Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » FP with Trojan Hunter?
Search Topic:
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
Virtualized rootkits - Part 1 »
« Why does Windows Defender Get such a Bad Rep?  
AuthorAll Replies


sammysnake
Never Forget 911
Premium
join:2002-01-19
Salt Lake City, UT
·Qwest.net
·Comcast Formerly ..

reply to MagnusM
Re: FP with Trojan Hunter?

Now I get this when I do a full scan with the latest updated defs:

Registry scan
No suspicious entries found
Inifile scan
No suspicious entries found
Port scan
No suspicious open ports found
Memory scan
No trojans found in memory
File scan
Error: Error while scanning C:\DELL\MEDIAEXE\PXCPYI64.EXE: Unknown machine type: 0x200 (C:\DELL\MEDIAEXE\PXCPYI64.EXE)
Error: Error while scanning C:\DELL\MEDIAEXE\PXHELP64.SYS: Unknown machine type: 0x200 (C:\DELL\MEDIAEXE\PXHELP64.SYS)
Error: Error while scanning C:\DELL\MEDIAEXE\PXINSI64.EXE: Unknown machine type: 0x200 (C:\DELL\MEDIAEXE\PXINSI64.EXE)
Error: Error while scanning C:\DELL\PXCPYI64.EXE: Unknown machine type: 0x200 (C:\DELL\PXCPYI64.EXE)
Error: Error while scanning C:\DELL\PXHELP64.SYS: Unknown machine type: 0x200 (C:\DELL\PXHELP64.SYS)
Error: Error while scanning C:\DELL\PXINSI64.EXE: Unknown machine type: 0x200 (C:\DELL\PXINSI64.EXE)
Error: Error while scanning C:\I386\PMSPL.DLL: This is not a PE format
Error: Error while scanning C:\I386\pxcpyi64.exe: Unknown machine type: 0x200 (C:\I386\pxcpyi64.exe)
Error: Error while scanning C:\I386\pxinsi64.exe: Unknown machine type: 0x200 (C:\I386\pxinsi64.exe)
Error: Error while scanning C:\WINDOWS\SYSTEM32\PMSPL.DLL: This is not a PE format
Error: Error while scanning C:\WINDOWS\SYSTEM32\pxcpyi64.exe: Unknown machine type: 0x200 (C:\WINDOWS\SYSTEM32\pxcpyi64.exe)
Error: Error while scanning C:\WINDOWS\SYSTEM32\pxinsi64.exe: Unknown machine type: 0x200 (C:\WINDOWS\SYSTEM32\pxinsi64.exe)
No trojan files found



Mind you.... the files listed above have always been on this machine and have never been flagged before.

Sammy


sammysnake
Never Forget 911
Premium
join:2002-01-19
Salt Lake City, UT

1 edit
 reply to MagnusM
Thank you Magnus!

MagnusM
Premium
join:2001-07-07

reply to sammysnake
Thanks, file received and analyzed. This is indeed a false positive and I've uploaded corrected signatures. Run LiveUpdate and this file should no longer be detected on your next scan.
--
Mischel Internet Security
http://www.misec.net
Forums » Up and Running » Security » SecurityVirtualized rootkits - Part 1 »
« Why does Windows Defender Get such a Bad Rep?  


Monday, 14-Dec 16:23:19 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.
page compression OFF
Most commented news this week
· [94] Google To Sell Phone Directly To Consumers
· [61] TiVO Tries To Figure Out Where It Fits
· [47] Faster Verizon DSL Service Will Burn Your House Down
· [41] NY Times: AT&T 3G Network Is Secretly Awesome
· [15] Rural Broadband User? You're Screwed
· [13] Sweden First To Get LTE Service
· [1] Monday Morning Links
Most people now reading
· Official Mediacom Email Discussion Thread [Mediacom]
· personal check etiquette [General Questions]
· Ashen Verdict Rep farming guide (ICC 10) [World of Warcraft]
· [Rant] BUG in MY FOOD, After i ate 90% of it.. [Rants, Raves, and Praise]
· Windows 7 boot manager editing questions [Microsoft Help]
· IMG 1.7 (IMG Updates and Discussion) [Verizon FIOS TV]
· Privacy concerns: dump Google and move to Bing [Security]
· Most Hated 5-man now. [World of Warcraft]
· So independants will be out of business in..........? [Canadian Broadband]
· Exalted with Ashen Verdict before the end of the week [World of Warcraft]