To register for an Internet.com membership to receive newsletters and white papers, use the Register button ABOVE.
To participate in the message forums BELOW, click here


Virtual DR   Earthweb  
Events Premium Services Media Kit E-mail Offers Whitepapers Vendor Showcases

Go Back   Virtual Dr Forums-Computer Tech Support > Center For Disease Control > Viruses/Trojans/Spyware

Viruses/Trojans/Spyware Discussion and Technical Support for Anti-virus software, firewalls, Privacy issues, etc.

Reply
 
Thread Tools Search this Thread Display Modes
  #1  
Old August 22nd, 2008, 11:51 AM
Syzich Syzich is offline
Virtual Resident
 
Join Date: Apr 2004
Posts: 674
AVG detected knlwrap.exe as infected

I ran a scan with AVG a little while ago and saw in the results that knlwrap.exe was infected. I decided to check my dad's computer to see if he also has this file on his computer. He does and as soon as I hovered the mouse pointer over it, his AVG flagged the file as well. Since the original file on my computer had already been deleted, I checked the creation date on his. It looks like it was created a few days after he installed Windows. I saw that it is related to the InstallShield(which makes sense, considering the folder it is/was in). Others also mention it after installing Roxio 5. I have Roxio 5 on my computer now and my dad had it on his at one point. So this leads me to think its a false positive since its just now flagging the file on my computer as well as his. I uploaded the file to Jotti. Here are the results:

AntiVir Found nothing
ArcaVir Found nothing
Avast Found nothing
AVG Antivirus Found Dropper.Agent.JOC
BitDefender Found nothing
ClamAV Found nothing
CPsecure Found nothing
Dr.Web Found nothing
F-Prot Antivirus Found nothing
F-Secure Anti-Virus Found nothing
Fortinet Found nothing
Ikarus Found nothing
Kaspersky Anti-Virus Found nothing
NOD32 Found nothing
Norman Virus Control Found nothing
Panda Antivirus Found nothing
Sophos Antivirus Found nothing
VirusBuster Found nothing
VBA32 Found nothing

MD5: 48befc3e2b36de65a415977b1288c0d7

AVG is the only scanner to flag this file, so I'm fairly sure it is a false positive. Though, some searches online do say that there is malware out there with the same filename. So to be sure, I want to send the file to AVG to analyze. Fink, I hope you see this thread. A short time ago, I had another false positive and you offered to password the .zip for me. Would you mind doing it again? I attached the .zip to my post.

FYI, the file location is: C:\Program Files\Common Files\Install Shield\engine\6\Intel32
Attached Files
File Type: zip knlwrap.zip (43.7 KB, 6 views)

Last edited by Syzich; August 22nd, 2008 at 12:35 PM.
Reply With Quote
  #2  
Old August 22nd, 2008, 01:35 PM
fink's Avatar
fink fink is online now
Site Moderator
 
Join Date: Jul 1998
Location: Toronto
Posts: 16,241
http://www.virustotal.com/analisis/c...3f4824fbcd3e1a

virustotal (similar to jotti) shows no hits at all incl AVG.

here's the zip.. password is password.

Wait until after the next time AVG updates to see if it's still flagged. 99.999% it's a false positive.
Attached Files
File Type: zip knlwrap.zip (44.4 KB, 14 views)
__________________
For future reference please let us know if your problem was solved.


_____________________
animal lovers click here
and here
Reply With Quote
  #3  
Old August 23rd, 2008, 09:44 AM
Syzich Syzich is offline
Virtual Resident
 
Join Date: Apr 2004
Posts: 674
It looks like Virustotal updated the definitions for the scanners they use. I went there again today and AVG is now flagging knlwrap.exe. I guess that might also explain the dates in your link and when I went there yesterday. Here are the results of the virustotal scan after going there a few minutes ago:

http://www.virustotal.com/analisis/1...8f6fb44fa09ecc

Here are the Jotti results:

AntiVir Found nothing
ArcaVir Found nothing
Avast Found nothing
AVG Antivirus Found Dropper.Agent.JOC
BitDefender Found nothing
ClamAV Found nothing
CPsecure Found nothing
Dr.Web Found nothing
F-Prot Antivirus Found nothing
F-Secure Anti-Virus Found nothing
Fortinet Found nothing
Ikarus Found nothing
Kaspersky Anti-Virus Found nothing
NOD32 Found nothing
Norman Virus Control Found nothing
Panda Antivirus Found nothing
Sophos Antivirus Found nothing
VirusBuster Found nothing
VBA32 Found nothing


Thanks for passwording the .zip for me, fink. I'm going to send it to AVG now. Hopefully I get a quick reply like I did last time.
Reply With Quote
  #4  
Old August 23rd, 2008, 09:57 AM
fink's Avatar
fink fink is online now
Site Moderator
 
Join Date: Jul 1998
Location: Toronto
Posts: 16,241
Judging from the nearly (3000) 4000 hits this thread has got since yesterday you aren't the only one looking for an explanation. I'm guessing that AVG is getting a lot of inquiries about this.

Worth mentioning is another thing that points to this being a false positive is the location of the file. If it were a virus it would be in the Windows or Windows\system 32 folder.
__________________
For future reference please let us know if your problem was solved.


_____________________
animal lovers click here
and here
Reply With Quote
  #5  
Old August 24th, 2008, 01:23 AM
Broni's Avatar
Broni Broni is offline
Malware Annihilator
 
Join Date: Dec 2007
Location: Daly City, CA
Posts: 11,907
Quote:
Judging from the nearly (3000) 4000 hits this thread has got since yesterday
What kind of tool do you use to see it?
__________________


My Home Page
Reply With Quote
  #6  
Old August 24th, 2008, 04:22 AM
SpywareDr's Avatar
SpywareDr SpywareDr is offline
VirtualDr PC Specialist
 
Join Date: Apr 2005
Location: Basking in the warm glow of a computer monitor somewhere
Posts: 10,398
Quote:
Originally Posted by Broni
What kind of tool do you use to see it?
Go into the "Viruses/Trojans/Spyware" forum:
http://discussions.virtualdr.com/forumdisplay.php?f=40
and note the "Views" column:
__________________
Doc


Secunia Software Inspector - Scan your system online for insecure software and missing updates

____________http://www.microsoft.com/security____________
\____________________ ____.-.____ ____________________/
\_____________\ -._)!(_.- /_____________/
\_______\. ~\ /~ ./_______/
\_______/
Reply With Quote
  #7  
Old August 24th, 2008, 08:23 AM
Syzich Syzich is offline
Virtual Resident
 
Join Date: Apr 2004
Posts: 674
I just updated AVG and restored knlwrap.exe and then scanned it, AVG is no longer flagging it.

Here are today's Jotti results:

A-Squared Found nothing
AntiVir Found nothing
ArcaVir Found nothing
Avast Found nothing
AVG Antivirus Found nothing
BitDefender Found nothing
ClamAV Found nothing
CPsecure Found nothing
Dr.Web Found nothing
F-Prot Antivirus Found nothing
F-Secure Anti-Virus Found nothing
Fortinet Found nothing
Ikarus Found nothing
Kaspersky Anti-Virus Found nothing
NOD32 Found nothing
Norman Virus Control Found nothing
Panda Antivirus Found nothing
Sophos Antivirus Found nothing
VirusBuster Found nothing
VBA32 Found nothing


I also got an email reply from AVG confirming the false positive.
Reply With Quote
  #8  
Old August 24th, 2008, 12:05 PM
Broni's Avatar
Broni Broni is offline
Malware Annihilator
 
Join Date: Dec 2007
Location: Daly City, CA
Posts: 11,907
Quote:
Go into the "Viruses/Trojans/Spyware" forum:

http://discussions.virtualdr.com/forumdisplay.php?f=40

and note the "Views" column:
Forgive me, but I had to work yesterday, and apparently, I was tired....hehehe.
__________________


My Home Page
Reply With Quote
  #9  
Old August 25th, 2008, 05:37 AM
SpywareDr's Avatar
SpywareDr SpywareDr is offline
VirtualDr PC Specialist
 
Join Date: Apr 2005
Location: Basking in the warm glow of a computer monitor somewhere
Posts: 10,398
Understandable. (Been there, done that).
__________________
Doc


Secunia Software Inspector - Scan your system online for insecure software and missing updates

____________http://www.microsoft.com/security____________
\____________________ ____.-.____ ____________________/
\_____________\ -._)!(_.- /_____________/
\_______\. ~\ /~ ./_______/
\_______/
Reply With Quote
Reply

Bookmarks
Go Back   Virtual Dr Forums-Computer Tech Support > Center For Disease Control > Viruses/Trojans/Spyware



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 08:27 AM.









Acceptable Use Policy


The Network for Technology Professionals

Search:

About Internet.com

Legal Notices, Licensing, Permissions, Privacy Policy.
Advertise | Newsletters | E-mail Offers

Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.