(Msg. 1) Posted: Fri Apr 13, 2007 12:17 am
Post subject: McAfee is moving program's exe into Quarantine folder Archived from groups: alt>comp>virus, others (more info?)
Hi All,
We have a program developed in VB6 and installed on hundreds of users
scattered around the world. This program is automatically run by an NT
service once a day. It's been running fine for the last 4-5 years.
Please note that all the users have exactly the same operating
environment, i.e. McAfee virus scan 8.0, OS is Windows XP SP2 and MS
office 2003 SP1.
Now SOME of the users have experienced a problem. The McAfee Virus
scan is moving the program's exe into C:\Quarantine folder and
renaming it to *.vir
(Msg. 2) Posted: Fri Apr 13, 2007 5:02 am
Post subject: Re: McAfee is moving program's exe into Quarantine folder [Login to view extended thread Info.] Archived from groups: per prev. post (more info?)
Hi,
McAfee detected an malware code inside your file. Question is if on every
system file is detected or only on some.
First case is caused by similiar malware signature in McAfee's database -
you can contact with McAfee and register a false positive
2nd case: can be caused by incorrect work of antivirus e.g. by damaged virus
signatures database. I met with that situation with Kaspersky AV. Try
re-download all database.
Marcin Domaslawski
Uzytkownik napisal w wiadomosci
> Hi All,
>
> We have a program developed in VB6 and installed on hundreds of users
> scattered around the world. This program is automatically run by an NT
> service once a day. It's been running fine for the last 4-5 years.
>
> Please note that all the users have exactly the same operating
> environment, i.e. McAfee virus scan 8.0, OS is Windows XP SP2 and MS
> office 2003 SP1.
>
> Now SOME of the users have experienced a problem. The McAfee Virus
> scan is moving the program's exe into C:\Quarantine folder and
> renaming it to *.vir
>
> Can you please advise why this problem is caused?
>
> Regards,
>
> FK
>
(Msg. 3) Posted: Fri Apr 13, 2007 5:23 am
Post subject: Re: McAfee is moving program's exe into Quarantine folder [Login to view extended thread Info.] Archived from groups: per prev. post (more info?)
On Apr 13, 1:12 pm, "Marcin Domaslawski" wrote:
> Hi,
>
> McAfeedetected an malware code inside your file. Question is if on every
> system file is detected or only on some.
> First case is caused by similiar malware signature inMcAfee'sdatabase -
> you can contact withMcAfeeand register a false positive
> 2nd case: can be caused by incorrect work of antivirus e.g. by damaged virus
> signatures database. I met with that situation with Kaspersky AV. Try
> re-download all database.
>
> Marcin Domaslawski
>
> Uzytkownik napisal w wiadomoscinews:1176448629.245440.276850@e65g2000hsc.googlegroups.com...
>
>
>
> > Hi All,
>
> > We have aprogramdeveloped in VB6 and installed on hundreds of users
> > scattered around the world. Thisprogramis automatically run by an NT
> > service once a day. It's been running fine for the last 4-5 years.
>
> > Please note that all the users have exactly the same operating
> > environment, i.e.McAfeevirus scan 8.0, OS is Windows XP SP2 and MS
> > office 2003 SP1.
>
> > Now SOME of the users have experienced a problem. TheMcAfeeVirus
> > scan ismovingtheprogram'sexeintoC:\Quarantinefolderand
> > renaming it to *.vir
>
> > Can you please advise why this problem is caused?
>
> > Regards,
>
> > FK- Hide quoted text -
>
> - Show quoted text -
I have just come to know that the executable is being detected as
malware just because it is using "RegCreateKeyEx" API to add a value
under "RunOnce" registry key.
Can you please tell a solution to this? I need to enter an entry under
"RunOnce" key.
(Msg. 4) Posted: Fri Apr 13, 2007 8:02 am
Post subject: Re: McAfee is moving program's exe into Quarantine folder [Login to view extended thread Info.] Archived from groups: per prev. post (more info?)
From:
| Hi All,
| We have a program developed in VB6 and installed on hundreds of users
| scattered around the world. This program is automatically run by an NT
| service once a day. It's been running fine for the last 4-5 years.
| Please note that all the users have exactly the same operating
| environment, i.e. McAfee virus scan 8.0, OS is Windows XP SP2 and MS
| office 2003 SP1.
| Now SOME of the users have experienced a problem. The McAfee Virus
| scan is moving the program's exe into C:\Quarantine folder and
| renaming it to *.vir
| Can you please advise why this problem is caused?
| Regards,
| FK
Assuming your author created a good ptrogram and not malware, submit the files being
falsely detected to McAfee via the email addtress virus_research.TakeThisOut@avertlabs.com and in the
subject of the email use "False Positive on VB6 software" and in the body of the email
state your case why you believe the attached files are not malware.
Attach all the files deemed malware (and you haven't posted what they were declared as) in
password protected ZIP file with the password being; infected { password = infected }
(Msg. 5) Posted: Fri Apr 13, 2007 1:05 pm
Post subject: Re: McAfee is moving program's exe into Quarantine folder [Login to view extended thread Info.] Archived from groups: per prev. post (more info?)
Hello,
Assuming the program is not malware I would not attempt to make any changes
to it.
Instead, follow David's advice and contact McAfee. If the program is not
malware they should be willing to update their definitions so the program is
no longer being flagged as malware.
--
Zephyr
wrote in message
> On Apr 13, 1:12 pm, "Marcin Domaslawski" wrote:
>> Hi,
>>
>> McAfeedetected an malware code inside your file. Question is if on every
>> system file is detected or only on some.
>> First case is caused by similiar malware signature inMcAfee'sdatabase -
>> you can contact withMcAfeeand register a false positive
>> 2nd case: can be caused by incorrect work of antivirus e.g. by damaged
>> virus
>> signatures database. I met with that situation with Kaspersky AV. Try
>> re-download all database.
>>
>> Marcin Domaslawski
>>
>> Uzytkownik napisal w
>> wiadomoscinews:1176448629.245440.276850@e65g2000hsc.googlegroups.com...
>>
>>
>>
>> > Hi All,
>>
>> > We have aprogramdeveloped in VB6 and installed on hundreds of users
>> > scattered around the world. Thisprogramis automatically run by an NT
>> > service once a day. It's been running fine for the last 4-5 years.
>>
>> > Please note that all the users have exactly the same operating
>> > environment, i.e.McAfeevirus scan 8.0, OS is Windows XP SP2 and MS
>> > office 2003 SP1.
>>
>> > Now SOME of the users have experienced a problem. TheMcAfeeVirus
>> > scan ismovingtheprogram'sexeintoC:\Quarantinefolderand
>> > renaming it to *.vir
>>
>> > Can you please advise why this problem is caused?
>>
>> > Regards,
>>
>> > FK- Hide quoted text -
>>
>> - Show quoted text -
>
> I have just come to know that the executable is being detected as
> malware just because it is using "RegCreateKeyEx" API to add a value
> under "RunOnce" registry key.
>
> Can you please tell a solution to this? I need to enter an entry under
> "RunOnce" key.
>
> Regards,
>
> FK
>
(Msg. 6) Posted: Fri Apr 13, 2007 6:03 pm
Post subject: Re: McAfee is moving program's exe into Quarantine folder [Login to view extended thread Info.] Archived from groups: per prev. post (more info?)
From: "Zephyr"
| Hello,
|
| Assuming the program is not malware I would not attempt to make any changes
| to it.
|
| Instead, follow David's advice and contact McAfee. If the program is not
| malware they should be willing to update their definitions so the program is
| no longer being flagged as malware.
|
Correct. They can create a negative Extra DAT that will disable the false declaration as
well subsequently update the next DAT revision to correct the mistaken identification.
(Msg. 7) Posted: Sat Apr 14, 2007 8:01 am
Post subject: Re: McAfee is moving program's exe into Quarantine folder [Login to view extended thread Info.] Archived from groups: alt>belgique>securite>virus, others (more info?)
It is my best shot.
inf0.TakeThisOut@sofutoinc.com
wrote in message
> Hi All,
>
> We have a program developed in VB6 and installed on hundreds of users
> scattered around the world. This program is automatically run by an NT
> service once a day. It's been running fine for the last 4-5 years.
>
> Please note that all the users have exactly the same operating
> environment, i.e. McAfee virus scan 8.0, OS is Windows XP SP2 and MS
> office 2003 SP1.
>
> Now SOME of the users have experienced a problem. The McAfee Virus
> scan is moving the program's exe into C:\Quarantine folder and
> renaming it to *.vir
>
> Can you please advise why this problem is caused?
>
> Regards,
>
> FK
>
(Msg. 8) Posted: Tue Apr 24, 2007 2:05 pm
Post subject: Re: McAfee is moving program's exe into Quarantine folder [Login to view extended thread Info.] Archived from groups: alt>comp>anti-virus, others (more info?)
I think Soooo
"Zephyr" wrote in message
> Hello,
>
> Assuming the program is not malware I would not attempt to make any
> changes to it.
>
> Instead, follow David's advice and contact McAfee. If the program is not
> malware they should be willing to update their definitions so the program
> is
> no longer being flagged as malware.
>
> --
> Zephyr
>
>
> wrote in message
> >> On Apr 13, 1:12 pm, "Marcin Domaslawski" wrote:
>>> Hi,
>>>
>>> McAfeedetected an malware code inside your file. Question is if on every
>>> system file is detected or only on some.
>>> First case is caused by similiar malware signature inMcAfee'sdatabase -
>>> you can contact withMcAfeeand register a false positive
>>> 2nd case: can be caused by incorrect work of antivirus e.g. by damaged
>>> virus
>>> signatures database. I met with that situation with Kaspersky AV. Try
>>> re-download all database.
>>>
>>> Marcin Domaslawski
>>>
>>> Uzytkownik napisal w
>>> wiadomoscinews:1176448629.245440.276850@e65g2000hsc.googlegroups.com...
>>>
>>>
>>>
>>> > Hi All,
>>>
>>> > We have aprogramdeveloped in VB6 and installed on hundreds of users
>>> > scattered around the world. Thisprogramis automatically run by an NT
>>> > service once a day. It's been running fine for the last 4-5 years.
>>>
>>> > Please note that all the users have exactly the same operating
>>> > environment, i.e.McAfeevirus scan 8.0, OS is Windows XP SP2 and MS
>>> > office 2003 SP1.
>>>
>>> > Now SOME of the users have experienced a problem. TheMcAfeeVirus
>>> > scan ismovingtheprogram'sexeintoC:\Quarantinefolderand
>>> > renaming it to *.vir
>>>
>>> > Can you please advise why this problem is caused?
>>>
>>> > Regards,
>>>
>>> > FK- Hide quoted text -
>>>
>>> - Show quoted text -
>>
>> I have just come to know that the executable is being detected as
>> malware just because it is using "RegCreateKeyEx" API to add a value
>> under "RunOnce" registry key.
>>
>> Can you please tell a solution to this? I need to enter an entry under
>> "RunOnce" key.
>>
>> Regards,
>>
>> FK
>>
>
>
>
You can post new topics in this forum You can reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum