CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

[DONE]sproder.dll - false positive

 
Post new topic   Reply to topic       All -> FavForums -> Grisoft AVG [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
ChrisRLG

Security Expert
Microsoft MVP

Joined: Apr 14, 2004
Posts: 515
Location: UK
MVP Security Experts

PostPosted: Tue Oct 31, 2006 7:54 pm    Post subject: sproder.dll - false positive
Reply with quote

The attached file is being targetted by AVG7 with the latest definitions.

It is removing the file - which is a major part of a filter system used by my church computers - as such unless I kill AVG7 and resore that file we lose internet access.

It is obviously a false positive.

The software it is targetting is FilterPak from www.familyguardian.net

The file sporder.dll which is a MS file from the c:\windows\system folder (not system32)

Description : WinSock2 reorder service providers

version : 5.0.1641.1

Can someone let grisoft know please.




sporder.zip
 Description:
Zipped copy of file c:windowssystemsprder.dll (NOT system32)

Download
 Filename:  sporder.zip
 Filesize:  2.3 KB
 Downloaded:  82 Time(s)


_________________
MS MVP member since 2005
Matthew 7:7"Ask and it will be given to you; seek and you will find; knock and a door will be opened to you."
Back to top
View users profile Send private message Visit posters website
nosirrah

Security Expert
Special Response Team

Joined: Apr 19, 2006
Posts: 6301
Location: USA
MIRT MVP Premium Rootkit Responders Security Experts SRT

PostPosted: Tue Oct 31, 2006 8:18 pm    Post subject:
Reply with quote

False positive reported .

I will check in again tonight and tomorrow if need be .

Back to top
View users profile Send private message Send email
ChrisRLG

Security Expert
Microsoft MVP

Joined: Apr 14, 2004
Posts: 515
Location: UK
MVP Security Experts

PostPosted: Tue Oct 31, 2006 8:26 pm    Post subject:
Reply with quote

Thanks Smile

At my church I am without most of my tools and email accounts - so needed your help Smile

You might even have got others with the same problem turning up Sad - if they are able to work out HOW to get internet active again Smile - needed all my knowledge to do that.

Regards.


_________________
MS MVP member since 2005
Matthew 7:7"Ask and it will be given to you; seek and you will find; knock and a door will be opened to you."
Back to top
View users profile Send private message Visit posters website
nosirrah

Security Expert
Special Response Team

Joined: Apr 19, 2006
Posts: 6301
Location: USA
MIRT MVP Premium Rootkit Responders Security Experts SRT

PostPosted: Tue Oct 31, 2006 8:39 pm    Post subject:
Reply with quote

ChrisRLG wrote:
Thanks Smile

At my church I am without most of my tools and email accounts - so needed your help Smile

You might even have got others with the same problem turning up Sad - if they are able to work out HOW to get internet active again Smile - needed all my knowledge to do that.

Regards.


Virustotal is saying that AVG is the only vendor with this as a positive .

I will submit it again tonight to see what happens .

I have a CD in my car with all of my tools , just in case . Wink

Back to top
View users profile Send private message Send email
ChrisRLG

Security Expert
Microsoft MVP

Joined: Apr 14, 2004
Posts: 515
Location: UK
MVP Security Experts

PostPosted: Tue Oct 31, 2006 9:00 pm    Post subject:
Reply with quote

This is a bummer.

With AVG installed I have no internet access - so I cannot even update the def files when they are updated tp fix this Sad

If I remove the filter software then the computers are wide open as they are used like those at a library - by all and sundry - but we can then use the internet to get the updates.

Think I have no choice - I remove the filter software till AVG have its update done.


_________________
MS MVP member since 2005
Matthew 7:7"Ask and it will be given to you; seek and you will find; knock and a door will be opened to you."
Back to top
View users profile Send private message Visit posters website
Tibilicus

Corporal
Corporal


Joined: Sep 10, 2006
Posts: 60
Location: USA

PostPosted: Tue Oct 31, 2006 10:36 pm    Post subject:
Reply with quote

Picked it up tonight aswell. MIne was found in the system 32 folder in the panda active scan files. Im guessing I should jsut leave it in quarantine for now although it doesnt mean anythign being a FP.

Tib

Back to top
View users profile Send private message
Tibilicus

Corporal
Corporal


Joined: Sep 10, 2006
Posts: 60
Location: USA

PostPosted: Tue Oct 31, 2006 10:38 pm    Post subject:
Reply with quote

And surley this can't be a positive due to its loaction in the active scan folder? BTW being picked up on AVG free 7.5 incase you didnt know.

Tib

Back to top
View users profile Send private message
ChrisRLG

Security Expert
Microsoft MVP

Joined: Apr 14, 2004
Posts: 515
Location: UK
MVP Security Experts

PostPosted: Tue Oct 31, 2006 10:54 pm    Post subject:
Reply with quote

The only time I know it to be a problem is if you are running a net filtering program such as FilterPak which uses that MS program.

If you do - the best way out I have found so far is to :-

1. uninstall AVG7 - (yep that bad)
2. put back the removed file
3. then uninstall filterpak (FamilyGardian).
4. re-install AVG7

The reason is while AVG is active that file is killed every time it is called - and you need that file for the filterpak to allow you to get to the internet.
You need to get to the internet to uninstall filterpak Sad - so AVG has to go first for that reason.


_________________
MS MVP member since 2005
Matthew 7:7"Ask and it will be given to you; seek and you will find; knock and a door will be opened to you."
Back to top
View users profile Send private message Visit posters website
nosirrah

Security Expert
Special Response Team

Joined: Apr 19, 2006
Posts: 6301
Location: USA
MIRT MVP Premium Rootkit Responders Security Experts SRT

PostPosted: Wed Nov 01, 2006 4:09 am    Post subject:
Reply with quote

It is still being flagged as malware .

I just gave them another poke .

This time I also linked directly to this topic .



Last edited by nosirrah on Wed Nov 01, 2006 6:59 pm, edited 1 time in total
Back to top
View users profile Send private message Send email
nosirrah

Security Expert
Special Response Team

Joined: Apr 19, 2006
Posts: 6301
Location: USA
MIRT MVP Premium Rootkit Responders Security Experts SRT

PostPosted: Wed Nov 01, 2006 3:19 pm    Post subject:
Reply with quote

STATUS: SCANNINGFile "sporder.dll" received on 11.01.2006 at 16:16:05 (CET) is being scanned by VirusTotal in this moment. Results will be shown as they're generated.


AVG 386 11.01.2006 no virus found

You are good to go . Thumbs Up

Back to top
View users profile Send private message Send email
ChrisRLG

Security Expert
Microsoft MVP

Joined: Apr 14, 2004
Posts: 515
Location: UK
MVP Security Experts

PostPosted: Wed Nov 01, 2006 3:30 pm    Post subject:
Reply with quote

good news - I can now try to put the systems back together - will probably still need to reinstall avg and filterpak - pains.


_________________
MS MVP member since 2005
Matthew 7:7"Ask and it will be given to you; seek and you will find; knock and a door will be opened to you."
Back to top
View users profile Send private message Visit posters website
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Grisoft AVG All times are GMT
Page 1 of 1

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer