PC Review


Reply
Thread Tools Rate Thread

Can a Defender scan trigger an AVG false positive?

 
 
=?Utf-8?B?QWxhbiBE?=
Guest
Posts: n/a
 
      5th Nov 2006
This is strange. This morning, Defender started its usual scan at 10.00.29
am, and stopped at 10.03.21. Moments later, my AVG Security suite's Resident
Shield leapt into action and declared it had found a virus - ciadoor.13 - in
mirc.exe (which is now held in the virus vault while I decide what to do).

This seems odd. I haven't actually used MIRC for over a year (indeed it
wasn't really worth installing it). During that time, mirc.exe has been
scanned hundreds of times by a whole range of scanners, both online and
on-board, and has come up clean.

So here are my questions:
1. The timing coincidence seems suspicious. Is there any way that the ending
of Defender's automatic scan could have triggered a false positive in the AVG
resident shield?
2. Just to be safe, I'd like to submit this mirc.exe file to one of those
multiple scan online tests, but I presume I need to I release it from the
virus vault in order to do so? Any advice would be appreciated.
 
Reply With Quote
 
 
 
 
Joe Faulhaber[MSFT]
Guest
Posts: n/a
 
      8th Nov 2006
Hi Alan,

My guess would be that the WinDefend scan touched the files, which AVG then
probably scanned on WD's open, which resulted in the detection. I've seen
this pretty frequently - an OnAccess scanner that doesn't know about an
OnDemand scanner can do such things.

WinDefend actually does a bunch of "consolidation" of repeated detections
that AV scanners tend to cause.

Regards,
Joe

"Alan D" <(E-Mail Removed)> wrote in message
news:358D535D-AF66-4364-8BC8-(E-Mail Removed)...
> This is strange. This morning, Defender started its usual scan at 10.00.29
> am, and stopped at 10.03.21. Moments later, my AVG Security suite's
> Resident
> Shield leapt into action and declared it had found a virus - ciadoor.13 -
> in
> mirc.exe (which is now held in the virus vault while I decide what to do).
>
> This seems odd. I haven't actually used MIRC for over a year (indeed it
> wasn't really worth installing it). During that time, mirc.exe has been
> scanned hundreds of times by a whole range of scanners, both online and
> on-board, and has come up clean.
>
> So here are my questions:
> 1. The timing coincidence seems suspicious. Is there any way that the
> ending
> of Defender's automatic scan could have triggered a false positive in the
> AVG
> resident shield?
> 2. Just to be safe, I'd like to submit this mirc.exe file to one of those
> multiple scan online tests, but I presume I need to I release it from the
> virus vault in order to do so? Any advice would be appreciated.


 
Reply With Quote
 
=?Utf-8?B?QWxhbiBE?=
Guest
Posts: n/a
 
      8th Nov 2006


"Joe Faulhaber[MSFT]" wrote:

> My guess would be that the WinDefend scan touched the files, which AVG then
> probably scanned on WD's open, which resulted in the detection. I've seen
> this pretty frequently - an OnAccess scanner that doesn't know about an
> OnDemand scanner can do such things.
>
> WinDefend actually does a bunch of "consolidation" of repeated detections
> that AV scanners tend to cause.


Thanks for this Joe. Actually the issue is resolved completely now, and the
full story can be read over in 'General', in the 'ciadoor.13' thread (useful
reading if you have difficulty sleeping I should think!)
 
Reply With Quote
 
 
 
Reply

Thread Tools
Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Windows Defender FALSE POSITIVE Panda_man Security Signatures 5 10th Mar 2009 06:07 AM
Windows Defender false positive on RegRun Security Suite Dmitry Sokolov Security Signatures 3 12th Jan 2009 07:13 AM
Is Defender causing false positive in McAfee SecurityCenter? =?Utf-8?B?Sl9lamZ1ZGQ=?= Spyware Application Compatibility 2 29th Jul 2007 05:34 AM
ShopAtHome False Positive with Full Scan? =?Utf-8?B?Q2hyaXM=?= Security and Anti-Spyware Community 1 8th Mar 2006 09:19 PM
BUG: False Positive on scan Henry Bordeleau Spyware Discussion 0 6th Jan 2005 05:39 PM


Features
 

Advertising
 

Newsgroups
 


All times are GMT +1. The time now is 02:45 PM.