From: Wile E. Coyote on
Dustin Cook wrote:

> It's been sent to us. I'll let you know what we find....
>
>

OK, thanks.
From: Dustin Cook on
"Wile E. Coyote" <coyote(a)ACME.invalid> wrote in
news:WD1Qm.27160$kY2.18314(a)newsfe01.iad:

Hi Wile.

I took a look at the sample file we've recieved myself, so I could get you
updated on it. Non of the files inside are executables themselves. So it's
very likely a false positive; and this should be cleared up soon. Sorry for
the inconvenience.


--
Dustin Cook [Malware Researcher]
MalwareBytes - http://www.malwarebytes.org
BugHunter - http://bughunter.it-mate.co.uk
From: David H. Lipman on
From: "Dustin Cook" <bughunter.dustin(a)gmail.com>

| "Wile E. Coyote" <coyote(a)ACME.invalid> wrote in
| news:WD1Qm.27160$kY2.18314(a)newsfe01.iad:

| Hi Wile.

| I took a look at the sample file we've recieved myself, so I could get you
| updated on it. Non of the files inside are executables themselves. So it's
| very likely a false positive; and this should be cleared up soon. Sorry for
| the inconvenience.


Some information was that it was unusually packed and that may have been the red flag.


--
Dave
http://www.claymania.com/removal-trojan-adware.html
Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp


From: Wile E. Coyote on
David H. Lipman wrote:
> From: "Dustin Cook" <bughunter.dustin(a)gmail.com>
>
> | "Wile E. Coyote" <coyote(a)ACME.invalid> wrote in
> | news:WD1Qm.27160$kY2.18314(a)newsfe01.iad:
>
> | Hi Wile.
>
> | I took a look at the sample file we've recieved myself, so I could get you
> | updated on it. Non of the files inside are executables themselves. So it's
> | very likely a false positive; and this should be cleared up soon. Sorry for
> | the inconvenience.
>
>
> Some information was that it was unusually packed and that may have been the red flag.
>
>
OK, thanks to both of you. Today Avira started to flag GTR2.exe which is
another game file and Avira has never flagged it previously and I am
positive that is false positive once again. :(
From: David H. Lipman on
From: "Wile E. Coyote" <coyote(a)ACME.invalid>

| David H. Lipman wrote:
>> From: "Dustin Cook" <bughunter.dustin(a)gmail.com>

>> | "Wile E. Coyote" <coyote(a)ACME.invalid> wrote in
>> | news:WD1Qm.27160$kY2.18314(a)newsfe01.iad:

>> | Hi Wile.

>> | I took a look at the sample file we've recieved myself, so I could get you
>> | updated on it. Non of the files inside are executables themselves. So it's
>> | very likely a false positive; and this should be cleared up soon. Sorry for
>> | the inconvenience.


>> Some information was that it was unusually packed and that may have been the red flag.


| OK, thanks to both of you. Today Avira started to flag GTR2.exe which is
| another game file and Avira has never flagged it previously and I am
| positive that is false positive once again. :(

Here's what to do...

Send the file in a password protected ZIP file with the password being; infected
{ password = infected }

Send it to; virus(a)antivir.de

With the subject; Possible False Positive.

State all information you know about the file in the body of the email.

--
Dave
http://www.claymania.com/removal-trojan-adware.html
Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp