Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » FP with Trojan Hunter?
Search Topic:
Uniqs:
1810
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
Virtualized rootkits - Part 1 »
« Why does Windows Defender Get such a Bad Rep?  
AuthorAll Replies


La Luna
Surviving Ashraful
Premium
join:2001-07-12
Warwick, NY
clubs:
 reply to sammysnake
Re: FP with Trojan Hunter?

Wow, talk about a quick response and fix. Awesome!! Just another reason why I like TH.


sammysnake
Never Forget 911
Premium
join:2002-01-19
Salt Lake City, UT
·Qwest.net
·Comcast Formerly ..

reply to MagnusM
Thank you again Magnus, all is well in snakeland again as shown:

Registry scan
No suspicious entries found
Inifile scan
No suspicious entries found
Port scan
No suspicious open ports found
Memory scan
No trojans found in memory
File scan
No trojan files found

Sammy

MagnusM
Premium
join:2001-07-07

reply to sammysnake
Ah... this has to do with support for scanning 64-bit executables that was recently added. The scanner doesn't recognize the machine type flag in the files listed above and throws an error. Of course, that shouldn't be happening so I will fix this ASAP.

If anyone is interested in the technical explanation, the files that give this error are files with machine type IMAGE_FILE_MACHINE_IA64, which is the Itanium architecture. This is separate from the x64 (AMD-64) architecture which is just the regular 64-bit format, which is why it was omitted.

Thanks Sammy for reporting this! I will upload a corrected version to the servers in the next 30 minutes.
--
Mischel Internet Security
http://www.misec.net


sammysnake
Never Forget 911
Premium
join:2002-01-19
Salt Lake City, UT
·Qwest.net
·Comcast Formerly ..

reply to MagnusM
Now I get this when I do a full scan with the latest updated defs:

Registry scan
No suspicious entries found
Inifile scan
No suspicious entries found
Port scan
No suspicious open ports found
Memory scan
No trojans found in memory
File scan
Error: Error while scanning C:\DELL\MEDIAEXE\PXCPYI64.EXE: Unknown machine type: 0x200 (C:\DELL\MEDIAEXE\PXCPYI64.EXE)
Error: Error while scanning C:\DELL\MEDIAEXE\PXHELP64.SYS: Unknown machine type: 0x200 (C:\DELL\MEDIAEXE\PXHELP64.SYS)
Error: Error while scanning C:\DELL\MEDIAEXE\PXINSI64.EXE: Unknown machine type: 0x200 (C:\DELL\MEDIAEXE\PXINSI64.EXE)
Error: Error while scanning C:\DELL\PXCPYI64.EXE: Unknown machine type: 0x200 (C:\DELL\PXCPYI64.EXE)
Error: Error while scanning C:\DELL\PXHELP64.SYS: Unknown machine type: 0x200 (C:\DELL\PXHELP64.SYS)
Error: Error while scanning C:\DELL\PXINSI64.EXE: Unknown machine type: 0x200 (C:\DELL\PXINSI64.EXE)
Error: Error while scanning C:\I386\PMSPL.DLL: This is not a PE format
Error: Error while scanning C:\I386\pxcpyi64.exe: Unknown machine type: 0x200 (C:\I386\pxcpyi64.exe)
Error: Error while scanning C:\I386\pxinsi64.exe: Unknown machine type: 0x200 (C:\I386\pxinsi64.exe)
Error: Error while scanning C:\WINDOWS\SYSTEM32\PMSPL.DLL: This is not a PE format
Error: Error while scanning C:\WINDOWS\SYSTEM32\pxcpyi64.exe: Unknown machine type: 0x200 (C:\WINDOWS\SYSTEM32\pxcpyi64.exe)
Error: Error while scanning C:\WINDOWS\SYSTEM32\pxinsi64.exe: Unknown machine type: 0x200 (C:\WINDOWS\SYSTEM32\pxinsi64.exe)
No trojan files found



Mind you.... the files listed above have always been on this machine and have never been flagged before.

Sammy


sammysnake
Never Forget 911
Premium
join:2002-01-19
Salt Lake City, UT

1 edit
 reply to MagnusM
Thank you Magnus!

MagnusM
Premium
join:2001-07-07

reply to sammysnake
Thanks, file received and analyzed. This is indeed a false positive and I've uploaded corrected signatures. Run LiveUpdate and this file should no longer be detected on your next scan.
--
Mischel Internet Security
http://www.misec.net


sammysnake
Never Forget 911
Premium
join:2002-01-19
Salt Lake City, UT
reply to MagnusM
File sent.

Thanks Magnus.

Sammy


hayc59
VoodooChild
Premium
join:2001-02-26
David R.I.P.
reply to sammysnake
Magnus, hello and kudos for stoppin by

MagnusM
Premium
join:2001-07-07
reply to sammysnake
This is almost certainly a false positive. Could you email the file to support@misec.net for analysis?
--
Mischel Internet Security
http://www.misec.net


sammysnake
Never Forget 911
Premium
join:2002-01-19
Salt Lake City, UT
·Qwest.net
·Comcast Formerly ..

  I just finished updating AVG Free, defs from 8/24/07, and Trojan Hunter, defs from 8/25/07, and while AVG comes up clean Trojan Hunter flags this: Found trojan file: C:\Program Files\Grisoft\AVG Free\avgmvfl.dll (Generic.LdPinch.A)

Anyone else seeing this and is it a FP?

Sammy
Forums » Up and Running » Security » SecurityVirtualized rootkits - Part 1 »
« Why does Windows Defender Get such a Bad Rep?  


Wednesday, 02-Dec 05:44:48 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.republican-creole
page compression OFF
Most commented news this week
· [151] Comcast Releasing Promised Usage Meter
· [69] Baltimore To Ban Lazy Cable Installs
· [56] Broadband Killed The Game Console
· [55] Latest Consumer Reports Survey Not Kind To AT&T
· [52] Rogers Unveils The ISP Dream Model
· [43] ACTA: Global Three Strikes
· [41] Rural Carriers Quickly Embracing Fiber
· [35] Charter Exits Chapter 11
· [33] AT&T Top Lobbyist Cicconi Has His Feelings Hurt
· [26] Vivendi Agrees, Comcast/NBC Deal Soon
Most people now reading
· [Newsgroups] Newzleech down? [Filesharing Software]
· Security Software Updates - 1 Dec 2009 [Security]
· Windows 7 boot manager editing questions [Microsoft Help]
· [WIN7] Outlook express under Windows 7? [Microsoft Help]
· [Snow Leopard] NFS Mounts - no more Directory Utility [All Things Macintosh]
· [Newsgroups] Newzleech is either down or gone for good... [Filesharing Software]
· Opening a file download dialog from a JavaScript function. [Webmasters and Developers]
· IE8 InPrivate filter from adblock plus list [Microsoft Help]
· [RESOLVED] Possible FP Avira AntiVir Personal [Security]
· IMG 1.7 (IMG Updates and Discussion) [Verizon FIOS TV]