BleepingComputer.com: Mcafee reporting combofix as a trojan???

Jump to content

Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

Mcafee reporting combofix as a trojan??? help

#1 User is offline   idiot10j 

  • New Member
  • Pip
  • Find Topics
  • Group: Members
  • Posts: 4
  • Joined: 11-July 09

Posted 11 July 2009 - 09:24 PM

Over the 4th weekend, my computer got hit by a virus that really messed up my computer, removed all of the restore points, infected all files that prefetch called, and kept stating that google updater encountered a problem (before I could even login) after I created a fresh install of XP pro, (including installing mcafee which my ISP provides free) A friend of mine mentioned combofix to me, and I thought I'd check it out, but when downloading it, Mcafee blacklisted it mentioningthat it contains a trojan, Artemis!E8F11525BD9B, from all 3 of the download links that were on bleepingcomputer website. Has anyone else get a virus detected warning while downloading the software? I didn't find anything when searching for trojan detected on download of combofix on the site...


EDIT: Moved to a more appropriate forum

This post has been edited by garmanma: 11 July 2009 - 09:58 PM


#2 User is offline   garmanma 

  • Computer Masochist
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Staff Emeritus
  • Posts: 27,809
  • Joined: 27-January 07
  • Location:Cleveland, Ohio

Posted 11 July 2009 - 09:59 PM

It is a false positive
Please read thew disclaimer before running it yourself
Mark
Posted Image
why won't my laptop work?

Having grandkids is God's way of giving you a 2nd chance because you were too busy working your butt off the 1st time around
Do not send me PMs with problems that should be posted in the forums. Keep it in the forums, so everyone benefits
Become a BleepingComputer fan: Facebook and Twitter

#3 User is offline   idiot10j 

  • New Member
  • Pip
  • Find Topics
  • Group: Members
  • Posts: 4
  • Joined: 11-July 09

Posted 11 July 2009 - 10:19 PM

unfortunately, I cannot find this disclaimer that you are referring to, is it located within the program, instead of something that i could find easily?

#4 User is offline   garmanma 

  • Computer Masochist
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Staff Emeritus
  • Posts: 27,809
  • Joined: 27-January 07
  • Location:Cleveland, Ohio

Posted 12 July 2009 - 09:17 AM

Posted Image
Mark
Posted Image
why won't my laptop work?

Having grandkids is God's way of giving you a 2nd chance because you were too busy working your butt off the 1st time around
Do not send me PMs with problems that should be posted in the forums. Keep it in the forums, so everyone benefits
Become a BleepingComputer fan: Facebook and Twitter

#5 User is offline   idiot10j 

  • New Member
  • Pip
  • Find Topics
  • Group: Members
  • Posts: 4
  • Joined: 11-July 09

Posted 12 July 2009 - 07:50 PM

Thank you garmanma. I guess that since it couldn't even DOWNLOAD without coming up with a trojan alert, I will NOT be using it..

This will be the END of my participation on this forum.

idiot10j

#6 User is offline   Stang777 

  • Just Hoping To Help
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Members
  • Posts: 1,757
  • Joined: 30-December 08
  • Location:Utah

Posted 13 July 2009 - 05:28 PM

Even though you say you are done here I still want to point this out. If you would do a little research on these types of programs, you would find that the tools that they use are often detected as malicious by many antivirus programs but these are FALSE positives, as Garnmanma said. False positives means they are not trojans or anything else malicious. But in any case, you really should not use this particular tool without supervisiion from an expert in malware removal as the use of it on your own could lead to the computer becoming inoperable.

#7 User is offline   Stang777 

  • Just Hoping To Help
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Members
  • Posts: 1,757
  • Joined: 30-December 08
  • Location:Utah

Posted 13 July 2009 - 05:32 PM

Does anyone know what it means if an antivirus program does not detect ComboFix as anything bad when it is downloaded? As in, does that mean the antivirus program is not as good as others and did not detect something it should have, or does it mean that it that it is able to tell that it is not malicious?

This post has been edited by Stang777: 13 July 2009 - 05:32 PM


#8 User is offline   quietman7 

  • Bleepin' Janitor
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Global Moderator
  • Posts: 25,513
  • Joined: 09-July 05
  • Gender:Male
  • Location:Virginia, USA

Posted 15 July 2009 - 12:45 PM

Certain embedded files that are part of legitimate programs or specialized fix tools such as Combofix may at times be detected by some anti-virus and anti-malware scanners as a "Risk Tool", "Hacking Tool", "Potentially Unwanted Program", or even "Malware" (virus/trojan) when that is not the case. This occurs for a variety of reasons to include the tool's compiler, the files it uses, registry fixes and malware strings it contains.

Such programs have legitimate uses in contexts where a Malware Removal Expert asked you to use the tool or when an authorized user/administrator has knowingly installed it. When flagged by an anti-virus or security scanner, it's because the program includes features, behavior or files that appear suspicious or it can potentially be used for malicious purposes. These detections do not necessarily mean the file is malware or a bad program.

It means it has the potential for being misused by others or that it was simply detected as suspicious due to the security program's Heuristic analysis engine which provides the ability to detect possible new variants of malware. Anti-virus scanners cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert you or even automatically remove them. In these cases the detection is a "False Positive".

This post has been edited by quietman7: 15 July 2009 - 12:46 PM

Microsoft MVP - Consumer Security 2007-2012 Posted Image
Member of UNITE, Unified Network of Instructors and Trusted Eliminators

Share this topic:


Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users