Avast false positive with DVD Region + CSS free

Avast false positive with DVD Region + CSS free

Secure Home | Search | About
 Anti-Virus Software    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Avast false positive with DVD Region + CSS free R.V.Gronoff 05-20-2008
Posted by on May 27, 2008, 1:07 am
If you were  Registered and logged in, you could reply and use other advanced thread options

>
> OK, my bad: Avast is God and I am Dr Evil's mini-me: the exe in question
> WAS infected! I un/re-installed the progamme from a fresh download and
> now it's clean.
>

How did you finally determine that? Did Avast send you a full report or did
you upload it to Virustotal? Were there any symptoms of the infection, ie
were there any registry strings added, any unusual additions to a hijackthis
log that you hadn't seen before, or were any files added to your OS
directory?

What's always puzzled me is that since these AV programs are scanning files
so quickly, are they actually "reading" every file or are they just checking
the filenames against a definition database.

How many AV programs actually can clean the registry and OS/programs
partition(s) of all the remnants of these trojans/viruses? Is just deleting
or quaranting the offending file enough?

If you read the Symantec manual cleaning instructions for any given trojan,
there's quite a few areas that have to be cleaned.

Posted by David H. Lipman on May 27, 2008, 4:29 pm
If you were  Registered and logged in, you could reply and use other advanced thread options

|
>> OK, my bad: Avast is God and I am Dr Evil's mini-me: the exe in question
>> WAS infected! I un/re-installed the progamme from a fresh download and
>> now it's clean.
>>
| How did you finally determine that? Did Avast send you a full report or did
| you upload it to Virustotal? Were there any symptoms of the infection, ie
| were there any registry strings added, any unusual additions to a hijackthis
| log that you hadn't seen before, or were any files added to your OS
| directory?
|
| What's always puzzled me is that since these AV programs are scanning files
| so quickly, are they actually "reading" every file or are they just checking
| the filenames against a definition database.
|
| How many AV programs actually can clean the registry and OS/programs
| partition(s) of all the remnants of these trojans/viruses? Is just deleting
| or quaranting the offending file enough?
|
| If you read the Symantec manual cleaning instructions for any given trojan,
| there's quite a few areas that have to be cleaned.

They (AV applications) use signature and heuristics and do NOT use filenames.

Symantec has traditionally been bad at removing Registry modifications and is
one of the
*many* reasons why Symantec is not at the top of the list of suggested AV
applications.

--
Dave
http://www.claymania.com/removal-trojan-adware.html
Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp



Similar ThreadsPosted
False Positive? September 10, 2005, 8:22 am
False positive? April 8, 2007, 4:28 pm
False Positive on Keylogger??? June 10, 2006, 11:38 am
Malwarebytes false positive July 14, 2008, 10:22 am
False Positive, Posssible / Likely? July 24, 2008, 1:20 pm
Spybot 1.4 Smitfraud-C False Positive? July 29, 2005, 11:23 pm
New False Positive from Spyware Doctor? February 1, 2007, 8:41 pm
Win32:Mhtplo-10 - False positive? November 30, 2007, 3:27 pm
PCANDIS5.sys Trojan or False Positive? June 28, 2008, 5:04 am
AVG false positive reported on user32.dll November 19, 2008, 1:01 am

The site map in XML format XML site map

Contact Us | Privacy Policy