Author Topic: FFXI: Uruguay 6/7/8 - false positive?  (Read 5855 times)

0 Members and 1 Guest are viewing this topic.

Offline keir

  • Newbie
  • *
  • Posts: 15
FFXI: Uruguay 6/7/8 - false positive?
« on: July 23, 2005, 06:12:11 PM »
I'm trying to update Final Fantasy XI, but it keeps alerting me to:

File name: C:\Program Files\PlayOnline\SquareEnix\FINAL FANTASY XI\ROM2\13\55.DAT.tmp3
File name: C:\Program Files\PlayOnline\SquareEnix\FINAL FANTASY XI\ROM2\13\55.DAT.tmp2

Malware name: Uruguay 6/7/8

Malware type: Virus/Worm

VPS version: 0529-2, 21/07/2005

false positives, surely?

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31302
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re: FFXI: Uruguay 6/7/8 - false positive?
« Reply #1 on: July 23, 2005, 06:17:42 PM »
Submit these files to JOTTI and tell us what it says.

Offline keir

  • Newbie
  • *
  • Posts: 15
Re: FFXI: Uruguay 6/7/8 - false positive?
« Reply #2 on: July 23, 2005, 06:27:20 PM »
 File:      55.DAT
Status:    
POSSIBLY INFECTED/MALWARE (Note: this file has been scanned before. Therefore, this file's scan results will not be stored in the database) (Note: this file was only classified as malware by scanners known to generate more false positives than the average scanner. Do not consider these results definately accurate. Also, because of this, results of this scan will not be recorded in the database.)
MD5    6dc4a8c3865218254f26333ef959057a
Packers detected:    
-
Scanner results
AntiVir    
Found nothing
ArcaVir    
Found nothing
Avast    
Found Uruguay 6/7/8
AVG Antivirus    
Found nothing
BitDefender    
Found nothing
ClamAV    
Found nothing
Dr.Web    
Found nothing
F-Prot Antivirus    
Found nothing
Fortinet    
Found nothing
Kaspersky Anti-Virus    
Found nothing
NOD32    
Found nothing
Norman Virus Control    
Found nothing
UNA    
Found nothing
VBA32    
Found nothing

what's it on about 'this file was only classified as malware by scanners known to generate more false positives than the average scanner.'?  cheeky! that's not been my experience of avast, if it was i'd be using something else!

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31302
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re: FFXI: Uruguay 6/7/8 - false positive?
« Reply #3 on: July 23, 2005, 06:34:28 PM »
Please submit the files in a password protected zip to virus@avast.com
Mention in the body of the mail the password and a link to this thread.
Let the people from Alwil have a look at it.

Offline calcu007

  • Avast Evangelist
  • Poster
  • ***
  • Posts: 482
  • I'm lamma!
Re: FFXI: Uruguay 6/7/8 - false positive?
« Reply #4 on: July 23, 2005, 09:44:47 PM »
Avast is good giving false positive. It is the price to use a free program. I had never seen a false positive using Norton and it have better detection rate.
« Last Edit: July 23, 2005, 09:50:15 PM by calcu007 »
Asus Intel i7 8GB RAM , Win 8.1 64 bit, Avast IS

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31302
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re: FFXI: Uruguay 6/7/8 - false positive?
« Reply #5 on: July 23, 2005, 10:15:48 PM »
Calcu,

I've seen FP's with EVERY AV I have seen. And trus me, after about 25 years I've seen a lot of av's.

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67247
Re: FFXI: Uruguay 6/7/8 - false positive?
« Reply #6 on: September 22, 2005, 03:29:24 AM »
Guestlogin, if you're sure, you can add it to the two avast! exclusion lists.
One in program settings, for the on-demand scanning.
And other in Standard Shield settings, for the on-access protection (residents).
The best things in life are free.

Offline Cloussau

  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 897
  • AVAST! antivirus with balls
Re: FFXI: Uruguay 6/7/8 - false positive?
« Reply #7 on: September 22, 2005, 03:31:19 AM »
if you are confident that it isnt malware and not a threat you can put the file path in your exclusion list (in settings) then it will not be scanned :)
sys- p4  3.0D ,  1024mb ddram ;arsenal :Avast IS 5.0 pro / Firefox / adblock /noscript : win xp/pro/sp3 32 bit