CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

[Virus base 268.14.4/532]: False positive [FIXED]

 
Post new topic   Reply to topic       All -> FavForums -> Grisoft AVG [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
Toblerone

Lieutenant
Lieutenant
Premium Member

Joined: Mar 31, 2006
Posts: 290
Location: Spain
Premium

PostPosted: Mon Nov 13, 2006 8:22 pm    Post subject: [Virus base 268.14.4/532]: False positive [FIXED]
Reply with quote

FYI, today I have updated my AVG Free 7.5.430 with the virus base 268.14.4/532 and I have received the following alert:

Code:
Threat Detected!
While opening file: ...\...\WMC.EXE
Trojan Horse Generic2.ENK


The file in question (WMC.EXE) is the main executable of an old game (Wild Metal Country, 1999), that have not been accesed in the last couple of years.

To be sure, I have made a binary comp with the file in the CD game and they are the same, so I suspect a false positive here.


_________________
Toblerone, the chocolate with teeth


Last edited by Toblerone on Thu Nov 16, 2006 10:01 am, edited 1 time in total
Back to top
View users profile Send private message
PCBruiser

SRT Team Lead
SRT Team Lead
Forums Admin

Joined: May 11, 2005
Posts: 11723

1st Responder Mentors 1st Responders Forums Admin MIRT Moderators Premium Rootkit Experts Security Experts SRT Team CC Committee

PostPosted: Mon Nov 13, 2006 8:51 pm    Post subject:
Reply with quote

Given that you were able to do a direct check with the original, I think you are quite safe assuming that whatever AVG is seeing is a false positive.

I had a similar false positive with one of the updates of a couple of weeks ago that identified a known good program as a possible virus (I forget which one). Malware is morphing so quickly these days that antimalware developers have to really tighten up and move fast to keep up - hourly sometimes. That can lead to issues like this pretty easily.


_________________
Don't read? Can't learn!
Back to top
View users profile Send private message
dp

Microsoft MVP
AVG Host
AVG Host

Joined: Mar 12, 2002
Posts: 416

MVP Premium

PostPosted: Tue Nov 14, 2006 8:57 am    Post subject:
Reply with quote

Yeah, sure sounds like a false positive. ZIP it up into a password protected zip and send it off to them so they can analyze it and adjust definitions as needed.
'infected' (w/o quotes) is generally a good password to use since it's recognized as the standard by most malware vendors.
Send it off to virus@grisoft.com or virus@grisoft.cz

Be sure to tell them in your email the ZIP password and your reasons why you believe it to be a f/p.


_________________
Microsoft MVP Consumer Security, 2004-2008
Back to top
View users profile Send private message Visit posters website
Toblerone

Lieutenant
Lieutenant
Premium Member

Joined: Mar 31, 2006
Posts: 290
Location: Spain
Premium

PostPosted: Tue Nov 14, 2006 11:06 am    Post subject:
Reply with quote

Hi, PCBruiser and dp.

Thanks for the advice and the Grisoft email addresses (BTW, shouldn't they be obfuscated, to avoid the spammers hammering them?) Wink

Temporally I have "fixed" the issue by renaming the WMC.EXE to WMC.XEX Razz

Just now I have the email disabled -it seems that my ISP is making maintenance- but I will send the file as soon I get the servers back (late this night or tomorrow, I hope).


_________________
Toblerone, the chocolate with teeth
Back to top
View users profile Send private message
Toblerone

Lieutenant
Lieutenant
Premium Member

Joined: Mar 31, 2006
Posts: 290
Location: Spain
Premium

PostPosted: Wed Nov 15, 2006 12:42 pm    Post subject: FP: Confirmed
Reply with quote

Yesterday I sent the file and just today AVG have confirmed that it is a False Positive that will be corrected in further updates.

Kudos to the AVG people for their blazing-fast support and a wonderful product! Thumbs Up


_________________
Toblerone, the chocolate with teeth
Back to top
View users profile Send private message
Toblerone

Lieutenant
Lieutenant
Premium Member

Joined: Mar 31, 2006
Posts: 290
Location: Spain
Premium

PostPosted: Thu Nov 16, 2006 10:03 am    Post subject:
Reply with quote

The FP has been corrected in virus base 268.14.6/535

The guys at Grisoft are really fast fixing things. Smile


_________________
Toblerone, the chocolate with teeth
Back to top
View users profile Send private message
dp

Microsoft MVP
AVG Host
AVG Host

Joined: Mar 12, 2002
Posts: 416

MVP Premium

PostPosted: Thu Nov 16, 2006 8:54 pm    Post subject:
Reply with quote

Toblerone wrote:
The FP has been corrected in virus base 268.14.6/535

The guys at Grisoft are really fast fixing things. Smile
Thanks for that feedback and thank you for submitting the file to them so they could address it. Smile


_________________
Microsoft MVP Consumer Security, 2004-2008
Back to top
View users profile Send private message Visit posters website
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Grisoft AVG All times are GMT
Page 1 of 1

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer