False Positives? Ad-Aware SE
Results 1 to 7 of 7

Thread: False Positives? Ad-Aware SE

  1. #1
    Join Date
    Oct 1999
    Location
    Houston, TX
    Posts
    248

    False Positives? Ad-Aware SE

    I just updated Ad-Aware to the definitions on 9/12/06 and scanned two of my computers with updated Win XP Home (SP2 with all updates), updated etrust AV, and updated ZA firewall. It found on both computers multiple instances of Win32.trojan and Bargain Buddy. My computers are working fine, and etrust AV scans along with ewido and trend micro do not find anything. Are these false positives?

    Thanks

  2. #2
    Join Date
    Jun 2002
    Location
    Israel
    Posts
    5,132
    Not neccesarily. I may not remember correctly, but I think Bargain Buddy might be in the add/remove programs list. Have a look there. In any case, you can go ahead and remove them with Ad-Aware. If you want, you can also install Spybot S&D before you remove them with Ad-Aware and see if Spybot finds anything.

  3. #3
    HAN's Avatar
    HAN is offline Virtual PC Specialist!!!
    Join Date
    Feb 2002
    Location
    USA
    Posts
    4,319
    There is talk here and there about 2 false positives (the ones you mention) with the 9/12 definitions. I would sit tight for a bit, ignore these finds for the moment and let Lavasoft get this situation analyzed/corrected.

  4. #4
    Join Date
    Dec 2000
    Location
    Springfield, OR
    Posts
    2,950
    Here's more info on the latest update which I copied from another forum.
    "RE: Adaware Update SE1R123 13.09.2006"

    This fixes a False Positive in Adware.AdMedia.
    This fixes a False Positive in TrojanBackdoor.Serv-U.
    This fixes a False Positive in BargainBuddy.
    This fixes a False Positive in Win32.Trojan.Agent.
    This fixes a False Positive in Win32.Trojan.Downloader.

    The MD5 checksum for the defs.ref file is 536bea2c1749341b09b2589bf3cc0143

    Additional Information
    ============================================
    You can use Webupdate to install the new reference file, or download it manually from:
    http://download.lavasoft.de.edgesuit...ublic/defs.zip

    If you think something needs to be sent to us for review, visit our submission site at:
    http://www.lavasofthelp.net/submit/

    If you have any questions, please contact us at:
    http://www.lavasoftsupport.com

    Note: After you download this, close the program and reopen it and check the Internal Build number and it should be 150

    Tufenuf

  5. #5
    Join Date
    Oct 1999
    Location
    Houston, TX
    Posts
    248
    Voila! The updates for 9/15/06 did not reveal anything. Guess they were false positives. I deleted those files on my other computer b/c I initially thought they were evil. Hope I don't need them.

  6. #6
    Join Date
    Dec 2000
    Location
    Springfield, OR
    Posts
    2,950
    BigTimeNovice, As far as those items you deleted you may want to follow the thread at the link below. In the future you may want to leave the Ad-aware items found in quarantine for a week or two just in case something like this happens again.

    http://www.lavasoftsupport.com/index.php?showtopic=3367

    Tufenuf

  7. #7
    Join Date
    Jun 2001
    Location
    Albuquerque, NM USA
    Posts
    14,686
    The latest AdAware reference file is SE1R123 14.09.2006
    Internal build : 151
    There were two issued on Sept. 14. The first fixed the false positives mentioned above, but introduced a new false positive (DiaRemover). The second (Build 151) seems to have fixed all false positives.
    Jim
    WIN7 Ultimate SP1 64bit, IE 11, NTFS,
    cable, MS Security Essentials, Windows 7 firewall

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •