ATS alert

Discussion in 'Trojan Defence Suite' started by jpc, Mar 2, 2004.

Thread Status:
Not open for further replies.
  1. jpc

    jpc Registered Member

    Joined:
    Jan 17, 2004
    Posts:
    45
    Location:
    France
    Sorry for my poor english, I'm french.
    I've had TDS3 for over 2 months and before that I used AntiTrojan Shield.
    Every days I use TDS3 and sometimes I scan my computer with ATS
    And Today, ATS tells me that it finds virus in some TDS3's files

    "ATS v.1.2.0.3
    21:33.28 - mars 2, 2004, mardi
    Started applications scan.
    Virus applications not detected.
    Memory scan.
    Virus proccesses not detected.
    Registry and system file scan.
    File C:\WINDOWS\win.ini did not contain suspicious records.
    File C:\WINDOWS\system.ini did not contain suspicious records.
    Virus PROBABLY TROJAN CLONE BIONET detected in d:\Proctection\TDS3\advscan.dll
    Virus "CaznovaIRCSpy.v2.5.server" detected in d:\Proctection\TDS3\Ext.Unpk\upx.exe
    Virus "GLSSPY.v1.0" detected in d:\Proctection\TDS3\xDynamic\TDS.Unpk\safexp.exe
    Virus "Devil.v4.0.EditDevil" detected in d:\Réseau\Avant Browser\aHTTP.exe
    Virus "GLSSPY.v1.0" detected in d:\Système\safexp\SafeXP.exe
    21:46.20
    Scan completed
    Files scanned: 19585
    Files infected: 5
    Scan speed: 26 files per second.
    Please regularly update ATS!"

    KAV find these files clean
    Do you think that ATS tells me wrong information ?
    Thank's
     
  2. Jooske

    Jooske Registered Member

    Joined:
    Feb 12, 2002
    Posts:
    9,713
    Location:
    Netherlands, EU near the sea
    Hello JPC and welcome!
    French nor English are my first languages either; this is a rather international forum so always french speaking people to help you out if needed, aren't there? (looking at gkweb, Jack and others)
    Please zip the files and send them to submit@diamondcs.com.au
    Gavin will tell you soon enough if there is anything wrong with those files.
    Mind you: TDS in the first place is a trojan scanner, not for viruses. In the Unpk folder are copies of files unpacked and scanned and after they are deleted in that or a next scan and that there is a possible nasty copy means there is or has been another original elsewhere on your system. You see the proof of this statement with your saveXP.exe on your D:\ drive.
    Bionet is most certainly in the primaries list!
    So submit the files alarmed on here and wait for Gavin's advices please!
    After that you can submit them to your scanner with Gavin's remarks so they can refine their detection, as no company is happy with possible false positives.
     
  3. jpc

    jpc Registered Member

    Joined:
    Jan 17, 2004
    Posts:
    45
    Location:
    France
    Thank's Jooske.
    I have sent the files to TDS support (submit@diamondcs.com.au) and they told me that the files are OK and that I should send all these files to ATS and tell them they are NOT trojans.
    I Have done that and "ATS support " wrote back to me that they'll remove signatures of the false trojans from the trojan definitions database immediately.
     
  4. Jooske

    Jooske Registered Member

    Joined:
    Feb 12, 2002
    Posts:
    9,713
    Location:
    Netherlands, EU near the sea
    Hey that's great to hear, glad you did and your system is really clean!
    Karma cookie for you!
     
Thread Status:
Not open for further replies.