Member Panel


Sponsors and Ads

Join the Team

Live Tag Cloud

PC Forum PC Help Forum » Security & Safety » Security Watch » [false positive] Virus Found In HijackThis !

Security Watch - [false positive] Virus Found In HijackThis ! posted in the Security & Safety forums; Greetings. My AV (McAfee) just found a virus located in 'HijackThis.exe' located under the 'Program Files' folder.? The virus's name is 'W32/Generic.worm!p2p.'? Checked with McAfee and it iwas added on ...

JOIN US NOW to remove these Ads

Post New Thread  Reply
  #1  
Old 08-18-2005
Bronze Member
 
Join Date: Jun 2005
Location: Sunny Southern California
Posts: 25
Rod-O-Matic - See this Members User comments on their Profile page
Default [false positive] Virus Found In HijackThis !

Greetings.

My AV (McAfee) just found a virus located in 'HijackThis.exe' located under the 'Program Files' folder.? The virus's name is 'W32/Generic.worm!p2p.'? Checked with McAfee and it iwas added on 5/30/2003 (a p2pWorm).? To clean it McAfee removed the offending executable file.? I then went to my backup copy of the downloaded Zip file.? I unzipped it and before I could move it to the 'Program Files' location McAfee discovered it again and cleaned/removed it, leaving the original zip file.

I then went to the 'Merijn' web site and downloade 3 copies of 'HijackThis.zip', one from each download site.? I then unzipped all 4 (my original being #4) in seperate folders.? Ran McAfee on all 4 executables and no virus was found.

I seldom get a virus, (must be the clean living), so I have very little experience dealing with them and very little understanding of how this one functions.

With that said, I have a question for anyone who might have an answer.

Is this a normal situation, that is to say; a virus was found in the 'HijackThis.exe' file and was cleaned/removed by an AV program.? The zip file, containing only the 'exe', also had the virus inside (?) it.? When unzipped a second time the virus was not there.? Is this a common occurance/situation ?

You opinion is wanted.

Thanks Guys

Rod-O-Matic



__________________
If you are to open minded, your brains will fall out.<br />Anonymous
  #2  
Old 08-18-2005
merlin's Avatar
Trusted Security Analyst
My PC
 
Join Date: Jul 2005
Location: Wisconsin
Posts: 2,622
PC Experience: Computers Fear Me
merlin - See this Members User comments on their Profile page merlin - See this Members User comments on their Profile page
Send a message via Yahoo to merlin
Default Re: Virus Found In HijackThis !

No its a false positive with the new hijack this


McAfee is at is again, unfortunately. Yes, I am aware of the fact that McAfee detects HijackThis 1.99.1 as a generic worm. For the fourth time. Yes, I am aware of the fact that McAfee detects the StartupList standalone as an mhtml exploit webpage. This makes respectively the fifth and sixth time McAfee has mistakenly detected one of my programs as some brand of virus. And I'm getting pretty tired of this. Am I supposed to email each and every new version of a program I publish to McAfee so they can verify that UPX compression does not automatically equal a scary virus??


__________________
QuickTime Alternative..Hijackthis..SpeedFan..ATI Tool..Whats Running..Everest..Absolute Control..All Drivers
If you feel we saved you some money please help support this site by DONATING as this site is funded by great people like you

OUT FOR LUNCH


  #3  
Old 08-18-2005
joe5's Avatar
Elite Member
My PC
 
Join Date: Jun 2005
Location: Netherlands
Posts: 9,044
joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page joe5 - See this Members User comments on their Profile page
Default Re: [false positive] Virus Found In HijackThis !



I have made this a sticky and edited youre title Rod-O-Matic , hope you don't mind. :-)


__________________
- PCHF Team. - (NL) - Mal-ware Eradicator! -

  #4  
Old 08-23-2005
Bronze Member
 
Join Date: Jun 2005
Location: Sunny Southern California
Posts: 25
Rod-O-Matic - See this Members User comments on their Profile page
Default Re: [false positive] Virus Found In HijackThis !

Merlin.?
Cool new avatar!

This is where I apologise for rushing to conclusions and posting a question that had already been answered.? I know that the 'Quote' you quoted is from the 'Merijn' web site.? I did read that one but failed to read farther down where he referred to the same worm by name.? ?:oops ?:banghead:

Feb. 16,2005 [Update 1] It seems McAfee is detecting the new HijackThis version as W32/Generic.worm!p2p. It is not the first time this happened and probably not the last time either. There is no virus in HijackThis. McAfee incorrectly detects the PE compression method I use on all of my programs as a generic Kazaa worm. I will try to contact McAfee about this and see if the incorrect detection can be removed in their next update.
[Update 2] Success! McAfee has put out new definitions that no longer detect HijackThis 1.99.1 as a virus. ^_^
I just purchased McAfee VirusScan 9 2005 (for free, with rebates) and the 'detected virus' was after installation of the new version.? I guess VirusScan had to choke on it once.

Sorry

Rod-O-Matic


p.s.
Love the addition of the 'spell checker', I know I need it...thanks


__________________
If you are to open minded, your brains will fall out.<br />Anonymous
  #5  
Old 08-23-2005
Bronze Member
 
Join Date: Jun 2005
Location: Sunny Southern California
Posts: 25
Rod-O-Matic - See this Members User comments on their Profile page
Default Re: [false positive] Virus Found In HijackThis !

Joe5.

I do not mind at all.? If other people read this and do not make the same mistake that I did (see previous posts) then all is well.? HijackThis is a great program and does not need to be maligned by me or anyone else.

McAfee should be embarrassed and sent to the corner for a 'time out' or until the light comes on? ::idea::.? ?I doubt either will happen!

I might write to them just to see what they have to say.

Later
Rod-O-Matic


__________________
If you are to open minded, your brains will fall out.<br />Anonymous
  #6  
Old 08-23-2005
Hengis's Avatar
PCHF Founder & Owner
My PC
 
Join Date: Jan 2004
Location: Berkshire, England
Posts: 11,114
PC Experience: Always learning
Hengis - See this Members User comments on their Profile page Hengis - See this Members User comments on their Profile page Hengis - See this Members User comments on their Profile page Hengis - See this Members User comments on their Profile page Hengis - See this Members User comments on their Profile page Hengis - See this Members User comments on their Profile page Hengis - See this Members User comments on their Profile page Hengis - See this Members User comments on their Profile page Hengis - See this Members User comments on their Profile page Hengis - See this Members User comments on their Profile page Hengis - See this Members User comments on their Profile page
Send a message via Skype™ to Hengis
Default Re: [false positive] Virus Found In HijackThis !

Humility is a very honorable quality Rod & I agree about McAfee

Thanks for your comments.


__________________
> Pre-Work > System File Checker
> Did we help you? If we did, please consider A Donation

Reply
Satellite TV on your PC - over 3000 Channels! Click Here!

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On


All times are GMT +1. The time now is 01:58 PM.
Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC7
All Graphics & Content Copyright © 2004-2008 - PC Help Forum.com


Back to Top
MPAA
Funny session with MPAA at the 2006 SXSW show.

Credit Cards
Credit card information and debt advice from Money Expert.

Adverse Credit Remortgage
Adverse credit remortgage information from the experts at Ocean.