Author Topic: pev.exe FP  (Read 2776 times)

0 Members and 1 Guest are viewing this topic.

Offline oldman

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4142
  • Some days..... MOS...this bug's for you
pev.exe FP
« on: January 13, 2012, 02:23:09 AM »
Hi,

Avast is detecting this file. It's a file used by one of our malware tools. I believe the file was submitted a day or so ago. If you need a new copy let me know.

C:\Windows\PEV.exe **INFECTED** Win32:Rootkit-gen [Rtk]

Thanks

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: pev.exe FP
« Reply #1 on: January 13, 2012, 11:12:59 PM »
I have also sent a copy to the labs via the ftp..  so hopefully should be cleared soon

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33904
  • malware fighter
Re: pev.exe FP
« Reply #2 on: January 13, 2012, 11:26:25 PM »
Hi oldman and essexboy,

Here avast did not flag it as yet: http://r.virscan.org/115a7219f89268b928d51a632bccb300
There is lot of disinformation on this executable: http://www.backgroundtask.eu/Systeemtaken/taakinfo/37294/pev.exe/F1FBA6185A6A2BC6456970914875078E/
and here on this totally bad web rep info site: http://www.latest-virus.com/pevexe-1060
and then you have this info ignating all this: http://www.prevx.com/filenames/2534574636446686797-X1/PEV.EXE.html
So now you see what then happens. After that the reputation of this previewer tool has been damaged. Let us hope the FP will be fixed soon and file status could change to something like risktool, PUP, something in the realm to what these heuristical av flags finds up,

pol
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline oldman

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4142
  • Some days..... MOS...this bug's for you
Re: pev.exe FP
« Reply #3 on: January 14, 2012, 01:27:22 AM »
Quote
2009/06/24 00:09:47
Those results are about 2 1/2 years old. Because of the behavior of some of our tools, AVs do detect them from time to time.

Seems to be fixed.  8)