avast!WEBforum
November 22, 2009, 01:35:02 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: avast! Home Edition - free for home non-commercial use!
 
   Home   Help Search Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: hook.dll - false positive?  (Read 1062 times)
KimB
Newbie
*
Offline Offline

Posts: 8


Personal Message (Offline)
« on: December 22, 2008, 11:23:11 AM »

Avast 4.8 flags a file called hook.dll in the windows/system32 directory as a virus. I have tracked it as a file installed with my Trust GM-4200 Gamer mouse driver. How can I prove if it is false positive or an infected file?

Thanks for your help.
Logged
Tech
avast! translator
avast! Technical
******
Offline Offline

Gender: Male
Spain Spain

Posts: 47062



Personal Message (Offline)
« Reply #1 on: December 22, 2008, 11:24:36 AM »

Can you inform the file as being a false positive? (click on the bottom right of the virus warning message).

To know if a file is a false positive, please submit it to VirusTotal and let us know the result. VirusTotal has a file size limit of 10Mb. You can use VirScan also.
If it is indeed a false positive, send it in a password protected zip to virus@avast.com. Please, mention in the body of the message why you think it is a false positive and the password used. Thanks.

Maybe you need to disable Hide protected operating system files and enable View hidden files and folders to manage the file(s).

As a workaround, you can add these files to the Standard Shield provider (on-access scanning) exclusion list.
Left click the 'a' blue icon, click on the provider icon at left and then Customize. Go to Advanced tab and click on Add button...
You can use wildcards like * and ?. But be careful, you should 'exclude' that many files that let your system in danger.
Logged

avast Settings - FAQ - Links
Help me helping you! Sign up & use Mozy to get 2,200 Mb for free remote backup. Enjoy its safety!
KimB
Newbie
*
Offline Offline

Posts: 8


Personal Message (Offline)
« Reply #2 on: December 22, 2008, 04:05:16 PM »

Here is the result of the VirusTotal

http://www.virustotal.com/analisis/e82d013585f0972c8f67bb3dbe669983

And VirScan results:
http://www.virscan.org/report/c03c4232be5c2fb240e5f617d5c2b336.html

Interesting but does it confirm it is or isn't a virus?

In the meantime I've sent an email to Trust to verify that hook.dll is part of the mouse driver.

The mouse driver allows the extra buttons on the mouse to do things like Ctrl-C copy and Ctrl-P paste etc. Not sure if that could trigger the alert. It's been on my computer for well over a year and yesterday was the first time AVG flagged it. Checking with my other computer running AVAST also flagged it as a virus.
« Last Edit: December 22, 2008, 04:32:45 PM by KimB » Logged
Jtaylor83
avast! Evangelist
*****
Offline Offline

Gender: Male
United States United States

Posts: 658


Personal Message (Offline)
« Reply #3 on: December 22, 2008, 04:54:13 PM »

It appears to be a keylogger. Not FP.

Avast says it's Win32:Spyware-gen [trj], so it's a pretty good detection.

Logged
DavidR
avast! Überevangelist
******
Online Online

Gender: Male
United Kingdom United Kingdom

Posts: 37819



Personal Message (Online)
« Reply #4 on: December 22, 2008, 05:18:32 PM »

I would also send them the URLs of the two virus scans to show them the strength of the detections. However your first link shows a different file, 467D7D_1.WRK and not hook.dll Huh

Personally I believe that this could be a/or is part of your mouse driver, though why the mouse driver should need to hook in this way as it makes it look like a keylogger which most are detecting as it behaves like a keylogger.

Hooks are normally hooking keystrokes, etc. to intercept commands, though why a mouse needs to do this, even one with additional functionality, is beyond me. I use  Trust Wireless Laser Mouse (Carbon Edition), and it runs wh_exec.exe on start-up for its additional functionality, but doesn't get detected in this way.
Logged

Core2Duo E8300/ 2GB Ram/ WinXP ProSP3/ Avast 4.8.1356 Home/ Outpost Firewall Pro 2009/ Firefox 3.5.5 NoScript/ MailWasher Pro 6.5.4/ SuperAntiSpyware Pro/ MalwareBytes AntiMalware/ WinPatrol/ HiJackThis /Drive Image 7.1 /OE6 /SnagIt 9.1 Image Capture
Tech
avast! translator
avast! Technical
******
Offline Offline

Gender: Male
Spain Spain

Posts: 47062



Personal Message (Offline)
« Reply #5 on: December 22, 2008, 07:01:01 PM »

I have tracked it as a file installed with my Trust GM-4200 Gamer mouse driver.
I don't think so... seems indeed a keylogger.
Logged

avast Settings - FAQ - Links
Help me helping you! Sign up & use Mozy to get 2,200 Mb for free remote backup. Enjoy its safety!
DavidR
avast! Überevangelist
******
Online Online

Gender: Male
United Kingdom United Kingdom

Posts: 37819



Personal Message (Online)
« Reply #6 on: December 22, 2008, 07:23:40 PM »

I'm not so sure as virtually all of the detections are generic/heuristic or don't have a specific signature based malware name. It isn't uncommon for a mouse driver to have this kind of hook, though why they need it is beyond me and it doesn't happen in my Trust mouse.
Logged

Core2Duo E8300/ 2GB Ram/ WinXP ProSP3/ Avast 4.8.1356 Home/ Outpost Firewall Pro 2009/ Firefox 3.5.5 NoScript/ MailWasher Pro 6.5.4/ SuperAntiSpyware Pro/ MalwareBytes AntiMalware/ WinPatrol/ HiJackThis /Drive Image 7.1 /OE6 /SnagIt 9.1 Image Capture
KimB
Newbie
*
Offline Offline

Posts: 8


Personal Message (Offline)
« Reply #7 on: December 23, 2008, 06:29:12 PM »

I would also send them the URLs of the two virus scans to show them the strength of the detections. However your first link shows a different file, 467D7D_1.WRK and not hook.dll Huh
....

Strange It told me it had been scanned before and gave me that page the first time. Here's the proper results:

http://www.virscan.org/report/c03c4232be5c2fb240e5f617d5c2b336.html

Thanks for your help so far. I've written to Trust and asked if hook.dll is supposed to be part of the mouse driver and to confirm it isn't a virus. I did open the file in notepad, and it did appear to have text that relates to the mouse. I'll report back when I get a reply.
Logged
DavidR
avast! Überevangelist
******
Online Online

Gender: Male
United Kingdom United Kingdom

Posts: 37819



Personal Message (Online)
« Reply #8 on: December 23, 2008, 06:54:27 PM »

No point opening the file in notepad it is a dll not a plain language file, all you will see for the most part is code and extreme care has to be taken not to inadvertently damage the file.

Personally I still think there is a likelihood this is a false positive detection as virtually all of the detections are generic or a non specific malware name, they look like they are detection on its actions and by its name alone it is a hook tool.

When avast next detects it select submit as a false positive so they can analyse it and give a link to this topic and the virus scan links.
Logged

Core2Duo E8300/ 2GB Ram/ WinXP ProSP3/ Avast 4.8.1356 Home/ Outpost Firewall Pro 2009/ Firefox 3.5.5 NoScript/ MailWasher Pro 6.5.4/ SuperAntiSpyware Pro/ MalwareBytes AntiMalware/ WinPatrol/ HiJackThis /Drive Image 7.1 /OE6 /SnagIt 9.1 Image Capture
Tech
avast! translator
avast! Technical
******
Offline Offline

Gender: Male
Spain Spain

Posts: 47062



Personal Message (Offline)
« Reply #9 on: December 23, 2008, 11:21:44 PM »

I hope Alwil team take a look on it... and the virus analysts could give us a final conclusion.
It's a strange file for sure, if not infected.
Logged

avast Settings - FAQ - Links
Help me helping you! Sign up & use Mozy to get 2,200 Mb for free remote backup. Enjoy its safety!
KimB
Newbie
*
Offline Offline

Posts: 8


Personal Message (Offline)
« Reply #10 on: December 29, 2008, 04:20:01 PM »

I've sent it off to virus@avast.com to look at.

I sent it to AVG yesterday and had a reply to say it was a false positive, so hopefully avast will update thier database too.

 
Logged
DavidR
avast! Überevangelist
******
Online Online

Gender: Male
United Kingdom United Kingdom

Posts: 37819



Personal Message (Online)
« Reply #11 on: December 29, 2008, 05:45:05 PM »

Normally they are quick to correct a false positive when confirmed.
Logged

Core2Duo E8300/ 2GB Ram/ WinXP ProSP3/ Avast 4.8.1356 Home/ Outpost Firewall Pro 2009/ Firefox 3.5.5 NoScript/ MailWasher Pro 6.5.4/ SuperAntiSpyware Pro/ MalwareBytes AntiMalware/ WinPatrol/ HiJackThis /Drive Image 7.1 /OE6 /SnagIt 9.1 Image Capture
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.10 | SMF © 2006-2009, Simple Machines LLC Valid XHTML 1.0! Valid CSS!
Page created in 0.077 seconds with 17 queries.