Is this a false positive?

Status
Not open for further replies.

joel2007

In Runtime
Messages
123
Code:
Premium Security Suite
Report file date: Friday, July 17, 2009  23:45

Scanning for 1548239 virus strains and unwanted programs.

Platform        : Windows Vista 64 Bit
Windows version : (Service Pack 1)  [6.0.6001]
Boot mode       : Normally booted
Username        : SYSTEM

Version information:
BUILD.DAT       : 9.0.0.377     29019 Bytes    6/9/2009 16:46:00
AVSCAN.EXE      : 9.0.3.6      466689 Bytes   5/11/2009 17:14:47
AVSCAN.DLL      : 9.0.3.0       40705 Bytes   2/27/2009 18:58:24
LUKE.DLL        : 9.0.3.2      209665 Bytes   2/20/2009 19:35:49
LUKERES.DLL     : 9.0.2.0       12033 Bytes   2/27/2009 18:58:52
ANTIVIR0.VDF    : 7.1.0.0    15603712 Bytes  10/27/2008 20:30:36
ANTIVIR1.VDF    : 7.1.4.132   5707264 Bytes   6/24/2009 22:09:09
ANTIVIR2.VDF    : 7.1.4.221   1273856 Bytes   7/12/2009 19:53:53
ANTIVIR3.VDF    : 7.1.4.252    445440 Bytes   7/17/2009 20:58:06
Engineversion   : 8.2.0.222
AEVDF.DLL       : 8.1.1.1      106868 Bytes   4/30/2009 19:52:04
AESCRIPT.DLL    : 8.1.2.18     442746 Bytes   7/17/2009 20:58:09
AESCN.DLL       : 8.1.2.3      127347 Bytes   5/14/2009 19:02:01
AERDL.DLL       : 8.1.2.4      430452 Bytes   7/14/2009 20:31:46
AEPACK.DLL      : 8.1.3.18     401783 Bytes   5/28/2009 00:07:20
AEOFFICE.DLL    : 8.1.0.38     196987 Bytes   6/18/2009 10:11:19
AEHEUR.DLL      : 8.1.0.143   1864055 Bytes   7/16/2009 21:35:39
AEHELP.DLL      : 8.1.4.5      229748 Bytes   7/14/2009 20:31:37
AEGEN.DLL       : 8.1.1.48     348532 Bytes    7/2/2009 20:56:29
AEEMU.DLL       : 8.1.0.9      393588 Bytes   10/9/2008 22:32:40
AECORE.DLL      : 8.1.7.5      180597 Bytes   7/14/2009 20:31:36
AEBB.DLL        : 8.1.0.3       53618 Bytes   10/9/2008 22:32:40
AVWINLL.DLL     : 9.0.0.3       18177 Bytes  12/12/2008 16:47:59
AVPREF.DLL      : 9.0.0.1       43777 Bytes   12/5/2008 18:32:15
AVREP.DLL       : 8.0.0.3      155905 Bytes   1/20/2009 22:34:28
AVREG.DLL       : 9.0.0.0       36609 Bytes   12/5/2008 18:32:09
AVARKT.DLL      : 9.0.0.3      292609 Bytes   3/24/2009 23:05:41
AVEVTLOG.DLL    : 9.0.0.7      167169 Bytes   1/30/2009 18:37:08
SQLITE3.DLL     : 3.6.1.0      326401 Bytes   1/28/2009 23:03:49
SMTPLIB.DLL     : 9.2.0.25      28417 Bytes    2/2/2009 16:21:33
NETNT.DLL       : 9.0.0.0       11521 Bytes   12/5/2008 18:32:10
RCIMAGE.DLL     : 9.0.0.25    2902785 Bytes   5/15/2009 23:28:32
RCTEXT.DLL      : 9.0.37.0      90369 Bytes   4/17/2009 18:04:17

Configuration settings for the scan:
Jobname.............................: Complete system scan
Configuration file..................: c:\program files (x86)\avira\antivir desktop\sysscan.avp
Logging.............................: low
Primary action......................: interactive
Secondary action....................: ignore
Scan master boot sector.............: on
Scan boot sector....................: on
Boot sectors........................: C:, 
Process scan........................: on
Scan registry.......................: on
Search for rootkits.................: on
Integrity checking of system files..: off
Scan all files......................: All files
Scan archives.......................: on
Recursion depth.....................: 20
Smart extensions....................: on
Macro heuristic.....................: on
File heuristic......................: medium

Start of the scan: Friday, July 17, 2009  23:45

Starting search for hidden objects.
The driver could not be initialized.

The scan of running processes will be started
Scan process 'avscan.exe' - '1' Module(s) have been scanned
Scan process 'avscan.exe' - '1' Module(s) have been scanned
Scan process 'avcenter.exe' - '1' Module(s) have been scanned
Scan process 'mobsync.exe' - '0' Module(s) have been scanned
Scan process 'WmiPrvSE.exe' - '0' Module(s) have been scanned
Scan process 'wmpnetwk.exe' - '0' Module(s) have been scanned
Scan process 'ADvdDiscHlp64.exe' - '0' Module(s) have been scanned
Scan process 'CCC.exe' - '0' Module(s) have been scanned
Scan process 'avwebgrd.exe' - '1' Module(s) have been scanned
Scan process 'avmailc.exe' - '1' Module(s) have been scanned
Scan process 'WUDFHost.exe' - '0' Module(s) have been scanned
Scan process 'SearchIndexer.exe' - '0' Module(s) have been scanned
Scan process 'svchost.exe' - '0' Module(s) have been scanned
Scan process 'svchost.exe' - '0' Module(s) have been scanned
Scan process 'SeaPort.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '0' Module(s) have been scanned
Scan process 'PnkBstrA.exe' - '1' Module(s) have been scanned
Scan process 'lxddcoms.exe' - '0' Module(s) have been scanned
Scan process 'mDNSResponder.exe' - '1' Module(s) have been scanned
Scan process 'AppleMobileDeviceService.exe' - '1' Module(s) have been scanned
Scan process 'avguard.exe' - '1' Module(s) have been scanned
Scan process 'avfwsvc.exe' - '1' Module(s) have been scanned
Scan process 'MOM.exe' - '0' Module(s) have been scanned
Scan process 'ehmsas.exe' - '0' Module(s) have been scanned
Scan process 'VCDDaemon.exe' - '1' Module(s) have been scanned
Scan process 'avgnt.exe' - '1' Module(s) have been scanned
Scan process 'jusched.exe' - '1' Module(s) have been scanned
Scan process 'hpwuSchd2.exe' - '1' Module(s) have been scanned
Scan process 'brs.exe' - '1' Module(s) have been scanned
Scan process 'AnyDVDtray.exe' - '1' Module(s) have been scanned
Scan process 'robotaskbaricon.exe' - '1' Module(s) have been scanned
Scan process 'taskeng.exe' - '0' Module(s) have been scanned
Scan process 'GoogleToolbarNotifier.exe' - '1' Module(s) have been scanned
Scan process 'ehtray.exe' - '0' Module(s) have been scanned
Scan process 'sidebar.exe' - '0' Module(s) have been scanned
Scan process 'lxddamon.exe' - '1' Module(s) have been scanned
Scan process 'RAVCpl64.exe' - '0' Module(s) have been scanned
Scan process 'explorer.exe' - '0' Module(s) have been scanned
Scan process 'dwm.exe' - '0' Module(s) have been scanned
Scan process 'taskeng.exe' - '0' Module(s) have been scanned
Scan process 'svchost.exe' - '0' Module(s) have been scanned
Scan process 'sched.exe' - '1' Module(s) have been scanned
Scan process 'spoolsv.exe' - '0' Module(s) have been scanned
Scan process 'svchost.exe' - '0' Module(s) have been scanned
Scan process 'svchost.exe' - '0' Module(s) have been scanned
Scan process 'atieclxx.exe' - '0' Module(s) have been scanned
Scan process 'SLsvc.exe' - '0' Module(s) have been scanned
Scan process 'svchost.exe' - '0' Module(s) have been scanned
Scan process 'audiodg.exe' - '0' Module(s) have been scanned
Scan process 'svchost.exe' - '0' Module(s) have been scanned
Scan process 'svchost.exe' - '0' Module(s) have been scanned
Scan process 'svchost.exe' - '0' Module(s) have been scanned
Scan process 'atiesrxx.exe' - '0' Module(s) have been scanned
Scan process 'svchost.exe' - '0' Module(s) have been scanned
Scan process 'svchost.exe' - '0' Module(s) have been scanned
Scan process 'winlogon.exe' - '0' Module(s) have been scanned
Scan process 'lsm.exe' - '0' Module(s) have been scanned
Scan process 'lsass.exe' - '0' Module(s) have been scanned
Scan process 'services.exe' - '0' Module(s) have been scanned
Scan process 'csrss.exe' - '0' Module(s) have been scanned
Scan process 'wininit.exe' - '0' Module(s) have been scanned
Scan process 'csrss.exe' - '0' Module(s) have been scanned
Scan process 'smss.exe' - '0' Module(s) have been scanned
21 processes with 21 modules were scanned

Starting master boot sector scan:
Master boot sector HD0
    [INFO]      No virus was found!
Master boot sector HD1
    [INFO]      No virus was found!
    [INFO]      Please restart the search with Administrator rights
Master boot sector HD2
    [INFO]      No virus was found!
    [INFO]      Please restart the search with Administrator rights
Master boot sector HD3
    [INFO]      No virus was found!
    [INFO]      Please restart the search with Administrator rights
Master boot sector HD4
    [INFO]      No virus was found!
    [INFO]      Please restart the search with Administrator rights

Start scanning boot sectors:
Boot sector 'C:\'
    [INFO]      No virus was found!

Starting to scan executable files (registry).
The registry was scanned ( '38' files ).


Starting the file scan:

Begin scan in 'C:\'
C:\hiberfil.sys
    [WARNING]   The file could not be opened!
    [NOTE]      This file is a Windows system file.
    [NOTE]      This file cannot be opened for scanning.
C:\pagefile.sys
    [WARNING]   The file could not be opened!
    [NOTE]      This file is a Windows system file.
    [NOTE]      This file cannot be opened for scanning.
C:\Users\Dung\Downloads\HD Tune Pro v3.50\patch\HDTunePro.exe
    [DETECTION] Is the TR/Spy.347648.A Trojan
C:\Users\Dung\Downloads\Legacy of Kain\Soul Reaver 2\patches\Soul_Reaver_2_crack.ace
  [0] Archive type: ACE
    --> sr2.exe
      [WARNING]   Out of memory! The virus or unwanted program was not deleted!
    --> fdx-sr22.nfo
      [WARNING]   No further files can be extracted from this archive. The archive will be closed
    [WARNING]   No further files can be extracted from this archive. The archive will be closed
C:\Users\Dung\Downloads\Mugen Project x\Mugen Project X.rar
    [WARNING]   An exception has been identified!
    [WARNING]   In the module 'aecore.dll' an exception occured.
Calling the function AVEPROC_TestFile in file: \\?\C:\Users\Dung\Downloads\Mugen Project x\Mugen Project X.rar
Error description:ACCESS_VIOLATION
  EAX = 00000000  EBX = 04C10AA8
  ECX = 0001FFFF  EDX = 0383EA04
  ESI = 0383EA04  EDI = 04c10aa4 
  EIP = 02D71E23  EBP = 00000000
  ESP = 0383E9F4  Flg = 00010283
  CS = 0000002B   SS = 00000023

Beginning disinfection:
C:\Users\Dung\Downloads\HD Tune Pro v3.50\patch\HDTunePro.exe
    [DETECTION] Is the TR/Spy.347648.A Trojan
    [NOTE]      The file was moved to '4ab5877f.qua'!


End of the scan: Saturday, July 18, 2009  01:26
Used time:  1:34:01 Hour(s)

The scan has been done completely.

  43906 Scanned directories
 730242 Files were scanned
      1 Viruses and/or unwanted programs were found
      0 Files were classified as suspicious
      0 files were deleted
      0 Viruses and unwanted programs were repaired
      1 Files were moved to quarantine
      0 Files were renamed
      2 Files cannot be scanned
 730239 Files not concerned
   3374 Archives were scanned
      6 Warnings
      3 Notes

Thank you.
 
I'd say yes if you are refering to

Beginning disinfection:
C:\Users\Dung\Downloads\HD Tune Pro v3.50\patch\HDTunePro.exe
[DETECTION] Is the TR/Spy.347648.A Trojan
[NOTE] The file was moved to '4ab5877f.qua'!
 
I'd say yes if you are refering to

Beginning disinfection:
C:\Users\Dung\Downloads\HD Tune Pro v3.50\patch\HDTunePro.exe
[DETECTION] Is the TR/Spy.347648.A Trojan
[NOTE] The file was moved to '4ab5877f.qua'!

Hi, do you know why it detected HDTunePro.exe as a Trojan?
Thanks.
 
Just the way it detects viruses, it was classified as one. I get that sometimes with Nod32 on things I know are safe.
 
Hi, do you know why it detected HDTunePro.exe as a Trojan?
Thanks.

It depends on the anti-virus solution in use. They all operate differently and some identify some objects as Trojans when they are not.
 
Status
Not open for further replies.
Back
Top Bottom