  CalamityJane Premium,VIP,MVM join:2002-08-27 Eustis, FL
edit: March 19th, @09:47PM
| reply to Mikey Re: Win32 backdoor D
said by Mikey :
Suggestions? 1. Will have to wait for Zone Alarm to correct it. It's their move now.
2. Don't use the Microsoft Malicious Software Removal Tool (for now).
I'll see if I can find a way to get the CCleaner installer to them to examine. I just downloaded a fresh copy and only Prevx Heuristics has a possible problem with it (Heuristics can do that - have FPs). All other scanners call it clean quote: File ccsetup205.exe received on 03.20.2008 01:01:51 (CET) Current status:finished Result: 1/32 (3.13%) Antivirus Version Last Update Result AhnLab-V3 2008.3.19.1 2008.03.19 - AntiVir 7.6.0.75 2008.03.19 - Authentium 4.93.8 2008.03.19 - Avast 4.7.1098.0 2008.03.19 - AVG 7.5.0.516 2008.03.19 - BitDefender 7.2 2008.03.20 - CAT-QuickHeal 9.50 2008.03.14 - ClamAV 0.92.1 2008.03.20 - DrWeb 4.44.0.09170 2008.03.19 - eSafe 7.0.15.0 2008.03.18 - eTrust-Vet 31.3.5628 2008.03.19 - Ewido 4.0 2008.03.19 - F-Prot 4.4.2.54 2008.03.19 - F-Secure 6.70.13260.0 2008.03.19 - FileAdvisor 1 2008.03.20 - Fortinet 3.14.0.0 2008.03.19 - Ikarus T3.1.1.20 2008.03.19 - Kaspersky 7.0.0.125 2008.03.20 - McAfee 5255 2008.03.20 - Microsoft 1.3301 2008.03.19 - NOD32v2 2961 2008.03.20 - Norman 5.80.02 2008.03.19 - Panda 9.0.0.4 2008.03.18 - Prevx1 V2 2008.03.20 Heuristic: Suspicious Hijacker Rising 20.36.22.00 2008.03.19 - Sophos 4.27.0 2008.03.20 - Sunbelt 3.0.978.0 2008.03.18 - Symantec 10 2008.03.20 - TheHacker 6.2.92.250 2008.03.19 - VBA32 3.12.6.3 2008.03.17 - VirusBuster 4.3.26:9 2008.03.19 - Webwasher-Gateway 6.6.2 2008.03.19 - Additional information File size: 2733520 bytes MD5: 06ab7fd00ca2f03baf4616c40bb2c761 SHA1: 96f0796a003371529d023d4381f7d6e8e6d55f1e PEiD: - packers: WiseSFXDropper, WiseSFXDropper, WiseSFXDropper Prevx info: »info.prevx.com/aboutprogramtext.···7DCE38E9
If you download the installer again check it first at VirusTotal: »www.virustotal.com/
Check the MD5 to my file above listed (MD5: 06ab7fd00ca2f03baf4616c40bb2c761) If it is the same, you have the clean one (with the FP problem ZA and MSRT).
All you can do is ignore those false reports. -- It takes a disaster to make a woman out of a female Microsoft MVP/Windows Security 2003-2008 Proud Member of ASAP (Alliance of Security Analysis Professionals) |