PDA

View Full Version : False positive


smage
January 19th, 2009, 11:49 AM
Hi.
I just purchased a new PC and in the package, I got Norton Cooperate 9 0 3 1000 for free.
I ran a scan and it detected four threats!
Are these false positives?

PiCo
January 19th, 2009, 12:03 PM
-{ Quote: "Hi.
I just purchased a new PC and in the package, I got Norton Cooperate 9 0 3 1000 for free.
I ran a scan and it detected four threats!
Are these false positives?" }-Apparently not!

EMPTY KEY.DLL (http://www.prevx.com/filenames/X583126739723444965-0/EMPTY+KEY.DLL.html)
SPWIZARD.EXE (http://www.prevx.com/filenames/X165404198172001010-X1/SPWIZARD2EEXE.html)
ALCOHOL 1.X.DLL (http://www.prevx.com/filenames/1244293579863037143-0/ALCOHOL+1.X.DLL.html)
TRIAL RESET.EXE (http://www.prevx.com/filenames/1942998374502560544-0/TRIAL+RESET2EEXE.html)

icr
January 19th, 2009, 12:03 PM
I don't know but u can upload these files here and check for urself
Virus Total (http://www.virustotal.com/)
Jotti (http://virusscan.jotti.org/)
or why not mail to norton itself

pugmug
January 19th, 2009, 12:06 PM
Alcohol one has been a problem before.Send them in to be checked,ps.these aren't cracked games,are they?

pugmug
January 19th, 2009, 12:16 PM
Just have to love when people leave with zero response after reading their feedback.

djohn
January 19th, 2009, 12:29 PM
-{ Quote: "Just have to love when people leave with zero response after reading their feedback." }-

Agree,Its getting to the point when we just do not reply any more.The benefit of doubt perhaps not read replys yet.On topic, I find rather strange a new pc would be infected from the start unless the OP did not take the right precautions before connection to the net or is off to bad surfing habbits from the get Go.

virtumonde
January 19th, 2009, 12:30 PM
-{ Quote: "Hi.
I just purchased a new PC and in the package, I got Norton Cooperate 9 0 3 1000 for free.
I ran a scan and it detected four threats!
Are these false positives?" }-
Do you have Winrar "extreme" the 17MB file size installed?

smage
January 19th, 2009, 12:31 PM
Hi,
I don't know about these files. they were already installed on the PC when it was delivered to me.
How to upload these files to VirusTotal if they are in Quarantine?

emperordarius
January 19th, 2009, 12:49 PM
-{ Quote: "
TRIAL RESET.EXE (http://www.prevx.com/filenames/1942998374502560544-0/TRIAL+RESET2EEXE.html)" }-

Mmmm...warez?:shifty:

PiCo
January 19th, 2009, 12:53 PM
-{ Quote: "Mmmm...warez?:shifty:" }-Don't have a clue!

If you ask me, they all have funny names, funny names -> not so legit file, PiCo heuristics :P

djohn
January 19th, 2009, 01:03 PM
-{ Quote: "Hi,
I don't know about these files. they were already installed on the PC when it was delivered to me.
How to upload these files to VirusTotal if they are in Quarantine?" }-
Now the question is if they are in fact virus/malware are they also in a recovery partion,As many new pc are comming this way rather then supplied CD of the OS and Drivers.I would certainly be pissed If a new pc came to me this way.

virtumonde
January 19th, 2009, 01:03 PM
-{ Quote: "Hi,
I don't know about these files. they were already installed on the PC when it was delivered to me.
How to upload these files to VirusTotal if they are in Quarantine?" }-
These detections doesn't look like false positives.Your best is that they not harmfull either.These files belong to a p2p release of program Winrar a installer on which besides winrar files some carck tools are added.They are not harmful,but they are not useful either.
The "genuine"if it can be called like this installer of these files doesn't contain malware only those cracking tools which like i said are useless.But since the program has doubtfull origins it is better to get rid of it immediatley
Please uninstall your current winrar,and download the program from it's original site. http://www.rarlab.com/

smage
January 19th, 2009, 03:09 PM
Ok thanks everyone, I am demanding explanation from the computer shop, good that I have not yet settled the bill completely.

Baz_kasp
January 19th, 2009, 03:25 PM
-{ Quote: "Ok thanks everyone, I am demanding explanation from the computer shop, good that I have not yet settled the bill completely." }-


Thats a new one...computer shops installing pirated software onto their machines and hoping nobody will notice ;D

GES/POR
January 19th, 2009, 03:38 PM
-{ Quote: "Thats a new one...computer shops installing pirated software onto their machines and hoping nobody will notice ;D" }-

Actually thats not highly uncommon, ive seen this before n trust me some sold pc's or reinstalled pc r loaded with malware

TechOutsider
January 19th, 2009, 04:50 PM
Gampass = warez

See if you can upgrade to Endpoint 11; contact symantec support.

http://www.symantec.com/support/index.jsp

zfactor
January 20th, 2009, 11:41 AM
i do repair and building. trust me i see this all the time. i will not of course name anyone but i have seen a number of cases of pirated vista and xp installations being sold on a brand new machine as a legit copy.. and the people are pretty shocked when i tell them "do you know the windows you are running is an illegal copy" this was even seen from asus on brand new laptops a short while ago.. there were cracked / keygens found on their recovery discs..

emperordarius
January 20th, 2009, 11:53 AM
-{ Quote: "Thats a new one...computer shops installing pirated software onto their machines and hoping nobody will notice ;D" }-

It's a standard here in Albania. However they use Kaspersky (really) and usually the computers are clean.

Try to get an Xp installation disc and you get a big skull in the main installation screen with things like "Windows Xp Ultimate by _______" :argh:

A short navigation through Xp Installation disk (Tested on old Xp laptop for Antivirus reaction):

205624
205625
205626

smage
January 21st, 2009, 05:11 AM
Hi,
I will explain what happens in these shops.

Manufacturer A sells a PC with certain specifications for price X and asks for Y amount additional for them to include Windows and Office on it.

Manufacturer B offers the same PC with same specifications at the same price X but also provides Windows and Office with it. So they trick people and deliver pirated softwares instead.

The amazing thing is that they provide free anti virus software, how do I know whether the anti virus is genuine or a cracked one?

TechOutsider
January 22nd, 2009, 08:07 PM
Just verify your subscription through Norton support:

norton.com/support

smage
January 23rd, 2009, 04:51 AM
OK thanks everyone.
I will get a genuine Windows etc and everything will be fine.