False positives?
#1 OFFLINE
Posted 29 June 2005 - 04:04 PM
Then scanned with a squared. Got 2 items as malware.
Filename:
C:\WINDOWS\system32\AS-Exp2.ocx
C:\WINDOWS\system32\AS-IFce1.ocx
Diagnosis:
Backdoor.MSWord.Nutshell
Backdoor.MSWord.Nutshell
This time I didn't delete anything [ if you remember,I had a bad experience b4, http://forum.CCleane...wtopic=1426&hl= ]
Wondering if those are false positives.
Cheers
#2 OFFLINE
Posted 29 June 2005 - 05:14 PM
Wait to see what Tarun or DjLizard say but I personally would remove those. If ewido finds them than I would deffinately remove them. Also remember to update ewido before you scan with it.
#3 OFFLINE
#4 OFFLINE
Posted 30 June 2005 - 01:29 AM
Tarun, on Jun 30 2005, 02:09 AM, said:
Did that last night, no virus indicated.
Steve
#5 OFFLINE
Posted 30 June 2005 - 01:30 AM
rridgely, on Jun 30 2005, 01:14 AM, said:
Wait to see what Tarun or DjLizard say but I personally would remove those. If ewido finds them than I would deffinately remove them. Also remember to update ewido before you scan with it.
Will try that tonite.Thanks
#6 OFFLINE
Posted 30 June 2005 - 01:37 AM
#7 OFFLINE
Posted 30 June 2005 - 02:47 PM
rridgely, on Jun 30 2005, 01:14 AM, said:
Wait to see what Tarun or DjLizard say but I personally would remove those. If ewido finds them than I would deffinately remove them. Also remember to update ewido before you scan with it.
Did that, nothing found
Tarun, on Jun 30 2005, 02:09 AM, said:
Did it again for the 2nd time , nothing found.
I scanned again with a squared this evening. Guess...this time nothing found. I'm truly puzzled. The only thing I did last nite was to run my regular Tarun's anti-malware package, that's it, nothing else.
Now, nothing found with a squared.
I'm delighted but also very puzzled, how "backdoor" can just disappear ?
Anybody has any clue ?
Steve
#8 OFFLINE
Posted 30 June 2005 - 07:14 PM
#9 OFFLINE
Posted 30 June 2005 - 08:47 PM
DjLizard.net
DjLizard.net wiki
Dial-a-fix
Dial-a-fix tips
DjLizard.net software support forum
Do you live in Bradenton, Sarasota, Tampa, or St. Petersburg, Florida? Visit Digital Doctors where I work :)
#10 OFFLINE
Posted 30 June 2005 - 08:54 PM
steve1368, on Jun 30 2005, 08:47 AM, said:
#11 OFFLINE
Posted 01 July 2005 - 04:35 AM
rridgely, on Jul 1 2005, 03:14 AM, said:
Andavari, on Jul 1 2005, 04:54 AM, said:
I have avast home resident scanner, msas & outpost pro running all the time.
Is there anyway to check further to be really sure, or should I just post here my current HJT log for analysis.
#12 OFFLINE
Posted 01 July 2005 - 04:55 AM
#13 OFFLINE
Posted 01 July 2005 - 03:18 PM
rridgely, on Jul 1 2005, 12:55 PM, said:
Did that with avast & ewido.....nothing
I'll post my new hijack this log in a new topic.
Hopefully nothing nasty.
Thanks
#14 OFFLINE
Posted 12 July 2005 - 10:56 PM
#15 OFFLINE
Posted 12 July 2005 - 11:11 PM
as-ifce1.ocx - Ariad Interface Components
Ariad components was made by Cyotek which was taken by Innovasys.












