Author Topic: False Positive Win32:Trojano-2167[Trj]??  (Read 6204 times)

0 Members and 1 Guest are viewing this topic.

Atomic_Ed

  • Guest
False Positive Win32:Trojano-2167[Trj]??
« on: August 27, 2005, 04:15:59 PM »
Hello everyone I am running Avast! 4.6 Pro and recently been getting a warning that a file on my system and an area of system restore is infected with Win32:Trojano-2167[Trj]. Now the file in question is the Acronis Disk Director Suite 9.0 application I recently purchased directly from the Acronis online store and have seen no ill effects with it. The filename is diskdirectorsuite9.0_d_en.exe

I have also since scanned the file with Mcaffe 9.0 and it does not detect anything.  I tried using the online scanners but because the file size is over 30mb it is too big for any of them I have found to scan.

Can anyone tell me if this is just a false positive? I think it is but want to make sure.

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: False Positive Win32:Trojano-2167[Trj]??
« Reply #1 on: August 27, 2005, 04:34:46 PM »
Most probably it's a false positive.
You can submit the file to Jotti and let us know the results, i.e., if it is or not a false positive.
If you are getting a virus warning that you believe is a false positive, then if you can zip and password protect ('virus', will do) the suspect file and send it to virus (at) avast.com.
Give a brief outline of the problem, the fact that you believe it to be a false positive and include the password in the body of the email. Some info on the avast version and VPS number (see About avast: right click avast icon) will also help.  ;)
The best things in life are free.

Atomic_Ed

  • Guest
Re: False Positive Win32:Trojano-2167[Trj]??
« Reply #2 on: August 27, 2005, 04:55:14 PM »
Thanks  for the reply but Jotti has a limit of 15mb and this file is over 30mb in size so I could not do that scan they have there. Also it is a commercial software so I am not sure it is legal to submit the file as it is the installer and whole program of Acronis Disk Director 9. I am not sure what the rules are for transmitting copyrighted programs like that and want to be careful not to violate and licensing terms.

Is there any other way for me to tell for sure if it is a false positive? Thanks again for your info on this.

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: False Positive Win32:Trojano-2167[Trj]??
« Reply #3 on: August 27, 2005, 04:59:16 PM »
Is there any other way for me to tell for sure if it is a false positive? Thanks again for your info on this.
Try on line with http://www.virustotal.com/
I'm not sure if it has a limitation.

Other backup (non-resident) scanners could be installed in your computer for this ocasions.
For instance, BitDefender (free), AVG (without the residents, plugins and email checker), ClamWin (without the residents), AntiVir (without the guard)...
They won't conflict with avast! if you choose NOT to install the residents.
The best things in life are free.

Atomic_Ed

  • Guest
Re: False Positive Win32:Trojano-2167[Trj]??
« Reply #4 on: August 27, 2005, 05:00:56 PM »
Thanks again I will try that link and post back. Also do you know if Panda TruePrevent will run with avast! ok too and also on x64 system which I am running? Sorry for all the questions but I do appreciate your help.

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: False Positive Win32:Trojano-2167[Trj]??
« Reply #5 on: August 27, 2005, 05:16:56 PM »
Also do you know if Panda TruePrevent will run with avast! ok too
I think not, as it is a resident and will conflict.

And also on x64 system which I am running?
Are you sure Panda works on x64 systems?
I thought only avast! was prepared for this right now  8)
The best things in life are free.

Atomic_Ed

  • Guest
Re: False Positive Win32:Trojano-2167[Trj]??
« Reply #6 on: August 27, 2005, 05:21:06 PM »
That was what I was asking if it would work on x64 but I think probably not. I tried that scan link and it failed as they have only a 10mb files size limit.

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: False Positive Win32:Trojano-2167[Trj]??
« Reply #7 on: August 27, 2005, 05:52:35 PM »
I recommend the backup (non-resident) scanners as before  8)
The best things in life are free.

Offline igor

  • Avast team
  • Serious Graphoman
  • *
  • Posts: 11856
    • AVAST Software
Re: False Positive Win32:Trojano-2167[Trj]??
« Reply #8 on: August 28, 2005, 01:58:06 AM »
Can you please upload the file to our anonymous FTP at ftp://ftp.asw.cz/incoming ? (You won't see anything there, because the anonymous account doesn't have read & list rights.)

We'll check the file and fix the false positive. Thanks! (and sorry for the troubles)

shatadal

  • Guest
Re: False Positive Win32:Trojano-2167[Trj]??
« Reply #9 on: August 28, 2005, 02:24:10 AM »
I think I have the same problem. I have another program from acronis, Acronis True Image 8.0. I just downloaded the install file from download.com and scanned it with avast. I got the following warning messages

File Name: trueimage8.0_d_en.exe\trueimg.exe
Malware Name: Win32:Trojano-2167 [Trj]
Malware Type: Trojan Horse
VPS version: 0534-4, 26/08/2005

File Name: trueimage8.0_d_en.exe\ti_boot.exe
Malware Name: Win32:Trojano-2167 [Trj]
Malware Type: Trojan Horse
VPS version: 0534-4, 26/08/2005

This seems to the same warning which the OP put in his post. I have uploaded the file trueimage8.0_d_en.exe to ftp.asw.cz/incoming

My system information is

Windows XP SP1
Avast version 4.6 Home edition Build Jul 2005 (4.6.691)
VPS version is given in the error messages

Thanks,
Shatadal.

Atomic_Ed

  • Guest
Re: False Positive Win32:Trojano-2167[Trj]??
« Reply #10 on: August 28, 2005, 11:07:26 PM »
Can you please upload the file to our anonymous FTP at ftp://ftp.asw.cz/incoming ? (You won't see anything there, because the anonymous account doesn't have read & list rights.)

We'll check the file and fix the false positive. Thanks! (and sorry for the troubles)


Thanks and I have uploaded the file to your ftp site just now.

shatadal

  • Guest
Re: False Positive Win32:Trojano-2167[Trj]??
« Reply #11 on: August 29, 2005, 10:24:00 PM »
I scanned the Acronis True Image installer file again this morning with the latest definitions update 0535-0 and this time I got no error messages. Thanks for the quick update to get rid of the false positives.

Offline igor

  • Avast team
  • Serious Graphoman
  • *
  • Posts: 11856
    • AVAST Software
Re: False Positive Win32:Trojano-2167[Trj]??
« Reply #12 on: August 29, 2005, 11:09:26 PM »
Yes, it was corrected.
Thanks for your help, and sorry for the troubles.

Atomic_Ed

  • Guest
Re: False Positive Win32:Trojano-2167[Trj]??
« Reply #13 on: August 30, 2005, 03:05:13 AM »
Thank you for so quickly addressing and fixing this!