PC Review Forums Newsgroups Microsoft AntiSpyware Security Signatures 4 false positives.

Reply

4 false positives.

 
Thread Tools Rate Thread
Old 07-01-2005, 02:09 AM   #1
Dr Pizza
Guest
 
Posts: n/a
Default 4 false positives.


It claimed that tapicfg was CoolWebSearch. It isn't (at least, the file it
found isn't, maybe CWS has something of the same name). It's part of
Windows Server 2003. The default is to remove this (which for CWS makes
sense...) but it shouldn't be touching it.

It similarly claimed that remote.exe in the Win2K Support Tools is
malicious. It's claiming it to be Cyanure or somesuch. It's not. It is a
tool that could be used for nefarious things (it's a remote control tool),
but it's not ipso facto malicious. Detecting it as an enabler would be
reasonable, perhaps.

It believed tvenuax.dll from an (ancient) version of Lernout and Hauspie
TruVoice to be WhenU.SaveNow, which again is not the case.

Finally, it detected sporder.dll from SafeTP as part of WebHancer. Again,
it ain't. Potentially it can be (there is a sporder.dll in WebHancer,
AIUI), but it's an MS-distributed dll that's perfectly legitimate.

Is there a mechanism within the program itself for reporting false
positives?


  Reply With Quote
Old 08-01-2005, 03:41 AM   #2
Bill Sanderson
Guest
 
Posts: n/a
Default Re: 4 false positives.

This is the place to report false positives.

"Dr Pizza" <drpizza@quiscalusmexicanus.org> wrote in message
news:ec6Oh4F9EHA.2532@cpmsftngsa05.privatenews.microsoft.com...
> It claimed that tapicfg was CoolWebSearch. It isn't (at least, the file
> it
> found isn't, maybe CWS has something of the same name). It's part of
> Windows Server 2003. The default is to remove this (which for CWS makes
> sense...) but it shouldn't be touching it.
>
> It similarly claimed that remote.exe in the Win2K Support Tools is
> malicious. It's claiming it to be Cyanure or somesuch. It's not. It is
> a
> tool that could be used for nefarious things (it's a remote control tool),
> but it's not ipso facto malicious. Detecting it as an enabler would be
> reasonable, perhaps.
>
> It believed tvenuax.dll from an (ancient) version of Lernout and Hauspie
> TruVoice to be WhenU.SaveNow, which again is not the case.
>
> Finally, it detected sporder.dll from SafeTP as part of WebHancer. Again,
> it ain't. Potentially it can be (there is a sporder.dll in WebHancer,
> AIUI), but it's an MS-distributed dll that's perfectly legitimate.
>
> Is there a mechanism within the program itself for reporting false
> positives?
>
>



  Reply With Quote
Reply



Thread Tools
Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off