Wilders Security Forums  

Go Back   Wilders Security Forums > Security Products > other anti-trojan software
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old May 31st, 2005, 05:20 AM
Labrie's Avatar
Labrie Labrie is offline
Regular Poster
 
Join Date: Oct 2004
Location: Valencia, Spain
Posts: 135
Default ewido false positive?

hi guys!

ewido have found as worm.finaldo a file named accwiz.exe in my windows system folder...well i run a scan over jotti´s place and none av has found nothing...i wonder if its a false positve?

tx.
__________________
"The situation is definitely hopeless, but not serious." -Billy Wilder-
  #2  
Old May 31st, 2005, 06:00 AM
Edwin024's Avatar
Edwin024 Edwin024 is offline
Frequent Poster
 
Join Date: Nov 2004
Posts: 999
Default Re: ewido false positive?

Look at the other thread on Ewido's beta 3.5. I think it very well might be a fp.
  #3  
Old May 31st, 2005, 07:20 AM
peter.ewido's Avatar
peter.ewido peter.ewido is offline
former ewido team
 
Join Date: Nov 2003
Location: Brno, Czech Republic
Posts: 737
Default Re: ewido false positive?

Could you please send the file to submit@ewido.net? Thx
  #4  
Old May 31st, 2005, 07:25 AM
Edwin024's Avatar
Edwin024 Edwin024 is offline
Frequent Poster
 
Join Date: Nov 2004
Posts: 999
Default Re: ewido false positive?

I have sent in the following information. A lot of false positives after a full scan:

---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------

+ Created on: 13:19:18, 31-5-2005
+ Report-Checksum: 680D03C

+ Scan result:

[3316] C:\WINDOWS\system32\mscomctl.ocx -> Backdoor.Ciadoor.13
C:\Apps\Your Unistaller 2005\urUninstaller.exe -> Heuristic.Win32.Backdoor
C:\Downloads\software\Karperskyremove.zip/KAV_Registry_Clean.exe -> Heuristic.Win32.AVKiller
C:\Downloads\software\Kasp_Reg_Remove.zip/KAV_Registry_Clean.exe -> Heuristic.Win32.AVKiller
C:\Downloads\software\mwav.exe/mwavscan.com -> Heuristic.Win32.AVKiller
C:\Downloads\yu2005dev.zip/urUninstaller.exe -> Heuristic.Win32.Backdoor
C:\Program Files\Advanced System Optimizer\BackupManager.exe -> Heuristic.Win32.Worm
C:\Program Files\LeechGet 2004\LeechGet.exe -> Heuristic.Win32.Dialer
C:\Program Files\LeechGet 2004\LGOptions.exe -> Heuristic.Win32.Dialer
C:\Program Files\MSN Messenger\msnmsgr.exe -> Heuristic.Win32.Backdoor
C:\WINDOWS\pchealth\helpctr\System\NetDiag\dglogs.htm -> Trojan.Io
C:\WINDOWS\system32\MSCOMCT2.OCX -> Backdoor.Ciadoor.13
C:\WINDOWS\system32\MSCOMCTL.OCX -> Backdoor.Ciadoor.13
E:\Warez\Audiograbber\agsetup.exe -> TrojanDownloader.TSUpdate.i
E:\Warez\Kaspersky Anti-Virus 5\KAV_Registry_Clean.zip/KAV_Registry_Clean.exe -> Heuristic.Win32.AVKiller
E:\Warez\LeechGet\crack\LeechGet.exe -> Heuristic.Win32.Dialer
E:\Warez\McAfee personal Firewall plus\McAfeePersonalFirewallPlus.exe -> TrojanDownloader.TSUpdate.i
E:\Warez\Norton Internet Security 2005\Setup\support\navtools\repair\gaobot\fxgaobot.exe ->

Heuristic.Win32.HostFile
E:\Warez\Norton Internet Security 2005\Setup\support\redist\msredist\mscomctl.ocx -> Backdoor.Ciadoor.13
E:\Warez\Outpost firewall\OutpostProInstall.exe -> TrojanDownloader.TSUpdate.i
E:\Warez\Outpost firewall\OutpostProInstall.exe/OUTPOST.EXE -> Heuristic.Win32.AVKiller
E:\Warez\PCMedik\crack\crack.rar/PcMedik.exe -> Heuristic.Win32.Backdoor
E:\Warez\Your Unistaller 2005\urUninstaller.exe -> Heuristic.Win32.Backdoor
E:\Warez\ZoneAlarm Pro 5\zapSetup_51_011.exe -> TrojanDownloader.TSUpdate.i
E:\Warez\ZoneAlarm Suite 5.1.033\zaSuiteSetup_51_033_000.exe -> TrojanDownloader.TSUpdate.i
H:\backup13mei\Downloads\software\Karperskyremove.zip/KAV_Registry_Clean.exe -> Heuristic.Win32.AVKiller
H:\backup13mei\Downloads\software\Kasp_Reg_Remove.zip/KAV_Registry_Clean.exe -> Heuristic.Win32.AVKiller
H:\backup13mei\Downloads\software\mwav.exe/mwavscan.com -> Heuristic.Win32.AVKiller
H:\backup22mei\Downloads\software\Karperskyremove.zip/KAV_Registry_Clean.exe -> Heuristic.Win32.AVKiller
H:\backup22mei\Downloads\software\Kasp_Reg_Remove.zip/KAV_Registry_Clean.exe -> Heuristic.Win32.AVKiller
H:\backup22mei\Downloads\software\mwav.exe/mwavscan.com -> Heuristic.Win32.AVKiller


::Report End
  #5  
Old May 31st, 2005, 07:54 AM
Labrie's Avatar
Labrie Labrie is offline
Regular Poster
 
Join Date: Oct 2004
Location: Valencia, Spain
Posts: 135
Default Re: ewido false positive?

Quote:
Originally Posted by fish25
Could you please send the file to submit@ewido.net? Thx

sent it
__________________
"The situation is definitely hopeless, but not serious." -Billy Wilder-
  #6  
Old May 31st, 2005, 09:31 AM
Edwin024's Avatar
Edwin024 Edwin024 is offline
Frequent Poster
 
Join Date: Nov 2004
Posts: 999
Default Re: ewido false positive?

Ewido-guys: please add an ignore function to the program. This mscomctl.ocx, for instance, is an active X component which I don't want or need to loose. But Ewido's guard is bugging me every time the pc starts up that it is there. And I can do remove or none... the last is my best option now but it is no option because the next time I startup Ewido sounds the alarm again...and again...
  #7  
Old May 31st, 2005, 09:58 AM
peter.ewido's Avatar
peter.ewido peter.ewido is offline
former ewido team
 
Join Date: Nov 2003
Location: Brno, Czech Republic
Posts: 737
Default Re: ewido false positive?

An ignore list will be implemented in 3.6... As "mscomctl.ocx" is a real false positive and not a possible (un)wanted app, the best way to deal with it is to fix it
  #8  
Old May 31st, 2005, 10:39 AM
Edwin024's Avatar
Edwin024 Edwin024 is offline
Frequent Poster
 
Join Date: Nov 2004
Posts: 999
Default Re: ewido false positive?

And will that happen soon? The FP's deleted I mean
  #9  
Old June 1st, 2005, 08:14 AM
Labrie's Avatar
Labrie Labrie is offline
Regular Poster
 
Join Date: Oct 2004
Location: Valencia, Spain
Posts: 135
Default Re: ewido false positive?

it was a fp..tx for the nice and quick rply EWIDO TEAM
__________________
"The situation is definitely hopeless, but not serious." -Billy Wilder-
  #10  
Old June 1st, 2005, 01:38 PM
gerardwil gerardwil is offline
Massive Poster
 
Join Date: Jan 2004
Posts: 4,510
Default Re: ewido false positive?

Hi,

I only got this FP left (Sygate). I will submit it.
Cheers,

Gerard
Attached Images
 

Last edited by Bubba : June 1st, 2005 at 02:49 PM. Reason: resized pic....blowing margins
  #11  
Old June 1st, 2005, 01:51 PM
Edwin024's Avatar
Edwin024 Edwin024 is offline
Frequent Poster
 
Join Date: Nov 2004
Posts: 999
Default Re: ewido false positive?

On my side I still see urUninstaller flagged as a false positive... and there is absolutely nothing wrong with this program.
  #12  
Old June 1st, 2005, 02:03 PM
peter.ewido's Avatar
peter.ewido peter.ewido is offline
former ewido team
 
Join Date: Nov 2003
Location: Brno, Czech Republic
Posts: 737
Default Re: ewido false positive?

Have you already submitted it?
  #13  
Old June 1st, 2005, 02:07 PM
lynchknot's Avatar
lynchknot lynchknot is offline
Frequent Poster
 
Join Date: Jun 2004
Location: SW WA
Posts: 904
Default Re: ewido false positive?

Here's some FP:


C:\Documents and Settings\me\Desktop\OutpostProInstall.exe -> TrojanDownloader.TSUpdate

C:\Program Files\Bluetack\Blocklist Manager\MSCOMCT2.OCX -> Backdoor.Ciadoor.13
C:\Program Files\Bluetack\Blocklist Manager\MSCOMCTL.OCX -> Backdoor.Ciadoor.13

It also quarantined over 2000 cookies
__________________
Firefox Themes20050620 Firefox/1.0.5
  #14  
Old June 1st, 2005, 02:11 PM
Edwin024's Avatar
Edwin024 Edwin024 is offline
Frequent Poster
 
Join Date: Nov 2004
Posts: 999
Default Re: ewido false positive?

Quote:
Originally Posted by fish25
Have you already submitted it?

I sent in the txt file after a scan where all the false positives were on... so I hope you guys saw it.

Ewido flagged a lot of legitimate programs wrongly as nasties. That is now over, apart from some programs, alas. But maybe tomorrow the next good update?
  #15  
Old June 1st, 2005, 02:12 PM
Edwin024's Avatar
Edwin024 Edwin024 is offline
Frequent Poster
 
Join Date: Nov 2004
Posts: 999
Default Re: ewido false positive?

Quote:
Originally Posted by lynchknot
Here's some FP:


C:\Documents and Settings\me\Desktop\OutpostProInstall.exe -> TrojanDownloader.TSUpdate

C:\Program Files\Bluetack\Blocklist Manager\MSCOMCT2.OCX -> Backdoor.Ciadoor.13
C:\Program Files\Bluetack\Blocklist Manager\MSCOMCTL.OCX -> Backdoor.Ciadoor.13

The mscom files are no longer seen as nasties in Ewido as far as I can tell. About Outpost you are right... Some more work to be done.
  #16  
Old June 1st, 2005, 02:13 PM
lynchknot's Avatar
lynchknot lynchknot is offline
Frequent Poster
 
Join Date: Jun 2004
Location: SW WA
Posts: 904
Default Re: ewido false positive?

I ran this last night while in bed. So there's an update?
It also quarantined over 2000 cookies
__________________
Firefox Themes20050620 Firefox/1.0.5
  #17  
Old June 1st, 2005, 03:36 PM
Just wondering
 
Posts: n/a
Default Re: ewido false positive?

Here are a few more false positives...there are a few FW leak tests, but the
ones for NetVeda, XPlite and visioneer are true FPs.
I already sent them in......Sure is a lot less than first scans.



C:\Documents and Settings\WORK1\Desktop\Downloads\xplite_trial.zip/XPlite_TRIAL.exe -> Heuristic.Win32.Backdoor2
C:\Documents and Settings\WORK1\Desktop\Tests\surfer.exe -> Heuristic.Win32.Downloader
C:\Documents and Settings\WORK1\Desktop\Tests\tooleaky.exe -> Heuristic.Win32.Downloader
C:\Documents and Settings\WORK1\Desktop\Tests\TrojDemo.exe -> Heuristic.Win32.Backdoor2
C:\Program Files\AxBx\PC Security Test 2005\PCSecurityTest.exe -> Heuristic.Win32.Backdoor2
C:\Program Files\NetVeda\Safety.Net\ipcsvc.exe -> Heuristic.Win32.Backdoor3
C:\Program Files\Visioneer\PaperPort\Pplinks.exe -> Heuristic.Win32.Keylogger
  #18  
Old June 1st, 2005, 03:40 PM
Edwin024's Avatar
Edwin024 Edwin024 is offline
Frequent Poster
 
Join Date: Nov 2004
Posts: 999
Default Re: ewido false positive?

And a few from my scan of a few minutes ago: ( a full scan by the way!)

---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------

+ Created on: 21:27:35, 1-6-2005
+ Report-Checksum: 4C97F27B

+ Scan result:

C:\Apps\Your Unistaller 2005\urUninstaller.exe -> Heuristic.Win32.Backdoor2
C:\Downloads\yu2005dev.zip/urUninstaller.exe -> Heuristic.Win32.Backdoor2
E:\Warez\Audiograbber\agsetup.exe -> TrojanDownloader.Wiser
E:\Warez\Look 'n'Stop firewall\LNSFW1-d1.zip/LNSFW1.sys -> Heuristic.Win32.Downloader
E:\Warez\Look 'n'Stop firewall\LNSFW1-d2.zip/LNSFW1.sys -> Heuristic.Win32.Downloader
E:\Warez\McAfee personal Firewall plus\McAfeePersonalFirewallPlus.exe -> TrojanDownloader.Wiser
E:\Warez\Norton Internet Security 2005\Setup\symsetup.exe -> Heuristic.Win32.AVKiller
E:\Warez\Outpost firewall\OutpostProInstall.exe -> TrojanDownloader.Wiser
E:\Warez\Your Unistaller 2005\urUninstaller.exe -> Heuristic.Win32.Backdoor2
E:\Warez\ZoneAlarm Pro 5\zapSetup_51_011.exe -> TrojanDownloader.Wiser
E:\Warez\ZoneAlarm Suite 5.1.033\zaSuiteSetup_51_033_000.exe -> TrojanDownloader.Wiser

::Report End

I have send in the files now, by the way

Last edited by Edwin024 : June 1st, 2005 at 03:58 PM.
  #19  
Old June 1st, 2005, 03:43 PM
Just wondering
 
Posts: n/a
Default Re: ewido false positive?

It shure likes to pick on FWs doesn't it.
  #20  
Old June 1st, 2005, 03:45 PM
lynchknot's Avatar
lynchknot lynchknot is offline
Frequent Poster
 
Join Date: Jun 2004
Location: SW WA
Posts: 904
Default Re: ewido false positive?

lol - "Warez" - I'd be suspicious of those for sure.

I have uruninstaller and it did not pick up on that.*edit - mine is 2004 version though.

**edit - something funny about that. I checked and there is no such thing as Your Unistaller 2005
__________________
Firefox Themes20050620 Firefox/1.0.5

Last edited by lynchknot : June 1st, 2005 at 03:53 PM.
  #21  
Old June 1st, 2005, 03:47 PM
Just wondering
 
Posts: n/a
Default Re: ewido false positive?

he he he....I just noticed that myself after double reading his report.

tsk tsk ....shame shame
  #22  
Old June 1st, 2005, 03:57 PM
lynchknot's Avatar
lynchknot lynchknot is offline
Frequent Poster
 
Join Date: Jun 2004
Location: SW WA
Posts: 904
Default Re: ewido false positive?

In fact it's even spelled wrong!

Quote:
C:\Apps\Your Unistaller 2005\urUninstaller.exe -> Heuristic.Win32.Backdoor2

I'd venture to say it may not be a FP
__________________
Firefox Themes20050620 Firefox/1.0.5
  #23  
Old June 1st, 2005, 04:00 PM
Edwin024's Avatar
Edwin024 Edwin024 is offline
Frequent Poster
 
Join Date: Nov 2004
Posts: 999
Default Re: ewido false positive?

It's about the files...not about the directory names.

And I have a dir in my E drive with the name warez where I put all the files that I download from legitimate corporate websites. I beta test urUninstaller for instance for the company which produces it... Just as I test Ewido, for the matter

That you guys have such funny ideas tell me something about you.
  #24  
Old June 1st, 2005, 04:02 PM
lynchknot's Avatar
lynchknot lynchknot is offline
Frequent Poster
 
Join Date: Jun 2004
Location: SW WA
Posts: 904
Default Re: ewido false positive?

Quote:
That you guys have such funny ideas tell me something about you.

It's not my idea, it's yours (to put legit downloads and label it "warez") It say s something about you, not us.
__________________
Firefox Themes20050620 Firefox/1.0.5
  #25  
Old June 1st, 2005, 04:04 PM
Edwin024's Avatar
Edwin024 Edwin024 is offline
Frequent Poster
 
Join Date: Nov 2004
Posts: 999
Default Re: ewido false positive?

I am from Holland, maybe that makes it that I choose names that you can't understand. It could have been software too... will rename the dir, ok?

NB: I renamed the urUninstaller dir and still the same result. Of course...
 

Wilders Security Forums > Security Products > other anti-trojan software « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 12:20 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums