| View previous topic :: View next topic |
| Author |
Message |
ChrisRLG
Security Expert Microsoft MVP
 Joined: Apr 14, 2004 Posts: 515 Location: UK
|
Posted: Tue Oct 31, 2006 7:54 pm Post subject: sproder.dll - false positive |
|
|
The attached file is being targetted by AVG7 with the latest definitions.
It is removing the file - which is a major part of a filter system used by my church computers - as such unless I kill AVG7 and resore that file we lose internet access.
It is obviously a false positive.
The software it is targetting is FilterPak from www.familyguardian.net
The file sporder.dll which is a MS file from the c:\windows\system folder (not system32)
Description : WinSock2 reorder service providers
version : 5.0.1641.1
Can someone let grisoft know please.
| Description: |
| Zipped copy of file c:windowssystemsprder.dll (NOT system32) |
|
 Download |
| Filename: |
sporder.zip |
| Filesize: |
2.3 KB |
| Downloaded: |
82 Time(s) |
_________________ MS MVP member since 2005
Matthew 7:7"Ask and it will be given to you; seek and you will find; knock and a door will be opened to you."
|
|
| Back to top |
|
 |
nosirrah
Security Expert Special Response Team
 Joined: Apr 19, 2006 Posts: 6301 Location: USA
|
Posted: Tue Oct 31, 2006 8:18 pm Post subject: |
|
|
False positive reported .
I will check in again tonight and tomorrow if need be .
|
|
| Back to top |
|
 |
ChrisRLG
Security Expert Microsoft MVP
 Joined: Apr 14, 2004 Posts: 515 Location: UK
|
|
| Back to top |
|
 |
nosirrah
Security Expert Special Response Team
 Joined: Apr 19, 2006 Posts: 6301 Location: USA
|
|
| Back to top |
|
 |
ChrisRLG
Security Expert Microsoft MVP
 Joined: Apr 14, 2004 Posts: 515 Location: UK
|
Posted: Tue Oct 31, 2006 9:00 pm Post subject: |
|
|
This is a bummer.
With AVG installed I have no internet access - so I cannot even update the def files when they are updated tp fix this
If I remove the filter software then the computers are wide open as they are used like those at a library - by all and sundry - but we can then use the internet to get the updates.
Think I have no choice - I remove the filter software till AVG have its update done. _________________ MS MVP member since 2005
Matthew 7:7"Ask and it will be given to you; seek and you will find; knock and a door will be opened to you."
|
|
| Back to top |
|
 |
Tibilicus
Corporal

 Joined: Sep 10, 2006 Posts: 60 Location: USA
|
Posted: Tue Oct 31, 2006 10:36 pm Post subject: |
|
|
Picked it up tonight aswell. MIne was found in the system 32 folder in the panda active scan files. Im guessing I should jsut leave it in quarantine for now although it doesnt mean anythign being a FP.
Tib
|
|
| Back to top |
|
 |
Tibilicus
Corporal

 Joined: Sep 10, 2006 Posts: 60 Location: USA
|
Posted: Tue Oct 31, 2006 10:38 pm Post subject: |
|
|
And surley this can't be a positive due to its loaction in the active scan folder? BTW being picked up on AVG free 7.5 incase you didnt know.
Tib
|
|
| Back to top |
|
 |
ChrisRLG
Security Expert Microsoft MVP
 Joined: Apr 14, 2004 Posts: 515 Location: UK
|
Posted: Tue Oct 31, 2006 10:54 pm Post subject: |
|
|
The only time I know it to be a problem is if you are running a net filtering program such as FilterPak which uses that MS program.
If you do - the best way out I have found so far is to :-
1. uninstall AVG7 - (yep that bad)
2. put back the removed file
3. then uninstall filterpak (FamilyGardian).
4. re-install AVG7
The reason is while AVG is active that file is killed every time it is called - and you need that file for the filterpak to allow you to get to the internet.
You need to get to the internet to uninstall filterpak - so AVG has to go first for that reason. _________________ MS MVP member since 2005
Matthew 7:7"Ask and it will be given to you; seek and you will find; knock and a door will be opened to you."
|
|
| Back to top |
|
 |
nosirrah
Security Expert Special Response Team
 Joined: Apr 19, 2006 Posts: 6301 Location: USA
|
Posted: Wed Nov 01, 2006 4:09 am Post subject: |
|
|
It is still being flagged as malware .
I just gave them another poke .
This time I also linked directly to this topic .
Last edited by nosirrah on Wed Nov 01, 2006 6:59 pm, edited 1 time in total |
|
| Back to top |
|
 |
nosirrah
Security Expert Special Response Team
 Joined: Apr 19, 2006 Posts: 6301 Location: USA
|
Posted: Wed Nov 01, 2006 3:19 pm Post subject: |
|
|
STATUS: SCANNINGFile "sporder.dll" received on 11.01.2006 at 16:16:05 (CET) is being scanned by VirusTotal in this moment. Results will be shown as they're generated.
AVG 386 11.01.2006 no virus found
You are good to go . 
|
|
| Back to top |
|
 |
ChrisRLG
Security Expert Microsoft MVP
 Joined: Apr 14, 2004 Posts: 515 Location: UK
|
Posted: Wed Nov 01, 2006 3:30 pm Post subject: |
|
|
good news - I can now try to put the systems back together - will probably still need to reinstall avg and filterpak - pains. _________________ MS MVP member since 2005
Matthew 7:7"Ask and it will be given to you; seek and you will find; knock and a door will be opened to you."
|
|
| Back to top |
|
 |
|
|