Author Topic: question  (Read 7349 times)

0 Members and 1 Guest are viewing this topic.

shrine

  • Guest
question
« on: August 27, 2003, 05:17:25 AM »
Hi im new here and i got a question, i scanned my drive with avast and it found C:\Program Files\WinRAR\Zip.SFX [L] Win32:Trojan-gen. {UPX!} , the weird thing is that it's in the winrar.exe installation program too (its packed with the application), does anyone know if its really a virus or a false positive?

Offline raman

  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 1062
Re:question
« Reply #1 on: August 27, 2003, 07:27:07 AM »
Yes, it is a false alarm, nothing to worry about. Do not ask me, why they donĀ“t fix it. :)
MfG Ralf

shrine

  • Guest
Re:question
« Reply #2 on: August 28, 2003, 12:32:29 AM »
thank you  :)

Offline W4WMM

  • Newbie
  • *
  • Posts: 19
Re:question
« Reply #3 on: November 04, 2004, 11:47:09 PM »
I found this "Win32:Trojan-Gen (UPX!)" on my system also.

I deleted the "corupt" file.  It was called "i2BA.tmp."

Have I messed something up?  Everything seems to be working OK but then I haven't been able to test *everything*, what should I do, anything?

Alan
Alan, W4WMM

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31079
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re:question
« Reply #4 on: November 04, 2004, 11:53:01 PM »
If you look at the extension of that file, you will see it is a temporary file. A lot of the malware is using temp files to infect a system. I suggest you run a boot scan to see if something else comes up. Better safe than infected. ;)

Offline W4WMM

  • Newbie
  • *
  • Posts: 19
Re:question
« Reply #5 on: November 04, 2004, 11:56:32 PM »
I did and it came up clean but what had me concerned was the previous message that said it was a "false positive" so I was afraid I deleted something important.
Alan, W4WMM

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31079
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re:question
« Reply #6 on: November 04, 2004, 11:59:08 PM »
Nope, nothing to worry about. And if you look at the first post here, you will see that it is about a legitimate winrar file. Also if you look at the date you will see that it is a rather old post.

If a false positive is detected, Alwil fixes this normally with the next vps release.

Offline W4WMM

  • Newbie
  • *
  • Posts: 19
Re:question
« Reply #7 on: November 05, 2004, 12:03:14 AM »
Thank you!
Alan, W4WMM