Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » FP with Trojan Hunter?
Uniqs:
1836
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
Virtualized rootkits - Part 1 »
« Why does Windows Defender Get such a Bad Rep?  

sammysnake
Never Forget 911
Premium
join:2002-01-19
Salt Lake City, UT
·Qwest.net
·Comcast Formerly ..

FP with Trojan Hunter?

I just finished updating AVG Free, defs from 8/24/07, and Trojan Hunter, defs from 8/25/07, and while AVG comes up clean Trojan Hunter flags this: Found trojan file: C:\Program Files\Grisoft\AVG Free\avgmvfl.dll (Generic.LdPinch.A)

Anyone else seeing this and is it a FP?

Sammy
MagnusM
Premium
join:2001-07-07

Re: FP with Trojan Hunter?

This is almost certainly a false positive. Could you email the file to support@misec.net for analysis?
--
Mischel Internet Security
http://www.misec.net

sammysnake
Never Forget 911
Premium
join:2002-01-19
Salt Lake City, UT

Re: FP with Trojan Hunter?

File sent.

Thanks Magnus.

Sammy

hayc59
VoodooChild
Premium
join:2001-02-26
David R.I.P.
Magnus, hello and kudos for stoppin by
MagnusM
Premium
join:2001-07-07

Thanks, file received and analyzed. This is indeed a false positive and I've uploaded corrected signatures. Run LiveUpdate and this file should no longer be detected on your next scan.
--
Mischel Internet Security
http://www.misec.net

sammysnake
Never Forget 911
Premium
join:2002-01-19
Salt Lake City, UT

1 edit

Re: FP with Trojan Hunter?

Thank you Magnus!

sammysnake
Never Forget 911
Premium
join:2002-01-19
Salt Lake City, UT
·Qwest.net
·Comcast Formerly ..

Now I get this when I do a full scan with the latest updated defs:

Registry scan
No suspicious entries found
Inifile scan
No suspicious entries found
Port scan
No suspicious open ports found
Memory scan
No trojans found in memory
File scan
Error: Error while scanning C:\DELL\MEDIAEXE\PXCPYI64.EXE: Unknown machine type: 0x200 (C:\DELL\MEDIAEXE\PXCPYI64.EXE)
Error: Error while scanning C:\DELL\MEDIAEXE\PXHELP64.SYS: Unknown machine type: 0x200 (C:\DELL\MEDIAEXE\PXHELP64.SYS)
Error: Error while scanning C:\DELL\MEDIAEXE\PXINSI64.EXE: Unknown machine type: 0x200 (C:\DELL\MEDIAEXE\PXINSI64.EXE)
Error: Error while scanning C:\DELL\PXCPYI64.EXE: Unknown machine type: 0x200 (C:\DELL\PXCPYI64.EXE)
Error: Error while scanning C:\DELL\PXHELP64.SYS: Unknown machine type: 0x200 (C:\DELL\PXHELP64.SYS)
Error: Error while scanning C:\DELL\PXINSI64.EXE: Unknown machine type: 0x200 (C:\DELL\PXINSI64.EXE)
Error: Error while scanning C:\I386\PMSPL.DLL: This is not a PE format
Error: Error while scanning C:\I386\pxcpyi64.exe: Unknown machine type: 0x200 (C:\I386\pxcpyi64.exe)
Error: Error while scanning C:\I386\pxinsi64.exe: Unknown machine type: 0x200 (C:\I386\pxinsi64.exe)
Error: Error while scanning C:\WINDOWS\SYSTEM32\PMSPL.DLL: This is not a PE format
Error: Error while scanning C:\WINDOWS\SYSTEM32\pxcpyi64.exe: Unknown machine type: 0x200 (C:\WINDOWS\SYSTEM32\pxcpyi64.exe)
Error: Error while scanning C:\WINDOWS\SYSTEM32\pxinsi64.exe: Unknown machine type: 0x200 (C:\WINDOWS\SYSTEM32\pxinsi64.exe)
No trojan files found



Mind you.... the files listed above have always been on this machine and have never been flagged before.

Sammy
MagnusM
Premium
join:2001-07-07

Ah... this has to do with support for scanning 64-bit executables that was recently added. The scanner doesn't recognize the machine type flag in the files listed above and throws an error. Of course, that shouldn't be happening so I will fix this ASAP.

If anyone is interested in the technical explanation, the files that give this error are files with machine type IMAGE_FILE_MACHINE_IA64, which is the Itanium architecture. This is separate from the x64 (AMD-64) architecture which is just the regular 64-bit format, which is why it was omitted.

Thanks Sammy for reporting this! I will upload a corrected version to the servers in the next 30 minutes.
--
Mischel Internet Security
http://www.misec.net

sammysnake
Never Forget 911
Premium
join:2002-01-19
Salt Lake City, UT
·Qwest.net
·Comcast Formerly ..

Re: FP with Trojan Hunter?

Thank you again Magnus, all is well in snakeland again as shown:

Registry scan
No suspicious entries found
Inifile scan
No suspicious entries found
Port scan
No suspicious open ports found
Memory scan
No trojans found in memory
File scan
No trojan files found

Sammy

La Luna
Surviving Ashraful
Premium
join:2001-07-12
Warwick, NY
clubs:
Wow, talk about a quick response and fix. Awesome!! Just another reason why I like TH.
Forums » Up and Running » Security » SecurityVirtualized rootkits - Part 1 »
« Why does Windows Defender Get such a Bad Rep?  


Wednesday, 09-Dec 07:24:39 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.
page compression OFF
Most commented news this week
· [194] Sprint Sued For Distracted Driving Death
· [81] 3G Network Test Says AT&T Is Tops
· [72] Mediacom Unveils 105 Mbps Pricing
· [62] Sprint Poised For A Turnaround?
· [52] WPA Cracker: Test WPA-PSK Networks In 20 Minutes
· [50] The Future Of Wi-Fi Is Bright
· [47] Site Leaks Yahoo, Verizon Fed Data Share Pricing
· [44] Microwaving Your Innards Is Not 'Extreme'
· [39] Verizon LTE: 5-12 Mbps Downstream
· [21] AT&T Releases Network Reporting iPhone App
Most people now reading
· Windows 7 boot manager editing questions [Microsoft Help]
· Comcast refused to install 400' feet. [Comcast HSI]
· [How to] Install Asterisk on an Asus WL-520GU router [VOIP Tech Chat]
· persistent connection to qw-in-f113.1e100.net on boot [Security]
· Maximizing Rogue DPS for 3.1 [World of Warcraft]
· Extjs grid combo box. [Webmasters and Developers]
· Tomato/MLPPP v3 alpha 6 released! [TekSavvy]
· [Config] cisco asa 5505 with multiple outside IP addresses [Cisco]
· What is the spell hit cap for a lvl 80 full arcane spec mage [World of Warcraft]
· Errrybody must be stuck home from the snow [Mediacom]