PDA

View Full Version : SD5 false positive


rdmaloyjr
05-19-2007, 08:56 PM
A couple of days ago I downloaded SD5. It have http://spyros.atspace.com/ bookmarked. SD5 detected it as a high threat. I didn't have the page opened at any time while SD5 was on my computer. spyros.atspace.com is Spyros's website. Spyros is a respected member of avast! forums and I don't believe he would have a site that has malware & phishing. No other infection was found.

Also, SD5 froze Opera & my computer in cycles. It would freeze Opera, then free it. Then it freeze my whole computer, then free it.

I uninstalled SD5 shortly afterwards.

Jinih
05-20-2007, 12:46 AM
If you want, you can put http://spyros.atspace.com/ on SD Global Action list.

in SD go to 'Settings' >> 'Global Action List'.

Click 'Add' and a box will appear. I think it says 'Add Rule' or something

In that box find a drop down box that says ' Select data type: ' and choose " Web site address/cookie "

Put the site URL to that box, check the always allow button and choose "add"


also about the freezing, my guess it is because SD automatically search for update and your comp looks like it freeze. I have the same problem, but after I disable the option for SD to get update automatic. The problem dissapear.

Support
05-20-2007, 03:16 PM
Have you tried to disable the on gaurd protection. To disable "File Guard" and Browser Gaurd.

Open Spyware Doctor and Click on the OnGuard button then Select "File Guard/Browser Gaurd" and disable the gaurds.

I hope this will solve your problem

AChen
05-22-2007, 07:17 AM
A couple of days ago I downloaded SD5. It have http://spyros.atspace.com/ bookmarked. SD5 detected it as a high threat. I didn't have the page opened at any time while SD5 was on my computer. spyros.atspace.com is Spyros's website. Spyros is a respected member of avast! forums and I don't believe he would have a site that has malware & phishing. No other infection was found.

Also, SD5 froze Opera & my computer in cycles. It would freeze Opera, then free it. Then it freeze my whole computer, then free it.

I uninstalled SD5 shortly afterwards.

Hey rdmaloyjr,

I have done some testing on this and Spyware Doctor does not block http://spyros.atspace.com/.

Spyros
05-25-2007, 03:05 PM
Hello,

My name is Spyros and I'm the creator of spyros.atspace.com

I'd like to assure everyone that my web-page does NOT contain any sign of scripts or malware, not even pictures. It is just a freeware site writen in HTML and other than that the only thing I use is a counter provided by shinystat, to track number of visitors (not even IP's).

I am really surprised by rdmaloyjr's post about SD5 flagging my web-page, although AChen's post is reassuring.
I would like the maintainers of SD5 to look into this, please.

Thank you.

tom.tdw
05-25-2007, 06:42 PM
maby the bookmark had been tampered with/contained a word (or combination of carictors) that made sd detect it

the location of the site is not the only thing checked

rdmaloyjr
05-26-2007, 04:23 PM
Hey rdmaloyjr,

I have done some testing on this and Spyware Doctor does not block http://spyros.atspace.com/.

SD5 didn't block http://spyros.atspace.com/ , it just detected the bookmark for http://spyros.atspace.com/ as a high threat.

I didn't go to http://spyros.atspace.com/ while I had SD5 on my computer so I don't know what would've happened if I did try to open it. I can't say whether it would've blocked it or not.

Originally Posted by rdmaloyjr
A couple of days ago I downloaded SD5. It have http://spyros.atspace.com/ bookmarked. SD5 detected it as a high threat. I didn't have the page opened at any time while SD5 was on my computer. spyros.atspace.com is Spyros's website. Spyros is a respected member of avast! forums and I don't believe he would have a site that has malware & phishing. No other infection was found.

Also, SD5 froze Opera & my computer in cycles. It would freeze Opera, then free it. Then it freeze my whole computer, then free it.

I uninstalled SD5 shortly afterwards.

redwolfe_98
05-26-2007, 06:42 PM
while spyros's webpage might be (is) perfectly fine, there may be other webpages that use the same domain, "atspace.com", that are recognized as being "bad", and that is why the spyros.atspace.com link was flagged..

i have seen the same thing where SD was flagging a webpage that i had in my "trusted sites" zone.. the webpage was safe, but there were other webpages that used the same domain that were recognized as being bad, and so SD was flagging it..

i wouldn't worry about it..