Two Plus Two Newer Archives

Two Plus Two Newer Archives (http://archives1.twoplustwo.com/index.php)
-   Computer Technical Help (http://archives1.twoplustwo.com/forumdisplay.php?f=50)
-   -   Please tell me these are false postives (http://archives1.twoplustwo.com/showthread.php?t=483055)

lawsoncb 08-21-2007 03:18 PM

Please tell me these are false postives
 
I just turn on my computer and got severel errors from AVG AV all from the setup.exe and ISSetup.dll.

This is a new computer(less then 2 weeks old) with Vista. No previous Virus/Spyware issues. This computer is used only for poker, e-wallets, bank, and email for these accounts.

This is the results from the 2nd scan.

http://img113.imageshack.us/img113/1111/virphotovp1.jpg

http://img113.imageshack.us/img113/1...hotovp1.th.jpg

The first scan came back with errors in the update manager folder and the errors from in the User/Chris. It healed the same number of errors as were in the update manager.

This scan was ran in a non administrator account and the Chris user is the administrator is why I think these were not healed.

I restarted and ran the 2 scan getting the above results in the non administrator account and only 6 threats were healed.

I am in the process of running a 3 scan in the in the Chris User(this user has not been opened in over a week). It is not complete but so far I have just getting the User/Chris errors.

Could these all be false postives?

lawsoncb 08-21-2007 03:22 PM

Re: Please tell me this are false postives
 
Here is a little larger image(Same as above)

http://img113.imageshack.us/img113/9...hotonp4.th.jpg

lawsoncb 08-21-2007 03:26 PM

Re: Please tell me this are false postives
 
3rd scan in the administrator account come back with the User/Chris threats but still did not heal them

running online Trend micro scan

psionic storm 08-21-2007 03:45 PM

Re: Please tell me this are false postives
 
that screenshot doesnt say much, post binaries for someone to look at.

im_not_1337 08-21-2007 03:47 PM

Re: Please tell me this are false postives
 
Looks like its a false positive and im pretty sure thats what it is. However, i guess it is remotely possible that it is legitimate malware, although i really doubt it.

Upload it to:
Jotti's online malware scanner:http://virusscan.jotti.org/
and Virustotal.com:http://www.virustotal.com/

Post the results and we'll take a look

lawsoncb 08-21-2007 03:48 PM

Re: Please tell me this are false postives
 
binaries?

lawsoncb 08-21-2007 04:08 PM

Re: Please tell me this are false postives
 
[ QUOTE ]
Looks like its a false positive and im pretty sure thats what it is. However, i guess it is remotely possible that it is legitimate malware, although i really doubt it.

Upload it to:
Jotti's online malware scanner:http://virusscan.jotti.org/
and Virustotal.com:http://www.virustotal.com/

Post the results and we'll take a look

[/ QUOTE ]

Thanks,

Any way to upload the files that were healed that are in the Virus Vault

lawsoncb 08-21-2007 05:34 PM

Re: Please tell me this are false postives
 
[ QUOTE ]
Looks like its a false positive and im pretty sure thats what it is. However, i guess it is remotely possible that it is legitimate malware, although i really doubt it.

Upload it to:
Jotti's online malware scanner:http://virusscan.jotti.org/
and Virustotal.com:http://www.virustotal.com/

Post the results and we'll take a look

[/ QUOTE ]

I tried these but were unable to get them to work.

virusscan.jotti- said uploading for 10 mins and then went to server busy pleas try again later.

virustotal- tried uploading for about 5 mins and said the files were to big

I am only able to upload the files that were not healed. The User/Chris files.

I scanned the followinfg folders with Kaspersky Online Scan and all came up clean.
dell\drivers
User\Chris
Program Files\InstallShield Installation Information (this is from the first scan that I do no have the screenshot from)

UbinTook 08-21-2007 06:16 PM

Re: Please tell me this are false postives
 
update all your virus definitions, retstart the computer in safemode and rescan and see what appears.

lawsoncb 08-21-2007 09:42 PM

Re: Please tell me this are false postives
 
[ QUOTE ]
update all your virus definitions, retstart the computer in safemode and rescan and see what appears.

[/ QUOTE ]

Found all the same threats in C:User\Chris as above. These were still not cleaned, deleted, or moved to the vault.


All times are GMT -4. The time now is 11:43 PM.

Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2024, vBulletin Solutions Inc.