Jump to content
IObit Forum
Top Free Driver Updater Tools Best 25 PC Optimization Software Best 22 Antimalware Best 22 Uninstaller Software IObit Coupons & Discount Offers PC Optimizer Mac Boost Advice IObit Coupons A Good Utility Program From IObit IObit Promo Codes IObit Coupon Codes IObit Coupons and Deals FAQs Driver Booster Pro Review

Are these False Positives? [SOLVED]


Recommended Posts

Just ran two on demand scans, one with IObit 360 and one with malwarebytes

 

Malwarebytes reported nothing and scanned 192861 objects, only reason i say this is because it scanned more objects than IObit 360 so would have more chance of similar results.

 

The IObit scan found 3 trojan agents, here is what the log file said;

 

IObit Security 360

 

OS:Windows 7

Version:1.4.0.11

Define Version:1321

Time Elapsed:00:27:38

Objects Scanned:131037

Threats Found:3

 

|Name|Type|Description|ID|

Trojan.Agent, File, C:\Program Files (x86)\Zone Labs\ZoneAlarm\cam.zap, 12-1046

Trojan.Agent, File, C:\Windows\winsxs\amd64_wiacn001.inf_31bf3856ad364e35_6.1.7600.16385_none_95eb24d2d4a0a55b\CNHW900.DLL, 12-1046

Trojan.Agent, File, C:\Windows\System32\DriverStore\FileRepository\wiacn001.inf_amd64_neutral_b7a0b2f53d745b5a\CNHW900.DLL, 12-1046

 

 

Would somebody please be able to tell me if these are false positives or if they are something to worry about?

 

Many thanks rob

Link to comment
Share on other sites

Link to comment
Share on other sites

Hi Rob,

 

They sure look like FPs to me. The first one is definitely Zone Alarm related.

I wasn't sure about the other two simply because you had a space in the .dll extension in your first post : CNHW900.D LL

 

VirusTotal clearly shows no space, and no detections whatsoever. The spaces were propably added when you copy/pasted from the IS360 log to here.

 

All clear :wink:

Link to comment
Share on other sites

Moved thread

 

Hi burrellbuzzman :smile:

 

Thanks for your post and the VirusTotal reports, well done.

Sure looks like FPs and will be corrected in a future Definitions update :smile:

 

I moved your thread to the False Positives Report section where it will get noticed more easily.

 

All the best, woz of oz

Link to comment
Share on other sites

Just ran two on demand scans, one with IObit 360 and one with malwarebytes

 

Malwarebytes reported nothing and scanned 192861 objects, only reason i say this is because it scanned more objects than IObit 360 so would have more chance of similar results.

 

The IObit scan found 3 trojan agents, here is what the log file said;

 

IObit Security 360

 

OS:Windows 7

Version:1.4.0.11

Define Version:1321

Time Elapsed:00:27:38

Objects Scanned:131037

Threats Found:3

 

|Name|Type|Description|ID|

Trojan.Agent, File, C:\Program Files (x86)\Zone Labs\ZoneAlarm\cam.zap, 12-1046

Trojan.Agent, File, C:\Windows\winsxs\amd64_wiacn001.inf_31bf3856ad364e35_6.1.7600.16385_none_95eb24d2d4a0a55b\CNHW900.DLL, 12-1046

Trojan.Agent, File, C:\Windows\System32\DriverStore\FileRepository\wiacn001.inf_amd64_neutral_b7a0b2f53d745b5a\CNHW900.DLL, 12-1046

 

 

Would somebody please be able to tell me if these are false positives or if they are something to worry about?

 

Many thanks rob

 

hello burrellbuzzman

Thanks for your feedback.

you can upload or send us your suspicious file, and then we can further investigate it.

We are looking forward to your reply.

_______________

IObit Support Team

Link to comment
Share on other sites

Here is the log scan again:

 

 

 

 

IObit Security 360

 

OS:Windows 7

Version:1.4.0.11

Define Version:1321

Time Elapsed:00:27:38

Objects Scanned:131037

Threats Found:3

 

|Name|Type|Description|ID|

Trojan.Agent, File, C:\Program Files (x86)\Zone Labs\ZoneAlarm\cam.zap, 12-1046

Trojan.Agent, File, C:\Windows\winsxs\amd64_wiacn001.inf_31bf3856ad364e35_6.1.7600.16385_none_95eb24d2d4a0a55b\CNHW900.DLL, 12-1046

Trojan.Agent, File, C:\Windows\System32\DriverStore\FileRepository\wiacn001.inf_amd64_neutral_b7a0b2f53d745b5a\CNHW900.DLL, 12-1046

 

 

 

 

I have attached the files in the password protected .zip like asked, i hope i have done this correctly, i think that the 2 CNH900.DLL files may be the same however there are to file directories for both so i included both files

 

All files are in a seperate folder in the zip file

 

System32 = C:\Windows\System32\DriverStore\FileRepository\wiacn001.inf_amd64_neutral_b7a0b2f53d745b5a\CNHW900.DLL

 

Winsxs = C:\Windows\winsxs\amd64_wiacn001.inf_31bf3856ad364e35_6.1.7600.16385_none_95eb24d2d4a0a55b\CNHW900.DL

 

ZoneAlarm = C:\Program Files (x86)\Zone Labs\ZoneAlarm\cam.zap

 

 

I hope this is all ok

 

Rob

FPs.zip

Link to comment
Share on other sites

Link to comment
Share on other sites

Here is the log scan again:

 

 

 

 

IObit Security 360

 

OS:Windows 7

Version:1.4.0.11

Define Version:1321

Time Elapsed:00:27:38

Objects Scanned:131037

Threats Found:3

 

|Name|Type|Description|ID|

Trojan.Agent, File, C:\Program Files (x86)\Zone Labs\ZoneAlarm\cam.zap, 12-1046

Trojan.Agent, File, C:\Windows\winsxs\amd64_wiacn001.inf_31bf3856ad364e35_6.1.7600.16385_none_95eb24d2d4a0a55b\CNHW900.DLL, 12-1046

Trojan.Agent, File, C:\Windows\System32\DriverStore\FileRepository\wiacn001.inf_amd64_neutral_b7a0b2f53d745b5a\CNHW900.DLL, 12-1046

 

 

 

 

I have attached the files in the password protected .zip like asked, i hope i have done this correctly, i think that the 2 CNH900.DLL files may be the same however there are to file directories for both so i included both files

 

All files are in a seperate folder in the zip file

 

System32 = C:\Windows\System32\DriverStore\FileRepository\wiacn001.inf_amd64_neutral_b7a0b2f53d745b5a\CNHW900.DLL

 

Winsxs = C:\Windows\winsxs\amd64_wiacn001.inf_31bf3856ad364e35_6.1.7600.16385_none_95eb24d2d4a0a55b\CNHW900.DL

 

ZoneAlarm = C:\Program Files (x86)\Zone Labs\ZoneAlarm\cam.zap

 

 

I hope this is all ok

 

Rob

 

Hi burrellbuzzman

After investigation, we have assured that it's a false positive. Sorry for the trouble we have caused to you.

 

We will solve this issue in our later update definition 1322.

 

Thanks for your support.

Link to comment
Share on other sites

Archived

This topic is now archived and is closed to further replies.

×
×
  • Create New...