You are here

Possible Threat Detected In SmithTech's DriveVar App

22 posts / 0 new
Last post
David Dixon II
David Dixon II's picture
Offline
Last seen: 2 years 7 months ago
Developer
Joined: 2007-06-11 22:54
Possible Threat Detected In SmithTech's DriveVar App

AVG Detected A Trogan Named

Generic3.FGK

Can Someone Please Explain This To Me And Why In The World Does This Have A Trogan In It..... :|

ZachHudock
ZachHudock's picture
Offline
Last seen: 1 year 9 months ago
Developer
Joined: 2006-12-06 18:07
False positive. Unless

False positive. Unless multiple different virus scanners detect it as an issue, it is most likely a false positive. This has happened quite a bit with AVG and Sophos. Both tend to detect occasional issues in the portable apps themselves, but after checking these issues with several other scanners, i.e. TrendMicro, AVAST, Symantec, McAfee,... one can usually confirm that it is in fact a false positive.
_________________________
I don't believe in signatures

The developer formerly known as ZGitRDun8705

David Dixon II
David Dixon II's picture
Offline
Last seen: 2 years 7 months ago
Developer
Joined: 2007-06-11 22:54
Ok, Thanks But If Someone

Ok, Thanks

But If Someone Can Check It Out With Something Different Than AVG That Would Be Nice. Wink TY For The Info.

=====================================
"PortableApps.com Lets Me Bring More Stuff To My Computer, Not Just Other Computers. Because My Computer Only Has 1GB Left" - dbdii407
-------------------------------------------
- U3 1GB Flash Drive

Na na na, come on!

alanbcohen
Offline
Last seen: 5 years 1 month ago
Joined: 2006-01-04 10:47
I hate to be the bearer of

I hate to be the bearer of 'bad news', but I just got another virus warning on this app from Symantec on my work machine (scanning my external drive). It is reporting 'Hacktool.Flooder'. It may indeed be a false positive, but since the author is on site here often, I figured this was a good place to add the info. Symantec also reported 'Action taken: Clean failed : Quarantine failed : Delete succeeded : Access denied'. That may give some useful info on what the underlying problem is.

SmithTech
SmithTech's picture
Offline
Last seen: 2 years 5 months ago
Developer
Joined: 2006-11-24 18:06
I've sent an email to

I've sent an email to Symantec, will update when they respond.

-----------------------------------------------------------------------------------------------
Because they stand on a wall and say nothing is going to hurt you tonight. Not on my watch.

"Because they stand on a wall and say, 'Nothing is going to hurt you tonight. Not on my watch.'" (A Few Good Men)
Coincidence is God's way of remaining anonymous.(Albert Einstein)

John T. Haller
John T. Haller's picture
Online
Last seen: 13 min 34 sec ago
AdminDeveloperModeratorTranslator
Joined: 2005-11-28 22:21
False Positive Procedures

Please follow the antivirus false positive procedures listed on the support and contact pages. Reports should not be posted unless you have personally verified that it is identified as a virus/spyware by AT LEAST 2 different antivirus products. There are two different online scanners linked to. And you can also use ClamWin Portable. Without a report of at least 2 products detecting it, your report will not be investigated further.

There are simply too many false positives by all the random antivirus packages out there -- especially the freeware ones. It's simply a waste of time for us to investigate all the uncorroborated ones.

Sometimes, the impossible can become possible, if you're awesome!

David Dixon II
David Dixon II's picture
Offline
Last seen: 2 years 7 months ago
Developer
Joined: 2007-06-11 22:54
ok... but avg wont let me

ok...

but avg wont let me download it..... how do i get it :|

=====================================
"PortableApps.com Lets Me Bring More Stuff To My Computer, Not Just Other Computers. Because My Computer Only Has 1GB Left" - dbdii407
-------------------------------------------
- U3 1GB Flash Drive

Na na na, come on!

ZachHudock
ZachHudock's picture
Offline
Last seen: 1 year 9 months ago
Developer
Joined: 2006-12-06 18:07
AVG won't let you download

AVG won't let you download ClamWin? If that is the case, adjust your settings in AVG and make them a little less strict. Or report to AVG that they are detecting several false positives. In your message to them, include the file it is incorrectly detecting, where you download the file from, and quote the entire error message for them.
_________________________
I don't believe in signatures

The developer formerly known as ZGitRDun8705

David Dixon II
David Dixon II's picture
Offline
Last seen: 2 years 7 months ago
Developer
Joined: 2007-06-11 22:54
i have clamwin portable i

i have clamwin portable i ment driveVar ss Sad

Na na na, come on!

John T. Haller
John T. Haller's picture
Online
Last seen: 13 min 34 sec ago
AdminDeveloperModeratorTranslator
Joined: 2005-11-28 22:21
Disable It

Simple... temporarily disable it. Download the suspect app but DO NOT run it. Then scan it with ClamWin Portable, etc.

You can't get infected with a virus by downloading an infected EXE. Only by running it.

Sometimes, the impossible can become possible, if you're awesome!

David Dixon II
David Dixon II's picture
Offline
Last seen: 2 years 7 months ago
Developer
Joined: 2007-06-11 22:54
ok

ok

Na na na, come on!

SmithTech
SmithTech's picture
Offline
Last seen: 2 years 5 months ago
Developer
Joined: 2006-11-24 18:06
Responce from Symantec

I finally received a response from Symantec.
I'm posting it here mostly for peace of mind for the user.
-------------------------------------------------------------------------------------
From: Security Risk Inquiries (Security_Risk_Inquiries@symantec.com)
To: {email address removed} see my profile.
Date: Tuesday, October 16, 2007 4:21:22 AM
Subject: Dispute Submission
We are writing in relation to your submission through Symantec's on-line Security Risk / False Positive Dispute Submission form for your DriveVar software version 1.x being detected by Symantec Software. In light of further investigation and analysis Symantec is happy to remove this detection from within its products. The updated detection will be distributed in the next set of virus definitions, available daily, or weekly via LiveUpdate, depending on Symantec product version, or daily from our website at http://securityresponse.symantec.com/avcenter/defs.download.html. Decisions made by Symantec are subject to change if alterations to the Software are made over time or as classification criteria and/or the policy employed by Symantec changes over time to address the evolving landscape. Sincerely, Symantec Security Response http://securityresponse.symantec.com
-----------------------------------------------------------------------------------

"Because they stand on a wall and say, 'Nothing is going to hurt you tonight. Not on my watch.'" (A Few Good Men)
Coincidence is God's way of remaining anonymous.(Albert Einstein)

digitxp
digitxp's picture
Offline
Last seen: 13 years 2 weeks ago
Joined: 2007-11-03 18:33
McAfee VirusScan Enterprise

says it's a trojan, too. It says it's generic.dc

Insert original signature here with Greasemonkey Script.

Patrick Patience
Offline
Last seen: 4 years 9 months ago
DeveloperModerator
Joined: 2007-02-20 19:26
Please Don't Bump

Please don't bump 5 month old posting with no more interest in them.

I'll come back and delete these comment later once you acknowledge this.

Thanks.

digitxp
digitxp's picture
Offline
Last seen: 13 years 2 weeks ago
Joined: 2007-11-03 18:33
Okay.

What exactly is bumping?

Insert original signature here with Greasemonkey Script.

Patrick Patience
Offline
Last seen: 4 years 9 months ago
DeveloperModerator
Joined: 2007-02-20 19:26
Commenting

Commenting on an old post with no more interest just to bring it all the way back to the top of the forums. Yours was clearly unintentional, and sometimes there is a good reason to bump it unintentionally, but since this post it quite old I don't think there was much need.

Tim Clark
Tim Clark's picture
Offline
Last seen: 13 years 5 months ago
Joined: 2006-06-18 13:55
Clarification

Of course if I read his post correctly it's not really bumping in the most negative sense of the word. He is not trying to get attention to a post of interest to himself.

He seems to be pointing out that a former problem, a false positive detected in an app offered by a member of this group has happened again. Formally by a AVG and Symantec, and currently by McAfee. This would of course be of interest to SmithTech. I'm don't currently have a copy of the app in question in order to upload it to our recommended testing sites to see how other products are reacting.

Tim

Things have got to get better, they can't get worse, or can they?

rab040ma
Offline
Last seen: 3 months 5 days ago
Joined: 2007-08-27 13:35
We'll need to strike a

We'll need to strike a balance between encouraging people to search, and complaining when they inadvertently "bump" an old topic when they find something.

MC

Tim Clark
Tim Clark's picture
Offline
Last seen: 13 years 5 months ago
Joined: 2006-06-18 13:55
Very Good Point

MC,

That's a very good point!

If someone searches first, as we encourage them to do, and finds what they they are looking for, which we hope, what do they do when it's over a month old? Reply? New Topic?

Very good point indeed.

Tim

Things have got to get better, they can't get worse, or can they?

Patrick Patience
Offline
Last seen: 4 years 9 months ago
DeveloperModerator
Joined: 2007-02-20 19:26
Yea

Good point. I know it was unintentional, and he was providing everyone with some good reassurance, but it's not like one of those things where we told him to search and then he 'bumped' to ask a question or provide feedback which is certainly fine, he probably just wound up on this old thread somehow and just wanted to let us know.

It's probably good that he provided reassurance, and I don't mind either way, I was just letting him know to be careful what he comments on next time and whether it's worthy of being bumped up. In this case yes it can be helpful to a new user that comes along and is still curious about the case of this situation although it did receive decent feedback/

Ed_P
Offline
Last seen: 5 years 11 months ago
Joined: 2007-02-19 09:09
yup

An excellent point indeed. Maybe John can add it to his Tempering Responses guidelines so the mods follow it.

BTW I think the Tempering Responses thread should be stickied.

Ed

SmithTech
SmithTech's picture
Offline
Last seen: 2 years 5 months ago
Developer
Joined: 2006-11-24 18:06
Reported to McAfee

Thanks for the update, I have reported the false positive to McAfee.
It is usually better though to use the contact link on the website for any utilites/applications you may download to report these things as the author may over look posts in forums Wink

"Because they stand on a wall and say, 'Nothing is going to hurt you tonight. Not on my watch.'" (A Few Good Men)
Coincidence is God's way of remaining anonymous.(Albert Einstein)

Log in or register to post comments