| View previous topic :: View next topic |
| Author |
Message |
Toblerone
Lieutenant
 Premium Member
 Joined: Mar 31, 2006 Posts: 290 Location: Spain
|
Posted: Mon Nov 13, 2006 8:22 pm Post subject: [Virus base 268.14.4/532]: False positive [FIXED] |
|
|
FYI, today I have updated my AVG Free 7.5.430 with the virus base 268.14.4/532 and I have received the following alert:
| Code: | Threat Detected!
While opening file: ...\...\WMC.EXE
Trojan Horse Generic2.ENK |
The file in question (WMC.EXE) is the main executable of an old game (Wild Metal Country, 1999), that have not been accesed in the last couple of years.
To be sure, I have made a binary comp with the file in the CD game and they are the same, so I suspect a false positive here. _________________ Toblerone, the chocolate with teeth
Last edited by Toblerone on Thu Nov 16, 2006 10:01 am, edited 1 time in total |
|
| Back to top |
|
 |
PCBruiser
SRT Team Lead
 Forums Admin
 Joined: May 11, 2005 Posts: 11723
|
Posted: Mon Nov 13, 2006 8:51 pm Post subject: |
|
|
Given that you were able to do a direct check with the original, I think you are quite safe assuming that whatever AVG is seeing is a false positive.
I had a similar false positive with one of the updates of a couple of weeks ago that identified a known good program as a possible virus (I forget which one). Malware is morphing so quickly these days that antimalware developers have to really tighten up and move fast to keep up - hourly sometimes. That can lead to issues like this pretty easily. _________________ Don't read? Can't learn!
|
|
| Back to top |
|
 |
dp
Microsoft MVP AVG Host

 Joined: Mar 12, 2002 Posts: 416
|
Posted: Tue Nov 14, 2006 8:57 am Post subject: |
|
|
Yeah, sure sounds like a false positive. ZIP it up into a password protected zip and send it off to them so they can analyze it and adjust definitions as needed.
'infected' (w/o quotes) is generally a good password to use since it's recognized as the standard by most malware vendors.
Send it off to virus@grisoft.com or virus@grisoft.cz
Be sure to tell them in your email the ZIP password and your reasons why you believe it to be a f/p. _________________ Microsoft MVP Consumer Security, 2004-2008
|
|
| Back to top |
|
 |
Toblerone
Lieutenant
 Premium Member
 Joined: Mar 31, 2006 Posts: 290 Location: Spain
|
|
| Back to top |
|
 |
Toblerone
Lieutenant
 Premium Member
 Joined: Mar 31, 2006 Posts: 290 Location: Spain
|
Posted: Wed Nov 15, 2006 12:42 pm Post subject: FP: Confirmed |
|
|
Yesterday I sent the file and just today AVG have confirmed that it is a False Positive that will be corrected in further updates.
Kudos to the AVG people for their blazing-fast support and a wonderful product!  _________________ Toblerone, the chocolate with teeth
|
|
| Back to top |
|
 |
Toblerone
Lieutenant
 Premium Member
 Joined: Mar 31, 2006 Posts: 290 Location: Spain
|
Posted: Thu Nov 16, 2006 10:03 am Post subject: |
|
|
The FP has been corrected in virus base 268.14.6/535
The guys at Grisoft are really fast fixing things.  _________________ Toblerone, the chocolate with teeth
|
|
| Back to top |
|
 |
dp
Microsoft MVP AVG Host

 Joined: Mar 12, 2002 Posts: 416
|
|
| Back to top |
|
 |
|
|