Live Chat & Podcast at 1:00PM Eastern on Sunday!
There's no such thing as a stupid question, but they're the easiest to answer.
JoinTour
Login
Search
General Security
Tag Cloud
access acer asus bios bsod computer crash desktop driver drivers error ethernet excel freeze games gaming hard drive hardware hdmi internet laptop malware memory monitor motherboard netgear network printer problem ram random registry router slow software sound trojan ubuntu 11.10 uninstall usb video virus vista wifi windows windows 7 windows 7 32 bit windows 7 64 bit windows xp wireless
Search
Search for:
Tech Support Guy Forums > Security & Malware Removal > General Security >
Expert Opinion Please?

Reply  
Thread Tools
Rivera42's Avatar
Computer Specs
Senior Member with 821 posts.
 
Join Date: Aug 2007
Location: Strong Island, New York
Experience: I Know That I Don't Know
26-May-2008, 05:20 AM #1
Expert Opinion Please?
Avast Home Edition 4.8 detects "dvdrip 0.2.exe" as a virus, which makes no sense to me. The file comes from the following:
http://lifehacker.com/355281/dvd-rip...ck-dvd-ripping
and I was hoping somebody could shed some light on this.

In an interesting side note, I've run this application at least once to get it set up, and Avast didn't flag it, but during this weekly scan of my PC, it did.

It's a simple no-install executable, and I'd like to upload it to Virus Total's online file scanner, but that isn't working. I assume this is because Avast is doing its job, for which I'm grateful, but I think you can see the conflict of interest here.

**NOTE: This morning (around six hours or so after first posting this), I launched SUPERAntiSpyware on my other laptop, and Avast decided to flag THAT as containing a virus. I was unable to run the program until I used the Avast "pause provider" feature.

I think DVD Rip is a script, and that may have a role in this. Go to:
http://www.autohotkey.com/forum/topic27562-15.html
__________________


---> Please click Refresh; I edit my posts frequently. <---


Your new best friend: the F-11 key

Best Default Homepage Ever For MSIE

Photographs Of A Rainbow!

New original pictures of 19th/20th century technology


Add me on Facebook

When I die, I want to go peacefully like my Grandfather did, in his sleep -- not screaming, like the passengers in his car.

Last edited by Rivera42; 26-May-2008 at 12:32 PM..
Mark0's Avatar
Junior Member with 8 posts.
 
Join Date: Apr 2008
Location: Venice, Italy
Experience: Intermediate
26-May-2008, 05:49 PM #2
When in doubt, you can always check a file with one of the various online analysis tools.
For example, VirtusTotal report the finding of a numbers of diffent antivirus engines:
http://www.virustotal.com/

But often, it just take an executable to be compressed with some EXE packer to raise the alarm of certain AV engines. An interesting analysis tools based on different principles is Norman Sandbox:
http://www.norman.com/microsites/nsic/Submit/

Hope this helps,
Bye!
Rivera42's Avatar
Computer Specs
Senior Member with 821 posts.
 
Join Date: Aug 2007
Location: Strong Island, New York
Experience: I Know That I Don't Know
26-May-2008, 06:16 PM #3
Quote:
Originally Posted by Rivera42 View Post
... I'd like to upload it to Virus Total's online file scanner, but that isn't working. I assume this is because Avast is doing its job, for which I'm grateful, but I think you can see the conflict of interest here...

I think DVD Rip is a script, and that may have a role in this. Go to:
http://www.autohotkey.com/forum/topic27562-15.html
Ummm.....
Mark0's Avatar
Junior Member with 8 posts.
 
Join Date: Apr 2008
Location: Venice, Italy
Experience: Intermediate
26-May-2008, 06:23 PM #4
Ops, sorry for the Virus Total double.
But, I just tried it myself and as I had supposed, various engine flagged it as a Trojan, while the analysis of the Norman Sandbox don't flag any strange activity.

Bye!
Rivera42's Avatar
Computer Specs
Senior Member with 821 posts.
 
Join Date: Aug 2007
Location: Strong Island, New York
Experience: I Know That I Don't Know
28-May-2008, 12:16 AM #5
Presumably the file you scanned is the same as the one on my pc. I think I have to disable Avast temporarily (right-click tray icon/pause on-access provider) to do anything with that file now, despite the fact that I've added its containing folder to the ignore list. Given the inconclusive nature of the mixed scan results, what -if anything- should I do about all this? Scrap the program entirely and get dvdfab or something like that, or what?
__________________


---> Please click Refresh; I edit my posts frequently. <---


Your new best friend: the F-11 key

Best Default Homepage Ever For MSIE

Photographs Of A Rainbow!

New original pictures of 19th/20th century technology


Add me on Facebook

When I die, I want to go peacefully like my Grandfather did, in his sleep -- not screaming, like the passengers in his car.
Mark0's Avatar
Junior Member with 8 posts.
 
Join Date: Apr 2008
Location: Venice, Italy
Experience: Intermediate
28-May-2008, 05:51 AM #6
This is the report from the Norman Sandbox:

Code:
 [ DetectionInfo ]
   * Sandbox name: NO_MALWARE
   * Signature name: NO_VIRUS
   * Compressed: YES
   * TLS hooks: NO
   * Executable type: Application
   * Executable file structure: OK

 [ General information ]
   * **Locates window "C:\SAMPLE.EXE [class AutoHotkey]" on desktop.
   * Display message box (SAMPLE.EXE) : CreateWindow.
   * File length:       305139 bytes.
   * MD5 hash: db0e34fe7f6f1eed30fca33b3754c7d8.
So I think the file is OK.
But, if you want to be perfectly safe, you could try it before in a Virtual Machine, maybe, or with Sandboxie.

Bye!
jbhardman's Avatar
Computer Specs
Member with 140 posts.
 
Join Date: Jan 2006
Location: Pleasant Grove, UT
Experience: Advanced
03-Jun-2008, 02:50 PM #7
Not to bash Avast (I know a lot of people love it) but av-comparatives.org gave it a rating of "many" on false positives.
Rivera42's Avatar
Computer Specs
Senior Member with 821 posts.
 
Join Date: Aug 2007
Location: Strong Island, New York
Experience: I Know That I Don't Know
03-Jun-2008, 04:50 PM #8
Now I can't run the application; Avast won't allow it and I'd have to disable On-Access protection to use the file. Not that I have any great burning need to run it right this second, I'm just sayin'.

It's great to have an AV that's aggressive, but this is a little much. Heck, I even tried to edit the allow list and it's still blocking the program anyway.
__________________


---> Please click Refresh; I edit my posts frequently. <---


Your new best friend: the F-11 key

Best Default Homepage Ever For MSIE

Photographs Of A Rainbow!

New original pictures of 19th/20th century technology


Add me on Facebook

When I die, I want to go peacefully like my Grandfather did, in his sleep -- not screaming, like the passengers in his car.
Reply

THIS THREAD HAS EXPIRED.
Are you having the same problem? We have volunteers ready to answer your question, but first you'll have to join for free. Need help getting started? Check out our Welcome Guide.

Search Tech Support Guy

Find the solution to your
computer problem!




Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
WELCOME TO TECH SUPPORT GUY! Are you looking for the solution to your computer problem? Join our site today to ask your question -- for free! Our site is run completely by volunteers who want to help you solve your computer problems. See our Welcome Guide to get started.
Thread Tools



Facebook Facebook Twitter Twitter TechGuy.tv TechGuy.tv Mobile TSG Mobile
You Are Using:
Server ID
Advertisements do not imply our endorsement of that product or service.
All times are GMT -4. The time now is 07:06 PM.
Copyright © 1996 - 2011 TechGuy, Inc. All rights reserved.

Powered by Cermak Technologies, Inc.