Virus in PB4.20 UpdateTool?

For everything that's not in any way related to PureBasic. General chat etc...
UserOfPure
Enthusiast
Enthusiast
Posts: 469
Joined: Sun Mar 16, 2008 9:18 am

Post by UserOfPure »

JCV wrote:I dont need to store any new data on my client client/server pc on the main partition since I keep all important/updating programs on a different hidden drive.
But what about apps like Firefox which write to %AppData% when adding bookmarks, cookies, and so on? Deep Freeze wouldn't be able to save them. That's what I'm trying to work around. Faronics has a mapping tool to supposedly redirect all %AppData% folder writes to another drive, but I can't get it to work.
srod
PureBasic Expert
PureBasic Expert
Posts: 10589
Joined: Wed Oct 29, 2003 4:35 pm
Location: Beyond the pale...

Post by srod »

ricardo wrote:I have some personal nigthmare story with Norton.
I too had a nightmare with that company and theirAV product. I now use AVG -which also reports a trojan with the update tool! :)
I may look like a mule, but I'm not a complete ass.
User avatar
Kaeru Gaman
Addict
Addict
Posts: 4826
Joined: Sun Mar 19, 2006 1:57 pm
Location: Germany

Post by Kaeru Gaman »

some AV's heuristic interprete every DownloadFromURL-call of a non-certified app as a "Trojan"....
oh... and have a nice day.
User avatar
Ajm
Enthusiast
Enthusiast
Posts: 242
Joined: Fri Apr 25, 2003 9:27 pm
Location: Kent, UK

Sophos

Post by Ajm »

This is a reply I got back this afterneen from Sophos after I submitted the update tool this morning.
It's a shame they don't all respond that quick.

Good afternoon Andy,

thank you for your email.

The file UpdateTool.exe that you sent to us for analysis is producing a false-positive report.
An IDE file that will correct this should be released on the Databank later this afternoon.
However, the file will still be detected with Suspicious detection on as Sus/UnkPacker. If so, it can be authorised.

Please do not hesitate to contact me if I can be of any further assistance.

Regards,

Karin Cowell
Sophos Technical Support

--Original Message--
From:
Date: 27/05/2008 11:00:40
To: samples@sophos.com
Subject: File sample submitted from the Sophos website

The following file(s) was submitted on:
Tue May 27 10:00:16 2008
Regards

Andy

Image
Registered PB & PureVision User
User avatar
DoubleDutch
Addict
Addict
Posts: 3220
Joined: Thu Aug 07, 2003 7:01 pm
Location: United Kingdom
Contact:

Post by DoubleDutch »

However, the file will still be detected with Suspicious detection on as Sus/UnkPacker. If so, it can be authorised.
This seems a little unfair - they know the file is not a virus - why do they continue to say its suspicious? This kind of thing should be libelous - they are knowingly slandering the program. :evil:
https://deluxepixel.com <- My Business website
https://reportcomplete.com <- School end of term reports system
Inf0Byt3
PureBasic Fanatic
PureBasic Fanatic
Posts: 2236
Joined: Fri Dec 09, 2005 12:15 pm
Location: Elbonia

Post by Inf0Byt3 »

Definitely outrageous! Didn't think this could ever happen. It isn't PB's fault that their analysts did a not so great job at examining the data or that compiled code between programs may look the same. This hurts PB's image IMO.
None are more hopelessly enslaved than those who falsely believe they are free. (Goethe)
User avatar
DoubleDutch
Addict
Addict
Posts: 3220
Joined: Thu Aug 07, 2003 7:01 pm
Location: United Kingdom
Contact:

Post by DoubleDutch »

Inf0Byt3 wrote: This hurts PB's image IMO.
This is exactly what I think too. If I did not trust the developers then I would think twice about using it - thus buying it. This means that they could lose sales due to what the AntiVirus tool is saying - thus (imho) they should be able to claim damages due to loss of sales and reputation.

If the antivirus authors fixed the problem without question then they could have a defense, but the attitude from this company is undefendable.
https://deluxepixel.com <- My Business website
https://reportcomplete.com <- School end of term reports system
Fred
Administrator
Administrator
Posts: 18162
Joined: Fri May 17, 2002 4:39 pm
Location: France
Contact:

Post by Fred »

I got response from AVG and Antivir, and both have release fixed version of their detections packages. I just tried here with the updatetool.exe, and it's no more flagged. If you still encounter such problem with a PB exe, feel free to post it, so we can mail them again.
User avatar
pdwyer
Addict
Addict
Posts: 2813
Joined: Tue May 08, 2007 1:27 pm
Location: Chiba, Japan

Post by pdwyer »

8)

I thought I was going have to port all my virus code to another language there for a moment! phew!

:mrgreen:
Paul Dwyer

“In nature, it’s not the strongest nor the most intelligent who survives. It’s the most adaptable to change” - Charles Darwin
“If you can't explain it to a six-year old you really don't understand it yourself.” - Albert Einstein
ricardo
Addict
Addict
Posts: 2438
Joined: Fri Apr 25, 2003 7:06 pm
Location: Argentina

Post by ricardo »

In this 2 pages (maybe more exists) you can do online scan of files to see if some AV still showing any flags

http://www.virustotal.com

http://virusscan.jotti.org/

They do an online scan of uploaded files with more than 30 of the most popular AV software and five results in a matter of minutes.
Post Reply