You are here

McAfee VirusScan Alert!

13 posts / 0 new
Last post
ionreflex
ionreflex's picture
Offline
Last seen: 11 years 11 months ago
Joined: 2006-11-27 12:19
McAfee VirusScan Alert!

Today's virus definition file (5150) for McAfee VirusScan detect registry.dll as a "Generic StartPage.r" when I start Thunderbird Portable 2.0.0.6; I'm pretty sure it's a false detect, I'll submit the case to McAfee and keep everyone posted here...

NB : I might forget, so if someone faster than me has info, please feel free to update this thread.

John Bentley
John Bentley's picture
Offline
Last seen: 14 years 8 months ago
Developer
Joined: 2006-01-24 13:26
http://portableapps.com/suppo

cowsay Moo
cowthink 'Dude, why are you staring at me.'

Tim Clark
Tim Clark's picture
Offline
Last seen: 13 years 3 weeks ago
Joined: 2006-06-18 13:55
Thanks

Thanks for the heads up.

I generally assume that a virus alert for an "offical" pa release is a false positive [not necessarily for anything else I've found here]

I will launch FFP and TBP before updating VirusScan.
If I get an alert after updating I'll choose to ignore it.

Thanks again for the heads up.

Tim

{EDIT: in checking my On Access scan settings I'm not seeing a setting for "let me choose what to do [e.g. ignore] so I am going to exclude "registry.dll" from scanning, since I don't know for sure if FFP will be able to run properly if the dll in question is deleted or quarantined }

Things have got to get better, they can't get worse, or can they?

Ryan McCue
Ryan McCue's picture
Offline
Last seen: 14 years 7 months ago
Joined: 2006-01-06 21:27
Nothing

registry.dll is only a temporary file and will be recreated next time you run FFP. Delete at your will.

"If you're not part of the solution, you're part of the precipitate."

rab040ma
Offline
Last seen: 1 week 6 days ago
Joined: 2007-08-27 13:35
I think he is asking what

I think he is asking what might happen if the AV deletes the DLL before the launcher has a chance to use it.

MC

ionreflex
ionreflex's picture
Offline
Last seen: 11 years 11 months ago
Joined: 2006-11-27 12:19
False positive indeed...

VirusTotal confirmed that McAfee detects a virus in Thunderbird Portable, so is Sunbelt! I've submitted the case to WebImmune...

(what was MISIIM input anyway ?)

ion][reflex
[reflexion]

John Bentley
John Bentley's picture
Offline
Last seen: 14 years 8 months ago
Developer
Joined: 2006-01-24 13:26
On the support page it says

On the support page it says don't report false positives.

cowsay Moo
cowthink 'Dude, why are you staring at me.'

RS.RODES
Offline
Last seen: 16 years 6 months ago
Joined: 2007-10-27 09:17
Also getting Generic.startpage.r with McAfee

I get four or five popup warnings in a row. It says:

Detection: Generic.startpage.r
Action: File deleted
Object: Registry.dll
Location: C:\Document...\Nsb213.tmp

So let me see if I understand.

1) We are now getting this warning from McAfee because of new definitions from McAfee. IOW, it is McAfee that has changed rather than Thunderbird portable.

2) It is a false positive. There is nothing wrong with Registry.dll.

And a question:

Q1) What damage is this (file deletion) doing to the execuction of Thunderbird Portable?

TIA.

Peter

Caehan
Caehan's picture
Offline
Last seen: 1 year 2 months ago
Joined: 2007-10-19 22:51
Same

I am getting the same false positive for Clamwin, Firefox, and Abiword.

zkam
Offline
Last seen: 4 years 6 months ago
Joined: 2007-10-27 12:08
Me too

Also getting the same virus report when launching FFP. Tried disabling all addons, then moving my Profile (creating a new one), then doing clean install. None of these steps made a difference.

Tim Clark
Tim Clark's picture
Offline
Last seen: 13 years 3 weeks ago
Joined: 2006-06-18 13:55
Nothing you can do to FFP will help

Things have got to get better, they can't get worse, or can they?

Lurking_Biohazard
Lurking_Biohazard's picture
Offline
Last seen: 5 years 8 months ago
Joined: 2006-02-18 18:06
And here...

~Lurk~

Caehan
Caehan's picture
Offline
Last seen: 1 year 2 months ago
Joined: 2007-10-19 22:51
John Haller's Report...

https://portableapps.com/node/9846

This addresses most questions that people can ask about this problem.

Log in or register to post comments