Jump to content
IObit Forum
Top Free Driver Updater Tools Best 25 PC Optimization Software Best 22 Antimalware Best 22 Uninstaller Software IObit Coupons & Discount Offers PC Optimizer Mac Boost Advice IObit Coupons A Good Utility Program From IObit IObit Promo Codes IObit Coupon Codes IObit Coupons and Deals FAQs Driver Booster Pro Review

IE 6 False Positive


Recommended Posts

It detected the autorun for IE6 as a trojan. It is not. Zero results one Virustotal.com: http://www.virustotal.com/analisis/2622c45b7d3edba1acd44c58b480e053710131cd1d8c99a8e2c7d9caedbef5f1-1251394307

 

IObit Security 360

 

OS:Windows XP

Version:0.4.0.20

Define Version:1123

Time Elapsed:8/27/2009 1:31:04 PM

Objects Scanned:57557

Threats Found:226

 

|Name|Type|Description|ID|

Trojan.Downloader, File, C:\Documents and Settings\Andy\Desktop\Utility CD\Browsers and accessories\Internet Explorer 6\IE.exe, 8-512

Link to comment
Share on other sites

I don't think that link is relevant to this item because it says that the file is W32/Sdbot-VS and provides a link to Sophos' website making me believe the item your link is referring to is detected by Sophos.

 

The item I'm talking about was uploaded to virustotal.com and Sophos said it was not a virus.

 

Also (though I'm not 100 percent sure on this part) I think this came off an genuine MSIE installation disc.

Link to comment
Share on other sites

I don't think that link is relevant to this item because it says that the file is W32/Sdbot-VS and provides a link to Sophos' website making me believe the item your link is referring to is detected by Sophos.

 

The item I'm talking about was uploaded to virustotal.com and Sophos said it was not a virus.

 

Also (though I'm not 100 percent sure on this part) I think this came off an genuine MSIE installation disc.

 

 

Sophos?

I can't see any sophos company link in the webpage I provided.

bleepingcomputer is an independent, authorative and well known forum devoted to security.

Well, and virustotal cannot know what happen when a file is executed, no warranties are provided;)

 

Cheers

Link to comment
Share on other sites

The W32/Sdbot-VS was the link in "Description: Added by W32/Sdbot-VS TROJAN/backdoor. Remote access, by way of the IRC network, becomes available to unauthorized users."

 

I guess my in my first post my case that it is a false positive revolved around the fact that it isn't detected by 41 malware scanners. Also I looked up the hash generated by virus total on Google and it found this: http://processlist.com/info/ie-4.html which says that it is the autorun program from the IE6 setup disc which is what I already thought it was. Is processlist.com is a pretty reputable site because I think the odds of the autorun having a hash collision in two different algorithms with a trojan is pretty slim?

Link to comment
Share on other sites

Archived

This topic is now archived and is closed to further replies.

×
×
  • Create New...