WDGC Posted January 14, 2006 Posted January 14, 2006 About a week ago I downloaded PsTools 2.24 from the Sysinternals website:http://www.sysinternals.com/index.htmlThe latest avast! A-V update [0602-3, 13/01/06] reports Win32:Doomber-C [Wrm], which it calls a Virus/Worm, as being present in psinfo.exe, which is a component of PsTools 2.24.Prior to the 0602-3, 13/01/06 update, avast! did not detect this "virus/worm" and nor do any other scanning programs I use - Ad-Aware, Spybot, MSASW, ewido, Webroot Spy Sweeper, all with latest definitions.It seems highly unlikely a program from a site of the eminence and standing of Sysinternals would contain a virus/worm.Is this detection a false positive?Any information regarding this matter would be appreciated..
atomizer Posted January 14, 2006 Posted January 14, 2006 contact them directly and find out. i highly suspect that's a false positive.
WDGC Posted January 14, 2006 Author Posted January 14, 2006 I have done so.http://forum.avast.com/index.php?topic=186...w;topicseen#new
atomizer Posted January 14, 2006 Posted January 14, 2006 cool.if you think about it, post back with the results if you send the file to them.
WDGC Posted January 14, 2006 Author Posted January 14, 2006 I also uploaded the file to Virus Total and Kaspersky:http://www.virustotal.com/xhtml/index_en.htmlhttp://www.kaspersky.com/scanforvirusHere are the results:14/01/2006Jotti's malware scan 2.99-TRANSITION_TO_3.00File to upload & scan: VirusServiceService load:0% 100%File: Psinfo.exeStatus:POSSIBLY INFECTED/MALWARE (Note: this file has been scanned before. Therefore, this file's scan results will not be stored in the database) (Note: this file was only classified as malware by scanners known to generate more false positives than the average scanner. Do not consider these results definately accurate. Also, because of this, results of this scan will not be recorded in the database.)MD5 ed55f8877ff59fc4780bfaa91d0dcdfbPackers detected:-Scanner resultsAntiVirFound nothingArcaVirFound nothingAvastFound Win32:Doomber-CAVG AntivirusFound nothingBitDefenderFound nothingClamAVFound nothingDr.WebFound nothingF-Prot AntivirusFound nothingFortinetFound nothingKaspersky Anti-VirusFound nothingNOD32Found nothingNorman Virus ControlFound nothingUNAFound nothingVBA32Found nothingThis is a report processed by VirusTotal on 01/14/2006 at 06:34:41 (CET) after scanning the file "Psinfo.exe" file.Antivirus Version Update ResultAntiVir 6.33.0.77 01.13.2006 no virus foundAvast 4.6.695.0 01.13.2006 Win32:Doomber-CAVG 718 01.13.2006 no virus foundAvira 6.33.0.77 01.13.2006 no virus foundBitDefender 7.2 01.14.2006 no virus foundCAT-QuickHeal 8.00 01.11.2006 no virus foundClamAV devel-20051123 01.13.2006 no virus foundDrWeb 4.33 01.13.2006 no virus foundeTrust-Iris 7.1.194.0 01.14.2006 no virus foundeTrust-Vet 12.4.1.0 01.13.2006 no virus foundEwido 3.5 01.13.2006 no virus foundFortinet 2.54.0.0 01.14.2006 no virus foundF-Prot 3.16c 01.13.2006 no virus foundIkarus 0.2.59.0 01.13.2006 no virus foundKaspersky 4.0.2.24 01.14.2006 no virus foundMcAfee 4674 01.13.2006 no virus foundNOD32v2 1.1364 01.13.2006 no virus foundNorman 5.70.10 01.13.2006 no virus foundPanda 9.0.0.4 01.13.2006 no virus foundSophos 4.01.0 01.14.2006 no virus foundSymantec 8.0 01.14.2006 no virus foundTheHacker 5.9.2.074 01.14.2006 no virus foundUNA 1.83 01.13.2006 no virus foundVBA32 3.10.5 01.13.2006 no virus foundVirusTotal is a free service offered by Hispasec Sistemas. There are no guarantees about the availability and continuity of this service. Although the detection rate afforded by the use of multiple antivirus engines is far superior to that offered by just one product, these results DO NOT guarantee the harmlessness of a file. Currently, there is not any solution that offers a 100% effectiveness rate for detecting viruses and malware.Kaspersky File ScannerYou're clean!Kaspersky Anti-Virus has not detected any viruses at this time in the file you submitted.However, only a fully-functional antivirus solution with regularly updated virus definitions can ensure comprehensive protection against malware. If you do not have an antivirus solution installed, you may wish to consider purchasing one today.* Download a trial version of Kaspersky Anti-Virus* Purchase Kaspersky Anti-Virus in our E-Store* Purchase Kaspersky Anti-Virus from a certified partnerScanned file: Psinfo.exePsinfo.exe - OKStatistics:Known viruses: 171751 Updated: 14-01-2006File size (Kb): 132 Virus bodies: 0Files: 1 Warnings: 0Archives: 0 Suspicious: 0.
LLXX Posted January 14, 2006 Posted January 14, 2006 From a manual inspection of the file, it contains many network paths and networking-related items that look suspicious, as well as containing an appended executable. Perhaps that was why it was detected as a worm.
WDGC Posted January 14, 2006 Author Posted January 14, 2006 False positive fixed.The latest avast! A-V update [0602-4, 14/01/06] doesn't detect Win32:Doomber-C [Wrm] as being present in psinfo.exe.
atomizer Posted January 14, 2006 Posted January 14, 2006 i just scanned it with my trusty ClamWin and came up clean.
WDGC Posted January 14, 2006 Author Posted January 14, 2006 atomizer said: i just scanned it with my trusty ClamWin and came up clean.Well, I should hope so - as my last post indicates - the avast! detection was a false positive.Apart from that did you not read the results I posted earlier?To wit:ClamAV devel-20051123 01.13.2006 no virus foundClamAVFound nothing.
atomizer Posted January 15, 2006 Posted January 15, 2006 WDGC said: Well, I should hope so - as my last post indicates - the avast! detection was a false positive.Apart from that did you not read the results I posted earlier?i did, but i didn't look for Clam because i just assumed it wouldn't be there
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now