You are here

Trojan Horse Downloader.Zlob -- False Positive?

11 posts / 0 new
Last post
PBoyington
PBoyington's picture
Offline
Last seen: 4 years 10 months ago
Joined: 2006-09-11 08:41
Trojan Horse Downloader.Zlob -- False Positive?

Apologies if this is not the place to post this, but this morning AVG anti-virus killed my portable apps due to them having the following:

Trojan Horse Downloader.Zlob

Can anyone enlighten me about this? I am hoping it is just a false positive, because I downloaded the programs again and the scan shows them to be infected also.

Thanks,
Preston

BvF7734
Offline
Last seen: 2 years 3 months ago
Joined: 2006-04-20 21:07
Holy cheese and crackers bat man!

I didn't believe your post so I remoted to my home machine sure as ticks on a hound dog it is there. odd... Lemme send one of the files to jotti for cross check. May be a bad definition file from AVG of which is not uncommon. First time I have seen it though...

You have the right to remain silent. Anything you do or say will be exaggerated or mis-quoted and used against you.

John T. Haller
John T. Haller's picture
Offline
Last seen: 7 hours 36 min ago
AdminDeveloperModeratorTranslator
Joined: 2005-11-28 22:21
It's AVG

It's a false positive. It's always a false positive. Wait for a definitions update to fix it.

And NEVER have your antivirus set to auto-delete files without asking. I still can't believe some people do this.

Sometimes, the impossible can become possible, if you're awesome!

PBoyington
PBoyington's picture
Offline
Last seen: 4 years 10 months ago
Joined: 2006-09-11 08:41
No data loss

still have my data so no harm there. this is just my temp when I am away from my Debian machine.

and I don't see where AVG (freeware) allows me to change this behavior...

hmm, will keep digging.

John T. Haller
John T. Haller's picture
Offline
Last seen: 7 hours 36 min ago
AdminDeveloperModeratorTranslator
Joined: 2005-11-28 22:21
If you figure it out...

... please drop a note back. I may post a how-to on AV config for folks that can't afford a commercial AV and are stuck with a free one (like AVG, AntiVir and Avast). I'm just so tired of having to deal with these issues.

Sometimes, the impossible can become possible, if you're awesome!

melendz
Offline
Last seen: 6 years 11 months ago
Joined: 2006-02-07 19:05
AVG Automatic Heal Infected Files

I just installed AVG Antivirus free version and was looking for that particular option. Here are the instructions:

1. Go to the AVG Test Center

2. On the top menus click on Tests --> Complete Test Settings
Then unclick "Automatically heal infected files" under "Scanning Parametes"

3. On the top menus click on Tests --> Selected Areas Test Settings
Then unclick "Automatically heal infected files" under "Scanning Parametes"

BvF7734
Offline
Last seen: 2 years 3 months ago
Joined: 2006-04-20 21:07
no worries

I have just confirmed that it is a false positive. Results here Jotti results prove thatit is false. I will try to contact AVG and let them know that they are pulling up false positive with there current defs.

You have the right to remain silent. Anything you do or say will be exaggerated or mis-quoted and used against you.

PBoyington
PBoyington's picture
Offline
Last seen: 4 years 10 months ago
Joined: 2006-09-11 08:41
might drop AVG

Downloaded Clamwin and am taking a look at it. I REALLY like that it is opensource and has more options available. The biggest "downside" I see is that it currently doesn't offer an on-access real-time scanner.

Thanks for confirming the false positive.

BvF7734
Offline
Last seen: 2 years 3 months ago
Joined: 2006-04-20 21:07
No prob at all

I have already submitted a copy of the thunderbird portable.exe to them to test. I also sent them the link to this site so they can test if they wish. Usually, they send out a new difinition very shortly depending on how complex it is to accomadate into the def to fix this fals positive.

Will post again if and when I reciev a update from AVG!

You have the right to remain silent. Anything you do or say will be exaggerated or mis-quoted and used against you.

BvF7734
Offline
Last seen: 2 years 3 months ago
Joined: 2006-04-20 21:07
Update:

This is the response. In a nut shell, it has been fixed. Update AVG and all is well with the force.

Thank you for your email.

Unfortunately, the previous virus database might have detected the
virus (Trojan Horse) on some legitimate applications. We
can confirm that it was a false alarm. We have immediately released the new virus update that removes the false positive on this application.
Please update your AVG and check your files again.

If you need to restore deleted files from AVG Virus Vault you can do it this way: open AVG Virus Vault (Start -> Programs -> AVG Antivirus -> AVG Virus Vault). Locate the file that was removed, right click on it and choose "Restore File(s)" option.

We are sorry for the inconvenience.

You have the right to remain silent. Anything you do or say will be exaggerated or mis-quoted and used against you.

John T. Haller
John T. Haller's picture
Offline
Last seen: 7 hours 36 min ago
AdminDeveloperModeratorTranslator
Joined: 2005-11-28 22:21
Not Bad

This is a much better (and faster) response than AnitVir and Avast usually have (they take days to fix stuff like this).

Sometimes, the impossible can become possible, if you're awesome!

Topic locked