A² Square -false positive?

Discussion in 'other anti-trojan software' started by jayt, Dec 11, 2004.

Thread Status:
Not open for further replies.
  1. jayt

    jayt Registered Member

    Joined:
    Aug 30, 2004
    Posts:
    345
    Location:
    PA - USA
    I just downloaded the new (large) update to A² Squared and ran it. It told me that I was infected with the worm Win.32.bagle.n. It said that the infected file was in C:/Windows. Actually the taskmon file which it said was infected is a normal file on Win9x and WinMe in the C:/Windows folder. From all I can read,if Win.32.bagle.n infects this file it is created in C:/Windows/System.
    Also, I ran EZ AV, Stinger.exe, Rav Online AV, and CA Associates Online AV, as well as AdAware, and Spybot, and nothing else indicates any kind of infection. Wouldn't you assume that this is a false positive?
    I also checked that particular file with Kaspersy AV, and it was clean.
     
    Last edited: Dec 11, 2004
  2. Don Pelotas

    Don Pelotas Registered Member

    Joined:
    Jun 29, 2004
    Posts:
    2,257
    Probably a falsepositive, submit it to be sure. :)
     
  3. jayt

    jayt Registered Member

    Joined:
    Aug 30, 2004
    Posts:
    345
    Location:
    PA - USA
    Thanks - I submitted it :)
     
  4. jayt

    jayt Registered Member

    Joined:
    Aug 30, 2004
    Posts:
    345
    Location:
    PA - USA
    Thanks to A² Squared staff. The false positive in taskmon.exe has already been fixed with today's download of updates. :)
     
  5. TopperID

    TopperID Registered Member

    Joined:
    Oct 1, 2004
    Posts:
    1,527
    Location:
    London
    A2 has been having some big changes recently, including an almost doubling of it's signature base to over 43,000 sigs. A small number of these have been causing problems with FPs, but the A2 team have been working hard to correct them when they become aware of them.

    A2 is much improved of late.
     
  6. hayc59

    hayc59 Guest

    Jay, good work by a great team!!
     
Thread Status:
Not open for further replies.