Antivir - Possible false positive?

Discussion in 'other anti-virus software' started by Drew99GT, Aug 6, 2006.

Thread Status:
Not open for further replies.
  1. Drew99GT

    Drew99GT Registered Member

    Joined:
    Jun 27, 2006
    Posts:
    338
    Location:
    Colorado Springs
    While I was running a scan with Webroot Spysweeper, Antivir guard alerted that Worm\Randon.A.51 was found. Apparently, after Googling it, it was added to the VDF file on August 3rd, yet it only alerted after running Spysweeper today. It's got several traces/sources. I also turned the heuristic on for the first time last week; don't no if that could be the issue. Anyone know anything about this? I think it's a false positive.

    One other question: after this whole thing transpired, I restored the files so I could use all the online virus scanners to see what they found; they found nothing. Of course, when I restored them, the Antivir Guard started alerting me so I clicked ignore on each alert. So I did another on demand scan with Antivir and in addition to the original files found in their original locations, Antivir found a bunch of files in C:\Documents and Settings\All Users\Application Data\Antivir Personal Edition Classic\AVSCAN-............. (there were 4 of them). What does that mean? I'm assuming it's because I kept clicking ignore on the guard alerts and because I restored the fileso_O Is Antivir alerting to stuff in the quarantine?

    I'm kinda freaked as this is the very first virus to ever be found on my 3 yr. old machine! Thanks for any info or help; I posted basically the same thing at the Antivir forum.
     
  2. pykko

    pykko Registered Member

    Joined:
    Apr 27, 2005
    Posts:
    2,236
    Location:
    Romania...and walking to heaven
    pls post the exact location where Avira found the worm.
     
  3. aigle

    aigle Registered Member

    Joined:
    Dec 14, 2005
    Posts:
    11,047
    Location:
    Saudi Arabia/ Pakistan
    u can try to upload some of these files to Jotti virus scan or virus total , to see.
     
  4. Drew99GT

    Drew99GT Registered Member

    Joined:
    Jun 27, 2006
    Posts:
    338
    Location:
    Colorado Springs
  5. Drew99GT

    Drew99GT Registered Member

    Joined:
    Jun 27, 2006
    Posts:
    338
    Location:
    Colorado Springs
    Someone at the Avira forum said it was a false positive and would be taken out of later updates. What should I do about these files in the quarantine, especially the 4 found in the Documents and Settings location?

    Thanks for the help :)
     
  6. pykko

    pykko Registered Member

    Joined:
    Apr 27, 2005
    Posts:
    2,236
    Location:
    Romania...and walking to heaven
    Well, those from system Restore can be solved easy. Turn off your system restore and they're gone. ;)
    Anyway, those from Doc and Settings you can keep them there as you may rescan them after couple of days to see if they were removed from detection. (FP was fixed). You can also restore them to a specific location e.g. Desktop and then upload those files to virustotal.com and see the result.
     
  7. Bubba

    Bubba Updates Team

    Joined:
    Apr 15, 2002
    Posts:
    11,271
    Hello Drew,

    Even tho I am a little unclear about what Antivir has found in regards to those 7 entries....I am very clear on the fact that turning off System restore as one of the first steps when working with a possible problem is wrong to suggest and one of the main drawbacks of that eroneous suggestion is that ALL restore points will be lost.

    In regards to the C:\i386\reg.exe file....am I understanding that is what Antivir is finding in regards to "Worm\Randon" :doubt:
    Also....is that reg.exe file 134KB in size and is this on a Dell computer ?

    Bubba
     
  8. lodore

    lodore Registered Member

    Joined:
    Jun 22, 2006
    Posts:
    9,006
    i would like to point out that wehn i used to run spysweeper in like version 4 my antivirus curently f-secure used to always says there was a virus in the middle of a spysweeper scan
     
  9. Drew99GT

    Drew99GT Registered Member

    Joined:
    Jun 27, 2006
    Posts:
    338
    Location:
    Colorado Springs
    Hi Bubba, Yes, my computer is a Dell Inspiron 5150 laptop. I can't tell the file size cause it's still sitting in the quarantine.
     
  10. Drew99GT

    Drew99GT Registered Member

    Joined:
    Jun 27, 2006
    Posts:
    338
    Location:
    Colorado Springs
    OK, after Mondays update, these files did turn out to be false positives. Thanks for everyone's help :thumb:
     
Loading...
Thread Status:
Not open for further replies.