PDA

View Full Version : Positive Identification


ChrisP
April 9th, 2005, 06:10 AM
Just dis a scan and TDS picked up the following:

Scan Control Dumped @ 11:04:58 09-04-05
Positive identification: Riskware.ProcessRestart
File: c:\program files\f-secure\backweb\7681197\6.1.4.58-7681197l\program\restart.exe

Is this TDS just picking up the perfrctly safe and harmless f-secure backweb component?

Pilli
April 9th, 2005, 06:29 AM
Looks like it maybe Chris, Please zip & submit the file to DCS for analysis.

submit@diamondcs.com.au

Pilli :)

Jooske
April 9th, 2005, 07:06 AM
Hello ChrisP, did you also look at these threads?
http://www.wilderssecurity.com/showthread.php?t=66209&highlight=restart.exe
http://www.diamondcs.com.au/forum/showthread.php?t=2767 (you'll have to register to DiamondCD forum to be able to see the thread)