False positive Adware.Cydoor on rundll32.exe

Discussion in 'Trojan Defence Suite' started by FanJ, Jul 23, 2004.

Thread Status:
Not open for further replies.
  1. Jooske

    Jooske Registered Member

    Joined:
    Feb 12, 2002
    Posts:
    9,713
    Location:
    Netherlands, EU near the sea
    So do submit the file as it was deleted from detection many days ago.
    I suppose you did update the radius file each day? With that it can't even be detected anymore, so either you didn't update properly each day or something else is the matter.
     
  2. dee

    dee Registered Member

    Joined:
    Jul 1, 2003
    Posts:
    72
    Yes, the radius updates have been done faithfully every day yet TDS3 displays the same alarm. NOD 32 has found nothing & I haven't d/loaded anything.

    But when I get TDS3 to scan C drive, it finds nothing, & the alarm then disappears from the interface. I'm sure my radius update is bound to catch up with this false positive and I just wonder why I'm so "blessed".
     
  3. FanJ

    FanJ Guest

    Hi Dee,

    Are you sure that your TDS-3 is showing you this:

    19:17:52 [Init] • Systems Initialised [36478 references - 14495 primaries/10141 traces/11842 variants/other]
    19:17:52 [Init] Radius Systems loaded. <Databases updated 04-08-2004>


    What is exactly the alert from TDS-3?
    Please post a scandump.
     
  4. dee

    dee Registered Member

    Joined:
    Jul 1, 2003
    Posts:
    72
    Yes, those are exactly the same figures shown in TDS3 here.
    Scandump txt:-

    Scan Control Dumped @ 08:20:24 05-08-04
    File Trace: Default trojan filename: Worm please submit.

    But the "problem" is solved, hopefully permanently. I'd deleted the extra [0 KB] rundll32.exe - but it's back ! Closed TDS3, deleted that pesky file & emptied Recycle Bin AGAIN, sacrificed a virtual white chicken, then fired up TDS3 & no alarm now.


    File: C:\Rundll32.exe
     
  5. FanJ

    FanJ Guest

    Hi Dee,

    I'm really happy that you managed to solve it ! :)

    It must be that "sacrificed a virtual white chicken" that did the trick ;) ;)

    Please keep us informed in case that alert might return...

    Regards, Jan.
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.