Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > malware problems & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old March 11th, 2004, 04:29 PM
notageek's Avatar
notageek notageek is offline
Very Frequent Poster
 
Join Date: Jun 2002
Location: Ohio
Posts: 1,597
Default OK I ran a trajan scan with a free AT and this is what it came up with.

I ran Ewido to try it. It found 2 so called backdoors. The files are called UWAKEON.EXE and UWAKEOFF.EXE. They both was classified as a backdoor.enculator.01. ANyone have any idea what these files are? I also did a scan with TH and nothing came up. I did a google search on UWEAKEON and it took me to a dell support page. Oh yeah btw Ewido found these files in the c:\dell folder.
__________________
The mind is like a drunken monkey dancing on hot coals.
  #2  
Old March 12th, 2004, 04:36 AM
Paul Wilders's Avatar
Paul Wilders Paul Wilders is offline
Administrator
 
Join Date: Jul 2001
Location: The Netherlands
Posts: 12,461
Default Re:OK I ran a trajan scan with a free AT and this is what it came up with.

notageek,

These could well be false positives. Please perform a free online check in regard to these files over here, and post the results.

In case they show up clean, contact Ewido in order to get this fixed. In case you do get positive alert(s), please post the names, and we'll take it from there

regards.

paul
__________________
01110010 01100101 01100111 01100001 01110010 01100100 01110011 00100000 01110000 01100001 01110101 01101100
  #3  
Old March 12th, 2004, 04:56 AM
dvk01's Avatar
dvk01 dvk01 is offline
Global Moderator
 
Join Date: Oct 2003
Location: Loughton, Essex. UK
Posts: 3,129
Default Re:OK I ran a trajan scan with a free AT and this is what it came up with.

I've just installed it to try it out
It doesn't eem to detect very much

I keep a folder of suspect & known trojans/vieruses that NOD/TDS and others now detect and this one hasn't found any of them at all

I'll keep it installed for a while as a backup scanner but if it doesn't detect any of the trojans I get hold hold of from ther various forums then it will soon go

  #4  
Old March 12th, 2004, 07:11 AM
ronny ronny is offline
Frequent Poster
 
Join Date: Feb 2004
Location: Belgium
Posts: 231
Default Re:OK I ran a trajan scan with a free AT and this is what it came up with.

Quote:
quoting: Paul Wilders link=board=30;threadid=24295;start=0#msg142987 date=1079084210]
These could well be false positives. Please perform a free online check in regard to these files over here, and post the results.
In case they show up clean, contact Ewido in order to get this fixed. In case you do get positive alert(s), please post the names, and we'll take it from there

Indeed be VERY careful before deleting something.

Perhaps ESS is a good program, but i'm quite sure it is not really finished.
Today i found again an infected(?) file with ESS.
But because no other scanner found it infected ,i thought it is a false positive ,so i sent it to ESS.
They told me it was indeed a false positive!They said they already fixed this and that i have to do an update.
But now it comes: i've ALREADY done their latest update before i scanned and found this false positive
  #5  
Old March 12th, 2004, 07:20 AM
peter.ewido's Avatar
peter.ewido peter.ewido is offline
former ewido team
 
Join Date: Nov 2003
Location: Brno, Czech Republic
Posts: 737
Default Re:OK I ran a trajan scan with a free AT and this is what it came up with.

Code:
--------------------------------------------------------- ewido security suite - Scan report --------------------------------------------------------- + Created on: 13:18:42, 12.03.2004 + Report-Checksum: 2CF5E938 + Date of database: 11.03.2004 + Version of scan engine: v1.1 ... + Scanned items: X:\OldProblems\mswsock.dll + Scan result: No infected files found!

Try deleting every file in the "Signatures" directory and then run the online-update again

Quote:
quoting: ronny link=board=30;threadid=24295;start=0#msg143008 date=1079093480]
Perhaps ESS is a good program, but i'm quite sure it is not really finished.

It is a finished product! But all signatures had to be redone (32545 in total!) because of this: http://home.arcor.de/scheinsicherheit/rebasing.htm
False positives unfortunately never can be avoided completely, even KAV had one in winrar.exe today...
  #6  
Old March 12th, 2004, 07:34 AM
peter.ewido's Avatar
peter.ewido peter.ewido is offline
former ewido team
 
Join Date: Nov 2003
Location: Brno, Czech Republic
Posts: 737
Default Re:OK I ran a trajan scan with a free AT and this is what it came up with.

Quote:
quoting: dvk01 link=board=30;threadid=24295;start=0#msg142993 date=1079085402]
I keep a folder of suspect & known trojans/vieruses that NOD/TDS and others now detect and this one hasn't found any of them at all

Could you please send them to submit@ewido.net so we can have a look at them? Thanks!
  #7  
Old March 12th, 2004, 07:37 AM
ronny ronny is offline
Frequent Poster
 
Join Date: Feb 2004
Location: Belgium
Posts: 231
Default Re:OK I ran a trajan scan with a free AT and this is what it came up with.

Quote:
quoting: fish25 link=board=30;threadid=24295;start=0#msg143012 date=1079094006]
Try deleting every file in the "Signatures" directory and then run the online-update again

thank you.I did that but it didn't help
The false positive keeps coming
  #8  
Old March 12th, 2004, 08:22 AM
ronny ronny is offline
Frequent Poster
 
Join Date: Feb 2004
Location: Belgium
Posts: 231
Default Re:OK I ran a trajan scan with a free AT and this is what it came up with.

Ok ,terrific support at ESS. They will fix it with the next update

(at 15h02 belgium time :no more false positives, everything seems already be fixed )
  #9  
Old March 12th, 2004, 08:58 AM
notageek's Avatar
notageek notageek is offline
Very Frequent Poster
 
Join Date: Jun 2002
Location: Ohio
Posts: 1,597
Default Re:OK I ran a trajan scan with a free AT and this is what it came up with.

Paul, I checked them with KAV file checker and they came up clean. Them files came up clean wit McAfee v7, BD v7 and trojan Hunter so I was assuming they was false positives. Now I'm off to send Ewido and email letting them know about the false positives. But I still would like to kbow what these files are.
__________________
The mind is like a drunken monkey dancing on hot coals.
  #10  
Old March 12th, 2004, 09:14 AM
notageek's Avatar
notageek notageek is offline
Very Frequent Poster
 
Join Date: Jun 2002
Location: Ohio
Posts: 1,597
Default Re:OK I ran a trajan scan with a free AT and this is what it came up with.

Just to report I sent the files in and was told they are fixed. Anyway I found out what these files are for. Thanks to everyone who responded to this.
__________________
The mind is like a drunken monkey dancing on hot coals.
  #11  
Old April 1st, 2004, 12:30 AM
challanged
 
Posts: n/a
Default Re:OK I ran a trajan scan with a free AT and this is what it came up with.

I found "UWAKEOFF" in my files as well. Did you ever get an answer to what it is? if so please help here. Thanks! very confused Jerry
  #12  
Old April 1st, 2004, 12:59 AM
snapdragin's Avatar
snapdragin snapdragin is offline
Administrator
 
Join Date: Feb 2002
Location: Southern Ont., Canada
Posts: 8,415
Default Re:OK I ran a trajan scan with a free AT and this is what it came up with.

removed duplicate post - snap
__________________
@-`-,--
 

Wilders Security Forums > Other Security Topics > malware problems & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 09:39 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums