PDA

View Full Version : false positive



arilo76
10-29-2007, 08:31 PM
Hi All
I want to know if any body hade the same issue with Portable application when open Thunderbird or Sunbird portable Spyware Doctor prompt me was a Trojan.Startpage and adware cinmus
I think is a false positive because three days ago was all fine (all my antimalware software is update everyday) and i check the application portable and was nothing regarding this two(Trojan.Startpage and adware cinmus)
Can you please let me know
Thanks

Arilo76

AChen
10-29-2007, 11:10 PM
Hi Arilo76,

Can you provide a screenshot of the detection and we'll investigate this further.

arilo76
10-30-2007, 07:36 PM
Hi
Thanks for your help

Here there is the screen shots

arilo76
10-30-2007, 07:41 PM
Hi
And here is when I open thunderbird

Thanks
Arilo76

AChen
10-30-2007, 11:15 PM
I have passed this info to the Malware Research Centre for further analysis

AChen
10-31-2007, 03:12 AM
We have tested (DB version: 3.08470) and installed both Sunbirdportable and ThunderbirdPortable and SD did not detected the files mentioned in you're screenshots. Could you send us the files to ensure the sources/download are the same and we'll look into this further.

arilo76
10-31-2007, 09:13 AM
Hi Achen
Here is where I download the portabelApps suite
http://portableapps.com/suite

Thanks
Arilo76

Reodor
10-31-2007, 09:31 AM
Hi Achen
Here is where I download the portabelApps suite
http://portableapps.com/suite

Thanks
Arilo76

According to Your own posting (?) on the 'portable forum'
problem was in the .exe file and not the security prg's??

http://portableapps.com/node/9857

kentroup
10-31-2007, 10:20 AM
According to Your own posting (?) on the 'portable forum'
problem was in the .exe file and not the security prg's??

http://portableapps.com/node/9857

Typically, what is happening here is that spyware doctor is identifying the program loader exe file as being the problem, caused by its running modules in the %temp% folder (usually Registry.dll).
So, on the face of it, the exe file is getting the blame but it is really the dll file that is getting identified.

Reodor
10-31-2007, 10:57 AM
Typically, what is happening here is that spyware doctor is identifying the program loader exe file as being the problem, caused by its running modules in the %temp% folder (usually Registry.dll).
So, on the face of it, the exe file is getting the blame but it is really the dll file that is getting identified.

My point was more that the problem seems to have been solved by downloading a new .exe file, an info that might have been useful for PC Tools. Unfortunately this type of problems/apps might turn into a 'chicken and egg' discusion.
I have had cases where memmory stick containing portable apps have been scanned by McAfee without problem, but when running the apps it blocks them. The same goes for some hacked/cracked games. Scanning the disk/stick, no problems, installing on the computer and run -no problem, but running from disk/stick:STOPPED by my security app.
Personally I would preferr my security apps to block anything from running on my comp that I have not installed. If a real problm, just disable the security app. Your choise: Security from 'abnormal' file activity or 'Portable'.

arilo76
11-01-2007, 08:01 PM
Hi all thanks for the response.
HI Reodor In the link you refer http://portableapps.com/node/9857 in the post I mention an other problem which I was unable to reinstall portableapps in the Usb pen drive after format the drive ( follow a quote from the forum from portable apps “I decided to close the application and decided to down load a new version of the suite (first time I downloaded was a week a go) and even the usb was out of the package I diced to format and install the suite I download a minute ago.
When I double click the installer I select the usb where I wan to install the application suite and I get an error sorry a message
F:\PortableApps_Suite_Standard_1.0exe is not supported archive”)
When I say the problem was solve in the next post was referring I could install portableapps back in the USB but the issue with SD still present and thought it could be handy for the everybody to post this issue in PCtools forum.
Please don’t think I try to be polemic but I should had mention the problem with SD was not solve in the post of portableapps.
My Fault!!!
:o
The reason why I’m using the Portableapps how you can imaging is handy to have all your email and your appointments with you with out have to buy a blackberry or what else.

Thanks for the help

Reodor
11-02-2007, 04:27 AM
Where I live 'portable apps' is rather common, and mainly in various cracked versions.
Internet cafe's everywhere and most infected. Quite a lot of 'travelling' sales people carry portable's instead of bringing the lap-top around, much easier. Hook them up whenever a comp is available and have the files they need like office etc. The new 'Open Office' has become rather popular in that way.
The same system is used by the illegal gambling syndicates! They do not use own comps as they are traceable. By using the 'portable apps' and hiding behind other comps they are next to untracable. Move around to a new location every day, just need a comp at a certain time every day to get online. Eay to hide, not as visible to police or whoever as carrying a comp!
My McAfee seems to auto-scan sticks inserted into the USB ports, and if ok accept whatever is going on inside the stick. However if the program in the stick tries to start activities on my hard drive, temp install of .exe or .dll's -I get the warning/blocking! The system is even use for 'distributing' pirated DVD's of different kinds to their dealers around the world and locally. How to trace, who to blame? No traces in the comp - all went from the stick!
One may learn a lot from the crooks!!
I have requested the 'auto scan' function to be included in PCTIS/SD and not only as an on-demand feature.

AChen
11-05-2007, 12:44 AM
Arilo76, this should now be resolved. Please let me know if you are still receiving these FP detections :)

arilo76
11-14-2007, 07:09 PM
Hi sorry for the delay for my post. :o
Yes all is fine thank you again for your help :)
Arilo76