CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

Online Armor Download Came With Trojan Horse

 
Post new topic   Reply to topic       All -> FavForums -> Firewalls [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
BigFelix
Warnings : 2

Captain
Captain
Premium Member

Joined: Mar 19, 2008
Posts: 506
Location: San Diego
Premium

PostPosted: Sun Apr 13, 2008 10:25 am    Post subject: Online Armor Download Came With Trojan Horse
Reply with quote

Earlier today, my daily AVG scan found two threats--both SHeur.BEKO and both infecting OA's oaui.exe. Healing left the firewall disabled. I downloaded anew, and during the installation AVG found the same Trojan Horse infecting the program. I'm now using Comodo.


_________________
The whole problem with the world is that fools and fanatics are always so certain of themselves, but wiser people so full of doubts.
    Bertrand Russell
Back to top
View users profile Send private message Send email
lordpake

Sergeant
Sergeant
Premium Member

Joined: Aug 17, 2005
Posts: 137
Location: Helsinki ~ European Union
Premium

PostPosted: Sun Apr 13, 2008 11:00 am    Post subject:
Reply with quote

That sounds to me like a heuristic false positive. Did you report this to Grisoft?


_________________
Kitten: small homicidal muffin on legs: affects human sensibilities to the point of endowing the most wanton and ruthless acts of destruction with near mythical overtones of cuteness. Not recommended for beginners, get at least two. [Fafnir]
Back to top
View users profile Send private message Visit posters website
BigFelix
Warnings : 2

Captain
Captain
Premium Member

Joined: Mar 19, 2008
Posts: 506
Location: San Diego
Premium

PostPosted: Sun Apr 13, 2008 11:14 am    Post subject:
Reply with quote

No. Why today not yesterday. I had my doubts but don't want to take any chances.


_________________
The whole problem with the world is that fools and fanatics are always so certain of themselves, but wiser people so full of doubts.
    Bertrand Russell
Back to top
View users profile Send private message Send email
lordpake

Sergeant
Sergeant
Premium Member

Joined: Aug 17, 2005
Posts: 137
Location: Helsinki ~ European Union
Premium

PostPosted: Sun Apr 13, 2008 12:33 pm    Post subject:
Reply with quote

BigFelix wrote:
No. Why today not yesterday. I had my doubts but don't want to take any chances.

Obviously there has been a change in definitions that caused this false positive.

Online Armor is trusted, reputable software. And this has all the hallmarks of false positive. It happens to every AV vendor every now and then.

If you have doubts (and in this case you really should have!), submit the detected file to Virustotal and to Grisoft (especially to latter).

Never have blind faith in your AV, they can make mistakes especially when it comes to other security software, as they may employ self-defence and other methods to protect themselves/detect malware.


_________________
Kitten: small homicidal muffin on legs: affects human sensibilities to the point of endowing the most wanton and ruthless acts of destruction with near mythical overtones of cuteness. Not recommended for beginners, get at least two. [Fafnir]
Back to top
View users profile Send private message Visit posters website
BigFelix
Warnings : 2

Captain
Captain
Premium Member

Joined: Mar 19, 2008
Posts: 506
Location: San Diego
Premium

PostPosted: Sun Apr 13, 2008 2:52 pm    Post subject:
Reply with quote

I ran "scared"' because I'm in the midst of Trend Micro HijackThis testing to cure me of existing problems. But I accept your advice and will contact Grisoft.


_________________
The whole problem with the world is that fools and fanatics are always so certain of themselves, but wiser people so full of doubts.
    Bertrand Russell
Back to top
View users profile Send private message Send email
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Firewalls All times are GMT
Page 1 of 1

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer