Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > malware problems & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old March 8th, 2005, 08:40 PM
ninja_style ninja_style is offline
Infrequent Poster
 
Join Date: Oct 2004
Posts: 41
Default is this a false positive?

ok, i installed the trial version of kaspersky prototype and it detected these two files:
1) C:\WINDOWS\_MSRSTRT.EXE
2) C:\System Volume Information\_restore{2030750F-248F-4951-9149-139762C4DA9F}\RP341\A0108232.exe

i am wondering if they are false positives or virus'?

thanks

Last edited by ninja_style : March 8th, 2005 at 08:54 PM.
  #2  
Old March 8th, 2005, 08:50 PM
Randy_Bell's Avatar
Randy_Bell Randy_Bell is offline
Updates Team
 
Join Date: May 2002
Location: Santa Clara, CA
Posts: 3,053
Default Re: is this a false positive?

What NAME did it give to the virus it detected?
  #3  
Old March 8th, 2005, 08:57 PM
ninja_style ninja_style is offline
Infrequent Poster
 
Join Date: Oct 2004
Posts: 41
Default Re: is this a false positive?

Quote:
Originally Posted by Randy_Bell
What NAME did it give to the virus it detected?
lol, hmm, it says "x-files" "not-a-virus:Tool.Win32.Reboot" lol, if it's supposed to be a porn file or whatever i wanna deleted i don't wanted in my computer, but i am asking if it's safe to deleted?
  #4  
Old March 8th, 2005, 09:27 PM
Randy_Bell's Avatar
Randy_Bell Randy_Bell is offline
Updates Team
 
Join Date: May 2002
Location: Santa Clara, CA
Posts: 3,053
Default Re: is this a false positive?

Quote:
Originally Posted by ninja_style
lol, hmm, it says "x-files" "not-a-virus:Tool.Win32.Reboot" lol, if it's supposed to be a porn file or whatever i wanna deleted i don't wanted in my computer, but i am asking if it's safe to deleted?
OH OK, well, that really isn't a viral detection, apparently you are loading the supersecure bases: "normal" + "extended" + "x" bases. It is the "normal" bases which identify malware {worm, virus, trojan, ect.}; the "extended+x" bases flag extra stuff which may or may not be malicious. So if you are unsure, just keep that file, it isn't a serious threat. KAV is just flagging it as a suspicious file or possible security risk, in the extra bases you have loaded. And you are right the "x" bases detect porn-related stuff as well.
  #5  
Old March 8th, 2005, 10:40 PM
ninja_style ninja_style is offline
Infrequent Poster
 
Join Date: Oct 2004
Posts: 41
Default Re: is this a false positive?

Quote:
Originally Posted by Randy_Bell
OH OK, well, that really isn't a viral detection, apparently you are loading the supersecure bases: "normal" + "extended" + "x" bases. It is the "normal" bases which identify malware {worm, virus, trojan, ect.}; the "extended+x" bases flag extra stuff which may or may not be malicious. So if you are unsure, just keep that file, it isn't a serious threat. KAV is just flagging it as a suspicious file or possible security risk, in the extra bases you have loaded. And you are right the "x" bases detect porn-related stuff as well.
thanks for your help, but how do i disable the extra bases, i would like to use the extended only, in the old version, you could choose if you wanted normal, extended, or extra bases, but in this one you have a different option it looks like this: http://img150.exs.cx/img150/7317/untitled2mp.jpg but i don't know which one to uncheck, i would only like to use the extended only, not the extra or whatever it's called. i am assuming the extra must be the the third one, which has riskware: remote access tools, dialers, jokes...i am gonna go head and uncheck that for now, assuming it's the extra bases.
  #6  
Old March 11th, 2005, 10:39 AM
Randy_Bell's Avatar
Randy_Bell Randy_Bell is offline
Updates Team
 
Join Date: May 2002
Location: Santa Clara, CA
Posts: 3,053
Default Re: is this a false positive?

Quote:
Originally Posted by ninja_style
i am assuming the extra must be the the third one, which has riskware: remote access tools, dialers, jokes...i am gonna go head and uncheck that for now, assuming it's the extra bases.
Not sure but I think what you have done is correct; I myself have older versions of KAV and have never used anything but the normal bases.
 

Wilders Security Forums > Other Security Topics > malware problems & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 02:30 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums