gnozal japbe - antivir found virus

Everything else that doesn't fall into one of the other PB categories.
Toshy
User
User
Posts: 15
Joined: Fri Feb 17, 2006 3:38 am

gnozal japbe - antivir found virus

Post by Toshy »

I'm back with my "google-english" :-(

i unpack the file "jaPBeForPB400_394.exe" from gnozals website an antivir found in file "displaysystemmetrics.exe" an virus called:
TR/Crypt.PEPM.gen.

wat ist "displaysystemmetrics.exe"?
in my old version it don`t exists.

Toshy
!! sorry, i only speak some words in english. !!
1. AMD,3 GB MB-RAM,WinXP
2. Linux-TabletPC
Inet: 7 Kbyte/s Down/7Kbyte (not MBit) Up
PB4.6x
Messenger: Trillian (yahoo, skype, MSN/Live,icq)
User avatar
idle
Always Here
Always Here
Posts: 5840
Joined: Fri Sep 21, 2007 5:52 am
Location: New Zealand

Post by idle »

most likely nothing, probably a false positive

The file may just be using a packer, which often set of lazy Anti virus checkers.
gnozal
PureBasic Expert
PureBasic Expert
Posts: 4229
Joined: Sat Apr 26, 2003 8:27 am
Location: Strasbourg / France
Contact:

Re: gnozal japbe - antivir found virus

Post by gnozal »

Toshy wrote:i unpack the file "jaPBeForPB400_394.exe" from gnozals website an antivir found in file "displaysystemmetrics.exe" an virus called:
TR/Crypt.PEPM.gen.
All my files are packed [PECompact2 or UPX], this may trigger some false positive with some AV software, specially with heuristics enabled.
Small + packed = virus ...
Toshy wrote:wat ist "displaysystemmetrics.exe"?
in my old version it don`t exists.
A new plugin.
Source is here : http://www.purebasic.fr/english/viewtopic.php?t=37026
For free libraries and tools, visit my web site (also home of jaPBe V3 and PureFORM).
User avatar
Kaeru Gaman
Addict
Addict
Posts: 4826
Joined: Sun Mar 19, 2006 1:57 pm
Location: Germany

Post by Kaeru Gaman »

Warnings containing a ".gen" are definitely Heuristics Warnings.

Depending on Product and Heuristics level, some Antivirus Software is quite trigger-happy.

e.g. some will even mock a Minigame, when you include a JPG image via IncludeBinary.

You could report this False Positive to your AV Company to enable them to set "displaysystemmetrics.exe" on their greenlist.
oh... and have a nice day.
Toshy
User
User
Posts: 15
Joined: Fri Feb 17, 2006 3:38 am

Post by Toshy »

thanks.

toshy
!! sorry, i only speak some words in english. !!
1. AMD,3 GB MB-RAM,WinXP
2. Linux-TabletPC
Inet: 7 Kbyte/s Down/7Kbyte (not MBit) Up
PB4.6x
Messenger: Trillian (yahoo, skype, MSN/Live,icq)
Post Reply