Found Heuristic/Trojan.PwdStealer (probable variant)
ArcaVir
Found nothing
Avast
Found nothing
AVG Antivirus
Found nothing
BitDefender
Found nothing
ClamAV
Found nothing
Dr.Web
Found nothing
F-Prot Antivirus
Found nothing
Fortinet
Found nothing
Kaspersky Anti-Virus
Found nothing
NOD32
Found nothing
Norman Virus Control
Found nothing
UNA
Found nothing
VBA32
Found nothing |
As I suspected, no other AV's detected the file as malware. Please advise.
HS _________________ [img]http://serve.dynasig.net/926.gif[/img]
DynaSig: Free Dynamic Forum Signatures
"Dogs are Running wild in the street...I just can't take it anymore!"
|
|
| Back to top |
|
 |
mav1976
Sergeant

 Joined: May 22, 2005 Posts: 116
|
Posted: Thu Jul 14, 2005 8:31 pm Post subject: |
|
|
Hi happyshiner,
how did you configured your Heuristic settings?
Send this file as an attachment to heuristik@antivir.de. This should be packed with WinZip or WinRar etc. Don't forget to give this attachment a password and tell it in your email. _________________ gruß mav
|
|
| Back to top |
|
 |
TopperID
Captain

 Joined: Oct 14, 2004 Posts: 375 Location: UK
|
Posted: Thu Jul 14, 2005 9:33 pm Post subject: |
|
|
HappyShiner,
This clearly looks like a false positive, so you should do as mav suggests above.
In the meantime though, there are a couple of things you can try. If it is the Guard finding this file you could try configuring the settings to reduce or switch off Heuristics. Alternatively, if this program has a process listed as running in Task Manager, you can enter the process in the Guard's 'filter' so that AntiVir will exclude it from realtime scanning.
You can also exclude the relevant file from demand scans with the main program; though in this case it will be the file you exclude and not the running process.
Let us know if the above works and also what H+BEDV have to say when you submit the file to them - they are usually quite quick to remedy this sort of thing.
|
|
| Back to top |
|
 |
HappyShiner
General
 Premium Member
 Joined: Jul 02, 2004 Posts: 7205 Location: Uk
|
|
| Back to top |
|
 |
TopperID
Captain

 Joined: Oct 14, 2004 Posts: 375 Location: UK
|
Posted: Thu Jul 14, 2005 11:20 pm Post subject: |
|
|
Good luck HappyShiner!
If I remember correctly, the default setting for the Guard is to have Win32 Heuristics disabled - so you should not feel too bad about switching it off, if you need to do that. 
|
|
| Back to top |
|
 |
HappyShiner
General
 Premium Member
 Joined: Jul 02, 2004 Posts: 7205 Location: Uk
|
|
| Back to top |
|
 |
HappyShiner
General
 Premium Member
 Joined: Jul 02, 2004 Posts: 7205 Location: Uk
|
Posted: Fri Jul 15, 2005 11:37 am Post subject: |
|
|
Hi there,
Wow, you were right about them being quick on the ball. I've got a reply from Stefan already:
| Quote: | Hi!
It is indeed a false positive. Strange enough, the program does process memory manipulation. I wonder why
a Hosts-file manager needs this piece of code?
Anyway, the heuristics & false positive will be fixed ASAP. Thanks for sending the file!
bye, Stefan Kurtzhals
|
I'm relieved that one of my favourite programs isn't bad and is going to get addressed in an AntiVir update.
But now I'm left with a new mystery. Do you think I ought to contact the authors of HostMan and ask them why memory manipulation is needed in the code?
Thanks for the help
Big Smiles
HS _________________ [img]http://serve.dynasig.net/926.gif[/img]
DynaSig: Free Dynamic Forum Signatures
"Dogs are Running wild in the street...I just can't take it anymore!"
|
|
| Back to top |
|
 |
TopperID
Captain

 Joined: Oct 14, 2004 Posts: 375 Location: UK
|
Posted: Fri Jul 15, 2005 12:04 pm Post subject: |
|
|
Good to hear H+BEDV are on the ball about this.
| Quote: | | But now I'm left with a new mystery. Do you think I ought to contact the authors of HostMan and ask them why memory manipulation is needed in the code? |
Well you can certainly ask them, but whether you get a satisfactory response is another matter; no harm in trying though for piece of mind. However if there was anything undesirable going on I would have expected the heuristics of some of the other scanners at Jotti's to have been triggered, which was not the case. So perhaps no need to worry too much!
|
|
| Back to top |
|
 |
HappyShiner
General
 Premium Member
 Joined: Jul 02, 2004 Posts: 7205 Location: Uk
|
|
| Back to top |
|
 |
mav1976
Sergeant

 Joined: May 22, 2005 Posts: 116
|
Posted: Fri Jul 15, 2005 3:21 pm Post subject: |
|
|
Hi,
good to hear that this false positive have been fixed so fast. _________________ gruß mav
|
|
| Back to top |
|
 |
HappyShiner
General
 Premium Member
 Joined: Jul 02, 2004 Posts: 7205 Location: Uk
|
|
| Back to top |
|
 |
|
|