![]() |
|
#1
|
|||
|
|||
![]() Hello, while scanning with the latest update, get the following (I hope) false positive: "c:\windows\system\HH.exe ----> TrojanSpy. Dwkeylogger " Scanning with TrojanHunter & NOD don't give anything suspicious. Kind regards, PeterVO |
|
#2
|
||||
|
||||
|
Hi PeterVO,
What OS do you have? hh.exe is a legitimate windows file and on Windows XP it is located both in C:\Windows and C:\Windows\System32. If you have a different OS then I am not sure of its location. Sounds like a probable false positive. I would go to the Ewido site and submit it and see what they have to say. Regards, Kent
__________________
Best regards, Kent AX64 Time Machine - Travel in Time Current Version 1.1.0.996 |
|
#3
|
|||
|
|||
|
Hello Kent,
I've a dual boot config: on the C-drive is Win98 Second Edition and on the E-drive Win XP Professional. ESS only falsly detect the Win98 "HH.exe" version. It doesn't stumble over the XP version. Strange, isn't it? Kind regards, PeterVO |
|
#4
|
|||
|
|||
|
Ewido is not supposed to work with 98. At least that is what their web site says.
|
|
#5
|
||||
|
||||
|
Could you please mail that file to submit@ewido.net? Thanks!
![]() |
|
#6
|
||||
|
||||
|
Quote:
True, but I imagine he was scanning his 98 partition from his xp partition .....Regards, Kent
__________________
Best regards, Kent AX64 Time Machine - Travel in Time Current Version 1.1.0.996 |
|
#7
|
|||
|
|||
|
Hello,
Peter the HH.exe file has just been e-mailed as you asked me to do. True, the 98-partition (FAT32) was scanned from the XP-partition (NTFS). Kind regards from a rainy Belgium, PeterVO |
|
#8
|
||||
|
||||
|
submit the file here to make sure what it is
http://www.kaspersky.com/scanforvirus.html url repaired==bigc Last edited by bigc73542 : April 10th, 2004 at 11:55 PM. |
|
#9
|
||||
|
||||
|
Hmm, unfortunately we didn't receive anything yet
![]() |
|
#10
|
|||
|
|||
|
Hello Peter,
did you receive my mail with attachment? I'v sent it two times with two different E-mail adresses. Kind regards, PeterVO ps: maybe it arrived in your Spam folder? |
|
#11
|
||||
|
||||
|
Unfortunately not.
Could you please try to upload it on this page?http://www.ewido.net/de/?section=malware Just add the file and leave the other fields blank ![]() url repaired==bigc Last edited by bigc73542 : April 10th, 2004 at 11:54 PM. |
|
#12
|
|||
|
|||
|
"Unfortunately not.
Could you please try to upload it on this page?http://www.ewido.net/de/?section=malware Just add the file and leave the other fields blank "Hello Peter, uploaded the file a few days ago using your web-form as asked. Scanned my dual-boot notebook within WinXP Pro with the definitions dated 10/04 but still the same "false" positive. When "HH.exe" is scanned within Win98 Sec Edition or Win Xp Pro using Kaspersky, NOD32, TDS3 & TrojanHunter, nothing suspicious is found. Kind regards, PeterVO |
|
#13
|
||||
|
||||
|
Quote:
I really can't get it reproduced ![]() |
|
#14
|
|||
|
|||
|
Greetings,
Just done a virus check using ewido SS and it gave me the following information: Filename: hh.exe Path: C:\WINNT\system32 Infection: TrojanSpy.Dwkeylogger The system's dual booted with Windows NT Workstation (Doesn'tworkstation -HAHAHAHAHA!) and Windows XP Home Edition. I know dad would wring my neck if there were any viruses, but this might be a false alarm. Dad accuses me of course, telling me I'm a hopeless techie. Please help a desperate techie before dad wrings me neck! I don't want a broken system! Now logged out! windowsxp_rules |
|
#15
|
||||
|
||||
|
Could you please send the file to submit@ewido.net? Thanks
![]() |
|
#16
|
|||
|
|||
|
Greetings,
Which file do I have to send to ewido? Is it the scan report? Anyway, I was safe from dad wringing my neck! he didn't blame me. he blamed ewido. I have posted comments on www.windowscrash.com, a Windows crash submission site! If anyone could provide the information, post it on the forum! I'll look as soon as poss! Thank you, windowsxp_rules ![]() |
|
#17
|
||||
|
||||
|
HH.exe
![]() |
|
#18
|
|||
|
|||
|
Greetings,
Are you sure? I'm not sending viruses over the net. Dad would not permit it! He'd wring my neck! Any replies on the forum would be useful. I'll check as soon as poss! Thank you, windowsxp_rules |
|
#19
|
||||
|
||||
|
Hi, Just zip it up to send it, it is quite safe to send such files to AV AT companies.
__________________
"Education is not the filling of a pail, but the lighting of a fire" Pilli's website http://www.pilliwinks.net |
|
#20
|
|||
|
|||
|
Hi,
I use windows xp so zipping the file should be no problem. It has built-in compression, which techie here should make use of. Dad will be sending the email, so he will wring my neck for that! Then i'll be in serious trouble! It's now safe to turn off your computer!!! --windowsxp_rules |
| « Previous Thread | Next Thread » |
| Thread Tools | Search this Thread |
|
|