Facebook   Twitter   Google+   YouTube Get FREE Online Help Free Download IObit Products  

Go Back   IObit.Com Forums > IObit Security Software > False Positive Reports by IObit Products
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

False Positive Reports by IObit Products Report the false positives from IObit Products. We will fix all false positives as soon as possible.

Reply
 
Thread Tools Display Modes
  #1  
Old Nov. 5th, 2010, 14:14
Flutterby's Avatar
Flutterby Flutterby is offline
Junior Member
 
Join Date: 08 Feb 2010
Posts: 9
Question Misleading.WindowsDefence GDIPFONTCACHEV1.DAT false positive?

My IObit Security 360 found this during a full scan.

Threats Found:1

|Name|Type|Description|ID|
Misleading.WindowsDefence, File, C:\Documents and Settings\Christina\Local Settings\Application Data\GDIPFONTCACHEV1.DAT, 4-31243


I read that it's a possible fp that could be linked with an hp printer, but I don't use an hp printer. Should I remove this?

Any help would be greatly appreciated.

TY

Last edited by Flutterby : Nov. 5th, 2010 at 14:16.
Reply With Quote
  #2  
Old Nov. 5th, 2010, 16:11
So_sad's Avatar
So_sad So_sad is offline
Expert User
 
Join Date: 19 Nov 2009
Posts: 407
Default

Hi Flutterby

That file has been present in Windows for years. It's a font cache .dat file.

Most likely a false positive.

A moderator will probably move this topic over to the False Positive section.

===
__________________
Is it winter yet ?
Reply With Quote
  #3  
Old Nov. 6th, 2010, 18:23
scrd01's Avatar
scrd01 scrd01 is offline
IObit VIP
 
Join Date: 09 Jun 2009
Posts: 592
Default snap

This file also came up on my quick scan today, running full scan now.

same on full scan, i dont have any printers on my setup either.
|Name|Type|Description|ID|
Misleading.WindowsDefence, File, C:\Users\scrd100\Local Settings\Application Data\GDIPFONTCACHEV1.DAT, 4-31243

Last edited by scrd01 : Nov. 6th, 2010 at 18:28. Reason: full scan detail
Reply With Quote
  #4  
Old Nov. 6th, 2010, 20:51
enoskype's Avatar
enoskype enoskype is offline
Mediator®
 
Join Date: 27 Oct 2006
Posts: 10,293
Default

Most probably false positive, but please follow the procedure in Guidelines and Requirements for Reporting a False Positive. thread.

Upload the file to www.VirusTotal.com to give the report link here, and upload the file to www.wikisend.com to give the download link here for IObit to further investigate.

Cheers.
__________________
enoskype

- Beauty lies in the eye of the beholder and belongs to the man who can appreciate it. -
Reply With Quote
  #5  
Old Nov. 6th, 2010, 21:10
scrd01's Avatar
scrd01 scrd01 is offline
IObit VIP
 
Join Date: 09 Jun 2009
Posts: 592
Default virus scan report

Hi Enoskype,
Virus scan came back clean,
MD5 : c1259a609995dc3678b41a047a9aa85a
SHA1 : 57b7a370c33dd32b73406def8934e6bee5121ee2
SHA256: 94fa8964abc708e1f7d07d3b77a86ef34849e7b7927f91b1de b28fcc4b557975


Roy
Reply With Quote
  #6  
Old Nov. 7th, 2010, 22:30
LesBater LesBater is offline
Senior Member
 
Join Date: 25 Feb 2010
Posts: 32
Question False Positive on file GDIPFONTCACHEV1.DAT

On November 5th, I updated the definition file and ran fulls scans on all of my PC's. These include WindowsXP-SP3, Windows Vista-SP2 both x32 and x64 and Winows 7 x64. All reported:

Misleading.WindowsDefence on file GDIPFONTCACGEV1.DAT file.

Here is the scan history report from one of the PC's

IObit Security 360

OS:Windows Vista
Version:1.5.0.13
Define Version:1924
Time Elapsed:00:01:10
Objects Scanned:49906
Threats Found:1

|Name|Type|Description|ID|
Misleading.WindowsDefence - Quarantined, File, C:\Users\LeslieDBater_Admin\Local Settings\Application Data\GDIPFONTCACHEV1.DAT, 4-31243

This file has been in Windows for years and has never been a problem.

I also uploaded the file to VirusTotal and it ran against 42 different scan software and none of them found anything wrong.

I hope that this gets corrected as soon as possible.

Les Bater
Reply With Quote
  #7  
Old Nov. 8th, 2010, 00:26
hxin's Avatar
hxin hxin is offline
IObit Support
 
Join Date: 20 Jan 2010
Posts: 283
Smile

Quote:
Originally Posted by scrd01 View Post
Hi Enoskype,
Virus scan came back clean,
MD5 : c1259a609995dc3678b41a047a9aa85a
SHA1 : 57b7a370c33dd32b73406def8934e6bee5121ee2
SHA256: 94fa8964abc708e1f7d07d3b77a86ef34849e7b7927f91b1de b28fcc4b557975


Roy
Hi scrd01

Tanks for your feeback.
You can send the file (GDIPFONTCACHEV1.DAT) to www.wikisend.com and give us the link.
__________________
IObit Support Team
Reply With Quote
  #8  
Old Nov. 8th, 2010, 00:33
Flagman Flagman is offline
Junior Member
 
Join Date: 27 Sep 2010
Posts: 11
Default

I also received the same when I did a full scan just started a few days ago and was fine before that.What is the next step to removing this link.Thanks in advance for your help.
Reply With Quote
  #9  
Old Nov. 8th, 2010, 11:03
wagygirl's Avatar
wagygirl wagygirl is offline
Junior Member
 
Join Date: 08 Nov 2010
Posts: 24
Unhappy False Positive-same one everyday

IObit Security 360

OS:Windows 7
Version:1.5.0.10
Define Version:1926
Time Elapsed:00:02:30
Objects Scanned:50932
Threats Found:1

|Name|Type|Description|ID|
Misleading.WindowsDefence- Quarantined, File, C:\Users\Amber\Local Settings\Application Data\GDIPFONTCACHEV1.DAT, 4-31243


_________________________________________________

I get this same false positive everyday. IObit Security 360 removes it, and Windows puts it back.
Please fix this. It is messing up my computer everyday when I start it.

Otherwise, I LOVE your products.
__________________
SavedByGrace -Ephesians 2:8-9
Reply With Quote
  #10  
Old Nov. 8th, 2010, 14:27
So_sad's Avatar
So_sad So_sad is offline
Expert User
 
Join Date: 19 Nov 2009
Posts: 407
Default

Hi hxin,

I checked on my own machine and the file is there. I opened it and it is all fonts descriptions inside. As the file name suggests, it is a font cache file. Totally harmless.

Because it is a cache file, I'm thinking that size (and therefore checksum) will vary from region to region, from OS to OS, so if IS360 is targetting the file by name only, you can safely remove the detection.

===
__________________
Is it winter yet ?
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Get FREE Online Help



Free Download IObit Products




Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Rogue/Misleading/Scareware that are not false positive Tim Xue False Positive Reports by IObit Products 11 Apr. 21st, 2011 05:53
False Positive? "Misleading.ExtremeSecurity" occasional False Positive Reports by IObit Products 1 Jul. 6th, 2010 06:26
Possible False Positive "Misleading.DefenseCenter" [SOLVED by db 1614] burrellbuzzman False Positive Reports by IObit Products 6 Jun. 21st, 2010 01:29
install.exe by MS, is it false positive? [SOLVED] enoskype False Positive Reports by IObit Products 2 Aug. 4th, 2009 00:02
Opera@USB False Positive [SOLVED] Max Wachtel False Positive Reports by IObit Products 2 Jul. 20th, 2009 20:39


All times are GMT +0. The time now is 14:45.


Powered by vBulletin® Version 3.6.8
Copyright ©2000 - 2014, Jelsoft Enterprises Ltd.