Outpost Users Support Forum  
Outpost User Operated Support Forum
Agnitum Outpost Pro Release (OP, OSS, AV): 2009 (6.7.3.3058) [08-FEB-2010]
www.agnitum.com

Go Back   Outpost Users Support Forum > Agnitum Outpost Security Suite / Outpost Firewall/Outpost Antivirus > Outpost Plug-In Discussions > General Plug-In Discussions

Reply
 
Thread Tools
  #1  
Old 05-13-2006, 12:03 AM
creeping.death creeping.death is offline
Junior Member
 
Join Date: Feb 2005
Location: Germany
Posts: 24
Anti-Spyware: false positive

Running the On-Demand-Spyware-Scanner on my WindowsXP Pro install leads to the following result:

WinAntivirus (Rogue Anti-Spyware product)

Two Registy keys are affected:
HKLM\software\classes\Component Categories\{56FFCC30-D398-11d0-B2AE-00A0C908FA49}\409

and

HKLM\software\classes\Component Categories\{56FFCC30-D398-11d0-B2AE-00A0C908FA49}

But these entries are necessary for the Microsoft Antivirus API?!

(And I have never installed WinAntiVirus oder visited their site).
Reply With Quote
  #2  
Old 05-13-2006, 01:12 AM
Paranoid2000's Avatar
Paranoid2000 Paranoid2000 is offline
Super Moderator
 
Join Date: Feb 2003
Location: North West, United Kingdom
Posts: 10,266
Re: Anti-Spyware: false positive

Welcome to the forums Creeping.death,

Please review the Outpost 3.0 - What to expect: Anti-Spyware FAQ for details on reporting false positives.
Reply With Quote
  #3  
Old 05-13-2006, 08:32 PM
creeping.death creeping.death is offline
Junior Member
 
Join Date: Feb 2005
Location: Germany
Posts: 24
Re: Anti-Spyware: false positive

The FAQ sais:
Quote:
I have encountered a false positive/suspicious file. How do I report it?
False positives (where the plugin is reporting an innocent file as malicious) and suspicious files not detected by the plugin should be sent to the Suspicious Files page.
But what file am I to send to the Suspicious Files page? An ISO image of my Windows partition?
As I said, there are only two registry keys and they belong to a Microsoft API.
Reply With Quote
  #4  
Old 05-13-2006, 10:51 PM
Minceypw Minceypw is offline
Member
 
Join Date: Sep 2004
Posts: 30
Re: Anti-Spyware: false positive

Quote:
Originally Posted by creeping.death
The FAQ sais:

But what file am I to send to the Suspicious Files page? An ISO image of my Windows partition?
As I said, there are only two registry keys and they belong to a Microsoft API.
I asked a similar question under this thread:
http://www.outpostfirewall.com/forum...ad.php?t=17255

Check Firepost's response under the 12th post

Hope that helps.
Reply With Quote
  #5  
Old 05-14-2006, 10:16 AM
FirePost FirePost is offline
Moderator
 
Join Date: May 2005
Posts: 2,568
Re: Anti-Spyware: false positive

For this particular detection my personal opinion was:
Quote:
Originally Posted by FirePost
I believe this is a false positive. Many AV will will register as an attachment scanner for "office antivirus"....
The entire reply was in the thread "help please."
Reply With Quote
  #6  
Old 05-15-2006, 03:32 AM
creeping.death creeping.death is offline
Junior Member
 
Join Date: Feb 2005
Location: Germany
Posts: 24
Re: Anti-Spyware: false positive

Thanks, Minceypw + FirePost.
Reply With Quote
  #7  
Old 09-10-2006, 10:12 AM
justme2 justme2 is offline
Member
 
Join Date: Aug 2004
Posts: 82
Re: Anti-Spyware: false positive

FALSE POSITIVE CONFIRMED:

TGUID 56FFCC30-D398-11d0-B2AE-00A0C908FA49
key409, data "officeantivirus"
--is mistaken for malware: "WinAntiVirus"
______________

ANOTHER FALSE POSITIVE:

Reports Nissan DataScan as: "win key genie"
(just because it uses the same uninstaller)
ST6UNST #1
______________

--THIS DETECTION METHOD IS SUPER-LAME!
SUGGEST AGNITUM TAKE A LICENSE FROM LAVASOFT SO'S OUTPOST CAN SCAN FOR MALWARE CORRECTLY!
Reply With Quote
  #8  
Old 09-10-2006, 01:52 PM
FirePost FirePost is offline
Moderator
 
Join Date: May 2005
Posts: 2,568
Re: Anti-Spyware: false positive

Quote:
Originally Posted by justme2
ANOTHER FALSE POSITIVE:

Reports Nissan DataScan as: "win key genie"
(just because it uses the same uninstaller)
ST6UNST #1
False detection for ST5UNST's as well. One should always double check any detections. I would not let ANY program automatically remove things.
My idea of Anti-Spyware protection does not include disabling the AV.
Reply With Quote
  #9  
Old 09-10-2006, 06:59 PM
Paranoid2000's Avatar
Paranoid2000 Paranoid2000 is offline
Super Moderator
 
Join Date: Feb 2003
Location: North West, United Kingdom
Posts: 10,266
Re: Anti-Spyware: false positive

Quote:
Originally Posted by FirePost View Post
False detection for ST5UNST's as well. One should always double check any detections.
I've encountered (and reported, again, to Agnitum) the ST5UNST false positive.
Reply With Quote
  #10  
Old 09-11-2006, 08:00 AM
FirePost FirePost is offline
Moderator
 
Join Date: May 2005
Posts: 2,568
Re: Anti-Spyware: false positive

Quote:
Originally Posted by Paranoid2000 View Post
I've encountered (and reported, again, to Agnitum) the ST5UNST false positive.
I reported it once and finally disabled the detection. When one key is returned as more than one detection, one knows something is suspect.
Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Outpost 3.5 Anti spyware and Bitdefender9 peebee Outpost Firewall General Discussions, Support, and Troubleshooting 1 04-20-2006 07:06 AM
False positive OP spyware plugin ? Golden Eye ntgof General Plug-In Discussions 2 03-22-2006 08:53 AM
Outpost Anti Spyware Plugin nippauls General Plug-In Discussions 46 11-01-2005 03:23 PM
OP 3.0 AntiSpyware - False positive? SandmanUK Outpost Firewall General Discussions, Support, and Troubleshooting 3 10-06-2005 05:16 PM


All times are GMT -12. The time now is 02:04 AM.


Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.