Help!

McAfee is moving program's exe into Quarantine folder

 
  

Post new topic   General Reply to Topic (not reply to a specific post)    Forums Home -> McAfee RSS
Next:  McAfee VirusScan 10: How to exclude entire folder..  
Author Message
its_faiz
External


Since: Apr 13, 2007
Posts: 2



PostPosted: Fri Apr 13, 2007 12:17 am    Post subject: McAfee is moving program's exe into Quarantine folder
Archived from groups: alt>comp>virus, others (more info?)

Hi All,

We have a program developed in VB6 and installed on hundreds of users
scattered around the world. This program is automatically run by an NT
service once a day. It's been running fine for the last 4-5 years.

Please note that all the users have exactly the same operating
environment, i.e. McAfee virus scan 8.0, OS is Windows XP SP2 and MS
office 2003 SP1.

Now SOME of the users have experienced a problem. The McAfee Virus
scan is moving the program's exe into C:\Quarantine folder and
renaming it to *.vir

Can you please advise why this problem is caused?

Regards,

FK
Back to top
its_faiz
External


Since: Apr 13, 2007
Posts: 2



PostPosted: Fri Apr 13, 2007 5:23 am    Post subject: Re: McAfee is moving program's exe into Quarantine folder [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

On Apr 13, 1:12 pm, "Marcin Domaslawski" <mila....TakeThisOut@wp.pl> wrote:
> Hi,
>
> McAfeedetected an malware code inside your file. Question is if on every
> system file is detected or only on some.
> First case is caused by similiar malware signature inMcAfee'sdatabase -
> you can contact withMcAfeeand register a false positive
> 2nd case: can be caused by incorrect work of antivirus e.g. by damaged virus
> signatures database. I met with that situation with Kaspersky AV. Try
> re-download all database.
>
> Marcin Domaslawski
>
> Uzytkownik <its_f....TakeThisOut@hotmail.com> napisal w wiadomoscinews:1176448629.245440.276850@e65g2000hsc.googlegroups.com...
>
>
>
> > Hi All,
>
> > We have aprogramdeveloped in VB6 and installed on hundreds of users
> > scattered around the world. Thisprogramis automatically run by an NT
> > service once a day. It's been running fine for the last 4-5 years.
>
> > Please note that all the users have exactly the same operating
> > environment, i.e.McAfeevirus scan 8.0, OS is Windows XP SP2 and MS
> > office 2003 SP1.
>
> > Now SOME of the users have experienced a problem. TheMcAfeeVirus
> > scan ismovingtheprogram'sexeintoC:\Quarantinefolderand
> > renaming it to *.vir
>
> > Can you please advise why this problem is caused?
>
> > Regards,
>
> > FK- Hide quoted text -
>
> - Show quoted text -

I have just come to know that the executable is being detected as
malware just because it is using "RegCreateKeyEx" API to add a value
under "RunOnce" registry key.

Can you please tell a solution to this? I need to enter an entry under
"RunOnce" key.

Regards,

FK
Back to top
Marcin Domaslawski
External


Since: Apr 13, 2007
Posts: 1



PostPosted: Fri Apr 13, 2007 10:12 am    Post subject: Re: McAfee is moving program's exe into Quarantine folder [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

Hi,

McAfee detected an malware code inside your file. Question is if on every
system file is detected or only on some.
First case is caused by similiar malware signature in McAfee's database -
you can contact with McAfee and register a false positive
2nd case: can be caused by incorrect work of antivirus e.g. by damaged virus
signatures database. I met with that situation with Kaspersky AV. Try
re-download all database.

Marcin Domaslawski


Uzytkownik <its_faiz.DeleteThis@hotmail.com> napisal w wiadomosci
news:1176448629.245440.276850@e65g2000hsc.googlegroups.com...
> Hi All,
>
> We have a program developed in VB6 and installed on hundreds of users
> scattered around the world. This program is automatically run by an NT
> service once a day. It's been running fine for the last 4-5 years.
>
> Please note that all the users have exactly the same operating
> environment, i.e. McAfee virus scan 8.0, OS is Windows XP SP2 and MS
> office 2003 SP1.
>
> Now SOME of the users have experienced a problem. The McAfee Virus
> scan is moving the program's exe into C:\Quarantine folder and
> renaming it to *.vir
>
> Can you please advise why this problem is caused?
>
> Regards,
>
> FK
>
Back to top
David H. Lipman
External


Since: Jul 04, 2003
Posts: 2116



PostPosted: Fri Apr 13, 2007 10:54 am    Post subject: Re: McAfee is moving program's exe into Quarantine folder [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

From: <its_faiz RemoveThis @hotmail.com>

| Hi All,

| We have a program developed in VB6 and installed on hundreds of users
| scattered around the world. This program is automatically run by an NT
| service once a day. It's been running fine for the last 4-5 years.

| Please note that all the users have exactly the same operating
| environment, i.e. McAfee virus scan 8.0, OS is Windows XP SP2 and MS
| office 2003 SP1.

| Now SOME of the users have experienced a problem. The McAfee Virus
| scan is moving the program's exe into C:\Quarantine folder and
| renaming it to *.vir

| Can you please advise why this problem is caused?

| Regards,

| FK



Assuming your author created a good ptrogram and not malware, submit the files being
falsely detected to McAfee via the email addtress virus_research RemoveThis @avertlabs.com and in the
subject of the email use "False Positive on VB6 software" and in the body of the email
state your case why you believe the attached files are not malware.

Attach all the files deemed malware (and you haven't posted what they were declared as) in
password protected ZIP file with the password being; infected { password = infected }



--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm
Back to top
Zephyr
External


Since: Apr 13, 2007
Posts: 1



PostPosted: Fri Apr 13, 2007 6:30 pm    Post subject: Re: McAfee is moving program's exe into Quarantine folder [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

Hello,

Assuming the program is not malware I would not attempt to make any changes
to it.

Instead, follow David's advice and contact McAfee. If the program is not
malware they should be willing to update their definitions so the program is
no longer being flagged as malware.

--
Zephyr


<its_faiz RemoveThis @hotmail.com> wrote in message
news:1176467034.276901.42840@n59g2000hsh.googlegroups.com...
> On Apr 13, 1:12 pm, "Marcin Domaslawski" <mila... RemoveThis @wp.pl> wrote:
>> Hi,
>>
>> McAfeedetected an malware code inside your file. Question is if on every
>> system file is detected or only on some.
>> First case is caused by similiar malware signature inMcAfee'sdatabase -
>> you can contact withMcAfeeand register a false positive
>> 2nd case: can be caused by incorrect work of antivirus e.g. by damaged
>> virus
>> signatures database. I met with that situation with Kaspersky AV. Try
>> re-download all database.
>>
>> Marcin Domaslawski
>>
>> Uzytkownik <its_f... RemoveThis @hotmail.com> napisal w
>> wiadomoscinews:1176448629.245440.276850@e65g2000hsc.googlegroups.com...
>>
>>
>>
>> > Hi All,
>>
>> > We have aprogramdeveloped in VB6 and installed on hundreds of users
>> > scattered around the world. Thisprogramis automatically run by an NT
>> > service once a day. It's been running fine for the last 4-5 years.
>>
>> > Please note that all the users have exactly the same operating
>> > environment, i.e.McAfeevirus scan 8.0, OS is Windows XP SP2 and MS
>> > office 2003 SP1.
>>
>> > Now SOME of the users have experienced a problem. TheMcAfeeVirus
>> > scan ismovingtheprogram'sexeintoC:\Quarantinefolderand
>> > renaming it to *.vir
>>
>> > Can you please advise why this problem is caused?
>>
>> > Regards,
>>
>> > FK- Hide quoted text -
>>
>> - Show quoted text -
>
> I have just come to know that the executable is being detected as
> malware just because it is using "RegCreateKeyEx" API to add a value
> under "RunOnce" registry key.
>
> Can you please tell a solution to this? I need to enter an entry under
> "RunOnce" key.
>
> Regards,
>
> FK
>
Back to top
David H. Lipman
External


Since: Jul 04, 2003
Posts: 2116



PostPosted: Fri Apr 13, 2007 9:27 pm    Post subject: Re: McAfee is moving program's exe into Quarantine folder [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

From: "Zephyr" <usenet.DeleteThis@zeppyster.com>

| Hello,
|
| Assuming the program is not malware I would not attempt to make any changes
| to it.
|
| Instead, follow David's advice and contact McAfee. If the program is not
| malware they should be willing to update their definitions so the program is
| no longer being flagged as malware.
|

Correct. They can create a negative Extra DAT that will disable the false declaration as
well subsequently update the next DAT revision to correct the mistaken identification.

--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm
Back to top
mybest
External


Since: Apr 14, 2007
Posts: 1



PostPosted: Sat Apr 14, 2007 8:19 pm    Post subject: Re: McAfee is moving program's exe into Quarantine folder [Login to view extended thread Info.]
Archived from groups: alt>belgique>securite>virus, others (more info?)

It is my best shot.
inf0 RemoveThis @sofutoinc.com

<its_faiz RemoveThis @hotmail.com> wrote in message
news:1176448629.245440.276850@e65g2000hsc.googlegroups.com...
> Hi All,
>
> We have a program developed in VB6 and installed on hundreds of users
> scattered around the world. This program is automatically run by an NT
> service once a day. It's been running fine for the last 4-5 years.
>
> Please note that all the users have exactly the same operating
> environment, i.e. McAfee virus scan 8.0, OS is Windows XP SP2 and MS
> office 2003 SP1.
>
> Now SOME of the users have experienced a problem. The McAfee Virus
> scan is moving the program's exe into C:\Quarantine folder and
> renaming it to *.vir
>
> Can you please advise why this problem is caused?
>
> Regards,
>
> FK
>
Back to top
Segolene
External


Since: Apr 25, 2007
Posts: 1



PostPosted: Wed Apr 25, 2007 2:11 am    Post subject: Re: McAfee is moving program's exe into Quarantine folder [Login to view extended thread Info.]
Archived from groups: alt>comp>anti-virus, others (more info?)

I think Soooo
"Zephyr" <usenet.RemoveThis@zeppyster.com> wrote in message
news:gaednaueqNzvLYLbRVnyugA@giganews.com...
> Hello,
>
> Assuming the program is not malware I would not attempt to make any
> changes to it.
>
> Instead, follow David's advice and contact McAfee. If the program is not
> malware they should be willing to update their definitions so the program
> is
> no longer being flagged as malware.
>
> --
> Zephyr
>
>
> <its_faiz.RemoveThis@hotmail.com> wrote in message
> news:1176467034.276901.42840@n59g2000hsh.googlegroups.com...
>> On Apr 13, 1:12 pm, "Marcin Domaslawski" <mila....RemoveThis@wp.pl> wrote:
>>> Hi,
>>>
>>> McAfeedetected an malware code inside your file. Question is if on every
>>> system file is detected or only on some.
>>> First case is caused by similiar malware signature inMcAfee'sdatabase -
>>> you can contact withMcAfeeand register a false positive
>>> 2nd case: can be caused by incorrect work of antivirus e.g. by damaged
>>> virus
>>> signatures database. I met with that situation with Kaspersky AV. Try
>>> re-download all database.
>>>
>>> Marcin Domaslawski
>>>
>>> Uzytkownik <its_f....RemoveThis@hotmail.com> napisal w
>>> wiadomoscinews:1176448629.245440.276850@e65g2000hsc.googlegroups.com...
>>>
>>>
>>>
>>> > Hi All,
>>>
>>> > We have aprogramdeveloped in VB6 and installed on hundreds of users
>>> > scattered around the world. Thisprogramis automatically run by an NT
>>> > service once a day. It's been running fine for the last 4-5 years.
>>>
>>> > Please note that all the users have exactly the same operating
>>> > environment, i.e.McAfeevirus scan 8.0, OS is Windows XP SP2 and MS
>>> > office 2003 SP1.
>>>
>>> > Now SOME of the users have experienced a problem. TheMcAfeeVirus
>>> > scan ismovingtheprogram'sexeintoC:\Quarantinefolderand
>>> > renaming it to *.vir
>>>
>>> > Can you please advise why this problem is caused?
>>>
>>> > Regards,
>>>
>>> > FK- Hide quoted text -
>>>
>>> - Show quoted text -
>>
>> I have just come to know that the executable is being detected as
>> malware just because it is using "RegCreateKeyEx" API to add a value
>> under "RunOnce" registry key.
>>
>> Can you please tell a solution to this? I need to enter an entry under
>> "RunOnce" key.
>>
>> Regards,
>>
>> FK
>>
>
>
>
Back to top
Display posts from previous:   
Post new topic   General Reply to Topic (not reply to a specific post)    Forums Home -> McAfee All times are: Eastern Time (US & Canada) (change)
Page 1 of 1

 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum