Author Topic: False Positive ? gtdownde_87.ocx  (Read 3907 times)

0 Members and 1 Guest are viewing this topic.

Mr K

  • Guest
False Positive ? gtdownde_87.ocx
« on: March 08, 2012, 11:00:40 PM »
An avast scan has indicated 'gtdownde_87.ocx' is a high risk file.  I've put it in the virus chest for now.

I'm not sure it is harmful.  Googling it gives different answers and a lot of paranoia (as ever !).  Some seem to think its part of Dell Support  (i have a Dell PC).

So any ideas ? Putting in the chest doesn't seem to have caused me any problems at the moment.  The file dates from 2004, when i got the pc.
« Last Edit: March 08, 2012, 11:05:49 PM by Mr K »

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37698
Re: False Positive ? gtdownde_87.ocx
« Reply #1 on: March 08, 2012, 11:02:58 PM »
and where was the file located....post full path

Mr K

  • Guest
Re: False Positive ? gtdownde_87.ocx
« Reply #2 on: March 08, 2012, 11:06:10 PM »
it was in c:\i386 

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37698
Re: False Positive ? gtdownde_87.ocx
« Reply #3 on: March 08, 2012, 11:14:51 PM »
what malware name did avast give it ?

one file with that name scanned at VT yesterday

https://www.virustotal.com/file/5c251565efff7efca6520938fcf7ab73ddeb7084be712890b36726961d147979/analysis/

First seen by VirusTotal  2006-06-07 03:58:34 UTC ( 5 år, 9 måneder ago )


Sigcheck

publisher................: Gteko Ltd.
product..................: GTDown Module
internal name............: GTDown
copyright................: Copyright (C) 2000 - 2004 Gteko Ltd.
original name............: GTDown.OCX
comments.................:
file version.............: 1, 0, 0, 89
description..............: GTDown Module




so you should upload and scan your file to see


Mr K

  • Guest
Re: False Positive ? gtdownde_87.ocx
« Reply #4 on: March 08, 2012, 11:19:54 PM »
thanks for the help

Avast said it was:-    Win32:malware-gen

sorry to be a bit dumb but where will i find the file (to upload it to Virus Total) now i've put it in the virus chest ?

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37698
Re: False Positive ? gtdownde_87.ocx
« Reply #5 on: March 08, 2012, 11:26:18 PM »
easy...in the virus chest   ;)

first right click the file in chest and upload to avast lab as false positive so they can check it again

Then

Create a folder called Suspect in the C:\ drive. Now exclude that folder in the File System Shield, Expert Settings, Exclusions, Add, type (or copy and paste) C:\Suspect\*
That will stop the File System Shield scanning any file you put in that folder.

right click the file in chest and restore to that folder....then go to virustotal and browse to that folder/file

post scan result


Mr K

  • Guest
Re: False Positive ? gtdownde_87.ocx
« Reply #6 on: March 08, 2012, 11:41:33 PM »
ok, thanks, have done.

scanned and got the below.

https://www.virustotal.com/file/5c251565efff7efca6520938fcf7ab73ddeb7084be712890b36726961d147979/analysis/1331246290/

can't say i'm much the wiser, does this mean some programmes think it is a virus and others don't ?

Guess it'll stay in the virus chest.  If it is part of Dell Support I never use it anyway.  I've enabled a boot time scan, is there anything else I should do ?

Incidentally the file seems to have recreated itself in the same location.
« Last Edit: March 08, 2012, 11:43:18 PM by Mr K »

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37698
Re: False Positive ? gtdownde_87.ocx
« Reply #7 on: March 08, 2012, 11:46:09 PM »
well from the SHA-256 hash it is the exact same file as the VT scan i found

file is 5 years old....i suspect FP 

Mr K

  • Guest
Re: False Positive ? gtdownde_87.ocx
« Reply #8 on: March 08, 2012, 11:47:06 PM »
ok thanks, i can go to sleep now   ;)

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37698
Re: False Positive ? gtdownde_87.ocx
« Reply #9 on: March 08, 2012, 11:50:52 PM »
Avira lab
Quote
The file 'GTDownDE_87.ocx' has been determined to be 'FALSE POSITIVE'. In particular this means that this file is not malicious but a false alarm. Detection is removed from our virus definition file (VDF) with the version: 7.1.6.147.
« Last Edit: March 09, 2012, 12:07:35 AM by Pondus »

Offline Milos

  • Avast team
  • Super Poster
  • *
  • Posts: 2295
Re: False Positive ? gtdownde_87.ocx
« Reply #10 on: March 09, 2012, 07:27:54 AM »
Hello,
thank you for notice. False positive will be fixed in next VPS update.

Milos

Mr K

  • Guest
Another false positive?
« Reply #11 on: March 09, 2012, 12:29:03 PM »
Thanks for the info. 

 Following this false positive, i did a full scan.  As well as gtdownde_87.ocx, it came up with 'A0414502.ocx', seems to be in a system restore folder  c:\system volume information\_restore....'  .

Virus total says:-
https://www.virustotal.com/file/5c251565efff7efca6520938fcf7ab73ddeb7084be712890b36726961d147979/analysis/1331292067/

Another false positive ?

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37698
Re: False Positive ? gtdownde_87.ocx
« Reply #12 on: March 09, 2012, 12:54:55 PM »
since it is in system restore i guess it is a backup of the one already detected

clear your restore point and make new and it should be gone...or wait for the avast VPS fix
« Last Edit: March 09, 2012, 03:19:30 PM by Pondus »

Mr K

  • Guest
Re: False Positive ? gtdownde_87.ocx
« Reply #13 on: March 09, 2012, 01:04:06 PM »
ah makes sense, ta.