Wilders Security Forums  

Go Back   Wilders Security Forums > Security Products > other anti-trojan software
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old April 6th, 2004, 12:48 PM
PeterVO PeterVO is offline
Regular Poster
 
Join Date: Aug 2003
Location: Belgium, Leuven
Posts: 87
Default Ewido SS false positive?



Hello,

while scanning with the latest update, get the following (I hope) false positive:

"c:\windows\system\HH.exe ----> TrojanSpy. Dwkeylogger "

Scanning with TrojanHunter & NOD don't give anything suspicious.

Kind regards,

PeterVO
  #2  
Old April 6th, 2004, 12:58 PM
puff-m-d's Avatar
puff-m-d puff-m-d is online now
Massive Poster
 
Join Date: Feb 2002
Location: North Carolina, USA
Posts: 3,638
Default Re:Ewido SS false positive?

Hi PeterVO,

What OS do you have? hh.exe is a legitimate windows file and on Windows XP it is located both in C:\Windows and C:\Windows\System32. If you have a different OS then I am not sure of its location. Sounds like a probable false positive. I would go to the Ewido site and submit it and see what they have to say.

Regards,
Kent
__________________
Best regards,
Kent

AX64 Time Machine - Travel in Time
Current Version 1.1.0.996
  #3  
Old April 6th, 2004, 01:49 PM
PeterVO PeterVO is offline
Regular Poster
 
Join Date: Aug 2003
Location: Belgium, Leuven
Posts: 87
Default Re:Ewido SS false positive?

Hello Kent,

I've a dual boot config: on the C-drive is Win98 Second Edition and on the E-drive Win XP Professional.
ESS only falsly detect the Win98 "HH.exe" version. It doesn't stumble over the XP version.
Strange, isn't it?

Kind regards,

PeterVO

  #4  
Old April 6th, 2004, 03:45 PM
WilliamP WilliamP is offline
Very Frequent Poster
 
Join Date: Jun 2003
Location: Fayetteville, Ga
Posts: 2,125
Default Re:Ewido SS false positive?

Ewido is not supposed to work with 98. At least that is what their web site says.
  #5  
Old April 6th, 2004, 08:08 PM
peter.ewido's Avatar
peter.ewido peter.ewido is offline
former ewido team
 
Join Date: Nov 2003
Location: Brno, Czech Republic
Posts: 737
Default Re:Ewido SS false positive?

Could you please mail that file to submit@ewido.net? Thanks!
  #6  
Old April 6th, 2004, 08:34 PM
puff-m-d's Avatar
puff-m-d puff-m-d is online now
Massive Poster
 
Join Date: Feb 2002
Location: North Carolina, USA
Posts: 3,638
Default Re:Ewido SS false positive?

Quote:
quoting: WilliamP link=board=25;threadid=27212;start=0#msg156660 date=1081280710]Ewido is not supposed to work with 98. At least that is what their web site says.

True, but I imagine he was scanning his 98 partition from his xp partition .....

Regards,
Kent
__________________
Best regards,
Kent

AX64 Time Machine - Travel in Time
Current Version 1.1.0.996
  #7  
Old April 7th, 2004, 09:50 AM
PeterVO PeterVO is offline
Regular Poster
 
Join Date: Aug 2003
Location: Belgium, Leuven
Posts: 87
Default Re:Ewido SS false positive?

Hello,

Peter the HH.exe file has just been e-mailed as you asked me to do.
True, the 98-partition (FAT32) was scanned from the XP-partition (NTFS).

Kind regards from a rainy Belgium,

PeterVO
  #8  
Old April 7th, 2004, 09:52 AM
Slovak's Avatar
Slovak Slovak is offline
Frequent Poster
 
Join Date: Mar 2004
Location: Medina, Ohio
Posts: 515
Default Re:Ewido SS false positive?

submit the file here to make sure what it is
http://www.kaspersky.com/scanforvirus.html






url repaired==bigc

Last edited by bigc73542 : April 10th, 2004 at 11:55 PM.
  #9  
Old April 7th, 2004, 10:35 AM
peter.ewido's Avatar
peter.ewido peter.ewido is offline
former ewido team
 
Join Date: Nov 2003
Location: Brno, Czech Republic
Posts: 737
Default Re:Ewido SS false positive?

Hmm, unfortunately we didn't receive anything yet
  #10  
Old April 8th, 2004, 04:23 AM
PeterVO PeterVO is offline
Regular Poster
 
Join Date: Aug 2003
Location: Belgium, Leuven
Posts: 87
Default Re:Ewido SS false positive?

Hello Peter,

did you receive my mail with attachment? I'v sent it two times with two different E-mail adresses.


Kind regards,

PeterVO

ps: maybe it arrived in your Spam folder?
  #11  
Old April 8th, 2004, 07:02 AM
peter.ewido's Avatar
peter.ewido peter.ewido is offline
former ewido team
 
Join Date: Nov 2003
Location: Brno, Czech Republic
Posts: 737
Default Re:Ewido SS false positive?

Unfortunately not. Could you please try to upload it on this page?
http://www.ewido.net/de/?section=malware
Just add the file and leave the other fields blank




url repaired==bigc

Last edited by bigc73542 : April 10th, 2004 at 11:54 PM.
  #12  
Old April 11th, 2004, 10:44 AM
PeterVO PeterVO is offline
Regular Poster
 
Join Date: Aug 2003
Location: Belgium, Leuven
Posts: 87
Default Re: Ewido SS false positive?

"Unfortunately not. Could you please try to upload it on this page?
http://www.ewido.net/de/?section=malware
Just add the file and leave the other fields blank "


Hello Peter,

uploaded the file a few days ago using your web-form as asked.
Scanned my dual-boot notebook within WinXP Pro with the definitions dated 10/04 but still the same "false" positive.
When "HH.exe" is scanned within Win98 Sec Edition or Win Xp Pro using Kaspersky, NOD32, TDS3 & TrojanHunter, nothing suspicious is found.

Kind regards,

PeterVO
  #13  
Old April 11th, 2004, 10:57 AM
peter.ewido's Avatar
peter.ewido peter.ewido is offline
former ewido team
 
Join Date: Nov 2003
Location: Brno, Czech Republic
Posts: 737
Default Re: Ewido SS false positive?

Quote:
---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------

+ Created on: 16:07:42, 08.04.2004
+ Report-Checksum: C55198EA

+ Date of database: 08.04.2004
+ Version of scan engine: v1.1

+ Duration: 27 ms
+ Scanned Files: 1
+ Speed: 37.04 Files/Second
+ Infected files: 0
+ Removed files: 0
+ Files put in quarantine: 0
+ Files that could not be opened: 0
+ Files that could not be removed: 0

+ Ignore extension: Yes
+ Binder: Yes
+ Crypter: Yes
+ Memory: No
+ Archives: No
+ Heuristic: No

+ Scanned items:
X:\incoming\08_04_04\15_15_47\hh.exe

+ Scan result:
No infected files found!


::Report End

I really can't get it reproduced
  #14  
Old June 24th, 2004, 06:29 PM
windowsxp_rules
 
Posts: n/a
Wink Re: Ewido SS false positive?

Greetings,
Just done a virus check using ewido SS and it gave me the following information:

Filename: hh.exe
Path: C:\WINNT\system32
Infection: TrojanSpy.Dwkeylogger

The system's dual booted with Windows NT Workstation (Doesn'tworkstation -HAHAHAHAHA!) and Windows XP Home Edition. I know dad would wring my neck if there were any viruses, but this might be a false alarm. Dad accuses me of course, telling me I'm a hopeless techie. Please help a desperate techie before dad wrings me neck! I don't want a broken system!
Now logged out!
windowsxp_rules
  #15  
Old June 25th, 2004, 05:11 AM
peter.ewido's Avatar
peter.ewido peter.ewido is offline
former ewido team
 
Join Date: Nov 2003
Location: Brno, Czech Republic
Posts: 737
Default Re: Ewido SS false positive?

Could you please send the file to submit@ewido.net? Thanks
  #16  
Old June 25th, 2004, 03:21 PM
windowsxp_rules
 
Posts: n/a
Wink Re: Ewido SS false positive?

Greetings,
Which file do I have to send to ewido? Is it the scan report? Anyway, I was safe from dad wringing my neck! he didn't blame me. he blamed ewido. I have posted comments on www.windowscrash.com, a Windows crash submission site!
If anyone could provide the information, post it on the forum! I'll look as soon as poss!
Thank you,
windowsxp_rules
  #17  
Old June 26th, 2004, 02:31 AM
peter.ewido's Avatar
peter.ewido peter.ewido is offline
former ewido team
 
Join Date: Nov 2003
Location: Brno, Czech Republic
Posts: 737
Default Re: Ewido SS false positive?

HH.exe
  #18  
Old June 26th, 2004, 06:01 AM
windowsxp_rules
 
Posts: n/a
Wink Re: Ewido SS false positive?

Greetings,
Are you sure? I'm not sending viruses over the net. Dad would not permit it! He'd wring my neck! Any replies on the forum would be useful. I'll check as soon as poss!
Thank you,
windowsxp_rules
  #19  
Old June 26th, 2004, 06:23 AM
Pilli's Avatar
Pilli Pilli is offline
Incredibly Massive Poster
 
Join Date: Feb 2002
Location: Hampshire UK
Posts: 6,217
Default Re: Ewido SS false positive?

Hi, Just zip it up to send it, it is quite safe to send such files to AV AT companies.
__________________
"Education is not the filling of a pail, but the lighting of a fire"
Pilli's website http://www.pilliwinks.net
  #20  
Old June 28th, 2004, 10:55 AM
windowsxp_rules
 
Posts: n/a
Smile Re: Ewido SS false positive?

Hi,
I use windows xp so zipping the file should be no problem. It has built-in compression, which techie here should make use of. Dad will be sending the email, so he will wring my neck for that!
Then i'll be in serious trouble!

It's now safe to turn off your computer!!!
--windowsxp_rules
 

Wilders Security Forums > Security Products > other anti-trojan software « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 02:48 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums