Wilders Security Forums  

Go Back   Wilders Security Forums > Security Products > other anti-virus software
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old December 19th, 2005, 04:10 PM
beethoven's Avatar
beethoven beethoven is offline
Frequent Poster
 
Join Date: Dec 2004
Posts: 719
Default win32:ircbot-KL

Avast came up with an alert to show that gss.exe has been infected by win32:ircbot_Kl Trojan. I have not yet been able to run the file via jotti or kaspersky online. As this file is more than 1mb, how could I get some independant confirmation?
Could that be a false positive?

Last edited by beethoven : December 19th, 2005 at 04:23 PM.
  #2  
Old December 19th, 2005, 04:47 PM
beethoven's Avatar
beethoven beethoven is offline
Frequent Poster
 
Join Date: Dec 2004
Posts: 719
Default Re: win32:ircbot-KL

Not sure why this was moved - I still think it is likely that the alert is a false positve and as such would be interesting to the developer of Ghost security and the other users there.
  #3  
Old December 19th, 2005, 05:11 PM
Bubba's Avatar
Bubba Bubba is offline
Global Moderator
 
Join Date: Apr 2002
Posts: 11,279
Default Re: win32:ircbot-KL

Quote:
Originally Posted by beethoven
Not sure why this was moved - I still think it is likely that the alert is a false positve and as such would be interesting to the developer of Ghost security and the other users there.
Given that your Avast AV program is giving you an alert and given that you would like an "independant confirmation"....to me personally it resides in an appropriate Forum whereby users of an AV program might frequent and give you that confirmation if they also use regdefend.

Of course that would have been my reasoning for moving it if I had seen it first
  #4  
Old December 19th, 2005, 05:40 PM
tazdevl's Avatar
tazdevl tazdevl is offline
Frequent Poster
 
Join Date: May 2004
Location: AZ, USA
Posts: 837
Default Re: win32:ircbot-KL

Install KAV or Bitdefender's online scanner and see if it finds it.
  #5  
Old December 19th, 2005, 06:01 PM
beethoven's Avatar
beethoven beethoven is offline
Frequent Poster
 
Join Date: Dec 2004
Posts: 719
Default Re: win32:ircbot-KL

Downloading KAV right now
  #6  
Old December 19th, 2005, 06:27 PM
RejZoR's Avatar
RejZoR RejZoR is offline
Polymorphic Sheep
 
Join Date: May 2004
Location: Europe/Slovenia/Ljubljana
Posts: 5,367
Default Re: win32:ircbot-KL

Jotti works with samples up to 10MB.
Also, is it so hard to verify source of the program? Google it maybe?
__________________
RejZoR's Little Secrets
  #7  
Old December 19th, 2005, 06:50 PM
beethoven's Avatar
beethoven beethoven is offline
Frequent Poster
 
Join Date: Dec 2004
Posts: 719
Default Re: win32:ircbot-KL

Kav is still scanning overal but looking at the individual files, nothing showed up.
Jotti also did not show anything including Avast. This brings me back to the original thought that Avast is showing gss.exe as a false positive and perhaps Jason might want to contact Avast?
  #8  
Old December 19th, 2005, 07:33 PM
Bubba's Avatar
Bubba Bubba is offline
Global Moderator
 
Join Date: Apr 2002
Posts: 11,279
Default Re: win32:ircbot-KL

Quote:
Originally Posted by beethoven
This brings me back to the original thought that Avast is showing gss.exe as a false positive and perhaps Jason might want to contact Avast?
Almost all threads where a False positive has been mentioned....programmers request the user contact the guilty program.
  #9  
Old December 19th, 2005, 07:47 PM
beethoven's Avatar
beethoven beethoven is offline
Frequent Poster
 
Join Date: Dec 2004
Posts: 719
Default Re: win32:ircbot-KL

If I were the developer of a software program I would not want to rely on users to act on my behalf. Some of them maybe lazy, don't know how to approach the correct people...
Personlly I would find it important to ensure that my software is not incorrectly shown as problematic and most likely I have existing contacts in the industry to get things sorted out quicker. But then again, I maybe wrong.
  #10  
Old December 19th, 2005, 11:22 PM
Jason_R0's Avatar
Jason_R0 Jason_R0 is offline
Developer
 
Join Date: Feb 2005
Location: Australia
Posts: 1,038
Default Re: win32:ircbot-KL

If a company adds a false positive into its signature database, the onus is on them to fix it, not every developer they falsely claim is a virus/worm/spyware. Does it make you feel secure knowing your anti-virus company is having problems adding signatures to their database that it incorrectly flags other programs?
  #11  
Old December 19th, 2005, 11:50 PM
beethoven's Avatar
beethoven beethoven is offline
Frequent Poster
 
Join Date: Dec 2004
Posts: 719
Default Re: win32:ircbot-KL

Jason, I fully agree that the mistake for FP is with the AV program and that they have to fix it. My point was just that not every user will take the steps to let the "faulty" program know that they should do something.
While I did send an email to their address, I don't know when and if they will take any amendment. If I am right and it is a FP, the longer it takes the more people will be unnecessarily alarmed by the innocent software, in this case RD.

As for FP in general, I had them a few times. Some progs seem to better at avoiding them than others, still I guess we have to live with them to a certain degree.
  #12  
Old December 20th, 2005, 05:16 AM
RejZoR's Avatar
RejZoR RejZoR is offline
Polymorphic Sheep
 
Join Date: May 2004
Location: Europe/Slovenia/Ljubljana
Posts: 5,367
Default Re: win32:ircbot-KL

I don't get it, whats the problem? It's a well known thing that FP's are fixed by AV vendor only. So, usually you send the FP report to AV vendor and they'll fix it. There were false positives by several AV vendors on my programs and users reported it to me FIRST. So i dealt with the FP by myself as developer.
So basically there ARE two ways, depends how people react.
Honestly, false positives aren't such a big deal imo. They happen to everyone, starting at Norton and going through NOD32, BitDefender, McAfee, Kaspersky, avast!, AVG, AntiVir blablabla etc etc...
__________________
RejZoR's Little Secrets
  #13  
Old December 20th, 2005, 07:21 AM
jbarr's Avatar
jbarr jbarr is offline
Infrequent Poster
 
Join Date: Apr 2005
Posts: 20
Default Re: win32:ircbot-KL

Hi Beethoven,

I was experiencing the same problem as you. But it appears that Avast! has taken care of the issue with its latest virus definition update:
VPS file version: 0551-1, Compilation date: 12-20-05

The RegDefend program did not open at startup, however upon manually opening it, the program opened without a virus warning.

Hoping Avast!'s technicians will acknowledge this assumption on my part. See my post on Avast! support forum:

http://forum.avast.com/index.php?topic=18152.0
  #14  
Old December 20th, 2005, 06:32 PM
tazdevl's Avatar
tazdevl tazdevl is offline
Frequent Poster
 
Join Date: May 2004
Location: AZ, USA
Posts: 837
Default Re: win32:ircbot-KL

Exclude the directory where the app is located or exclude the file itself from scans. I think at this point you can confirm it's a FP. If you still aren't comfy, scan with BitDefender's Online Scanner.

Last edited by tazdevl : December 20th, 2005 at 06:49 PM.
  #15  
Old December 20th, 2005, 08:43 PM
jbarr's Avatar
jbarr jbarr is offline
Infrequent Poster
 
Join Date: Apr 2005
Posts: 20
Default Re: win32:ircbot-KL

Thanks tazdevl, an avast! support forum moderator has confirmed that this issue has been resolved with their virus database update earlier today.

But, in the future, I'll certainly keep your suggestion in mind, to exclude the file from an AV scan, in an effort to determine if the warning is a false positive one. Your feedback is appreciated
 

Wilders Security Forums > Security Products > other anti-virus software « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 08:13 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums