Author Topic: is this a spoof site  (Read 5802 times)

0 Members and 1 Guest are viewing this topic.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: is this a spoof site
« Reply #15 on: July 08, 2011, 10:27:50 PM »
Change the drop down marked to no scan - otherwise it will invoke a quick scan with Avast as you have it resident

Does that file have a manufacturer under properties ?  I feel it may be becoming a bit sensative with the heuristics

Do you have a dell or HP as the MBR is non standard due to the recovery partition, this is not evident under Vista/7 as a different recovery method is used

Dch48

  • Guest
Re: is this a spoof site
« Reply #16 on: July 08, 2011, 10:39:32 PM »
Change the drop down marked to no scan - otherwise it will invoke a quick scan with Avast as you have it resident

Does that file have a manufacturer under properties ?  I feel it may be becoming a bit sensative with the heuristics

Do you have a dell or HP as the MBR is non standard due to the recovery partition, this is not evident under Vista/7 as a different recovery method is used
I have an HP but there is no recovery partition because I completely wiped the HD and installed XP Pro from another disk. I didn't use the HP recovery disks. I did however install all of the HP drivers including HP Quick Play which makes a 1gb partition at the end of the drive for the files needed to boot into Quick Play without fully booting Windows. I can push the DVD or Quick Play buttons on my keyboard when the machine is completely shut down and play a DVD without, as I said, fully booting into Windows. Maybe this has caused the non standard MBR you mention.

The file does have ATI Technologies as the manufacturer and it's described as - ATI Radeon WindowsNT Miniport Driver. It's a file that's present in all Radeon driver packages. When I navigate to the file and do a right click scan with Avast, it says it's clean. That's kind of strange , isn't it?
« Last Edit: July 08, 2011, 10:45:56 PM by Dch48 »

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: is this a spoof site
« Reply #17 on: July 08, 2011, 10:44:54 PM »
Sounds like another FP - an update has just been released so I am re-scanning with aswMBR to see if it is present

 HP Quick Play actually amends the MBR so that you do not need to boot to windows to use it

Dch48

  • Guest
Re: is this a spoof site
« Reply #18 on: July 08, 2011, 10:49:52 PM »
It still comes up as suspicious in aswMBR but the right click scan says it's clean.