Page 1 of 1
AVG false positive flag?
Posted: Wed Aug 21, 2013 3:01 pm
by liverpooljim
hi, i used to use this bot back in 09 for war and aion, thought i would subscribe again and use it on swtor, Just signed up and grabbed the swtor bot but avg is flagging everything as high threat. Can i just confirm this is a false positive?
Many thanks
Re: AVG false positive flag?
Posted: Wed Aug 21, 2013 7:35 pm
by PitViper
Yes it is.. it should be some generic message you are getting saying its encrypted, but viper doesnt have anything harmful in it.. ie no adware, spyware, virii, trojans, etc.
Re: AVG false positive flag?
Posted: Wed Aug 21, 2013 8:35 pm
by liverpooljim
thanks viper, i thought as much, however something alarming in my avg report today.
7 threats (medium) all related to the system32/driver/sdpy.sys
no matter what i do the threats return. Google thinks its somethig to do with daemon tools but its only just started to be flagged up. Bit concerned.
Re: AVG false positive flag?
Posted: Wed Aug 21, 2013 8:42 pm
by PitViper
Did a quick search.. didnt come up with anything for that specific dll.. Lemme know what you find out.
Re: AVG false positive flag?
Posted: Thu Aug 22, 2013 10:17 am
by liverpooljim
sorry buddy its spdy.sys hehe
"";"pci.sys, hooked import ntoskrnl.exe IoDetachDevice -> spdy.sys +0x625DC, C:\Windows\System32\Drivers\spdy.sys";"Infected"
"";"pci.sys, hooked import ntoskrnl.exe IoAttachDeviceToDeviceStack -> spdy.sys +0x62650, C:\Windows\System32\Drivers\spdy.sys";"Infected"
"";"Inline hook ataport.SYS DllUnload -> spdy.sys +0x5E360, C:\Windows\System32\Drivers\spdy.sys";"Infected"
"";"atapi.sys, hooked import ataport.SYS AtaPortWritePortUchar -> spdy.sys +0x2DA24, C:\Windows\System32\Drivers\spdy.sys";"Infected"
"";"atapi.sys, hooked import ataport.SYS AtaPortWritePortBufferUshort -> spdy.sys +0x2DBA0, C:\Windows\System32\Drivers\spdy.sys";"Infected"
"";"atapi.sys, hooked import ataport.SYS AtaPortReadPortUchar -> spdy.sys +0x2D224, C:\Windows\System32\Drivers\spdy.sys";"Infected"
"";"atapi.sys, hooked import ataport.SYS AtaPortReadPortBufferUshort -> spdy.sys +0x2D35C, C:\Windows\System32\Drivers\spdy.sys";"Infected"
is my avg report, it could be daemon tools as one site suggested but its only just happend after i installed the bot yesterday
when i hit remove threat they are all back within seconds, not evena reboot helps. avg lists them as medium.
Re: AVG false positive flag?
Posted: Thu Aug 22, 2013 10:22 am
by PitViper
Definitely viper does not have that.
But it does sound like you have a virus. Try malwarebytes.
Re: AVG false positive flag?
Posted: Thu Aug 22, 2013 10:32 am
by liverpooljim
strange, i rebooted and now avg shows up splp.sys. dont seem to find the exact proble online, only avg is flagging too. used spybot and rogue killer and they dont find anyting wrong, just running malwarebytes now. Will keep you posted
thanks in advance for the help btw
Re: AVG false positive flag?
Posted: Thu Aug 22, 2013 10:41 am
by liverpooljim
no results in malwarebytes, think ill try another virus checker other than avg. I know it likes to flag loads of cracked exes for games and such as issues.
Re: AVG false positive flag?
Posted: Thu Aug 22, 2013 11:01 am
by liverpooljim
just ran malwarebytes anti rootkit tool as well and nothing flagged up.
Currently running MSE and superantispyware afterwards to makesure after removing AVG
pretty sure its just being a dick. I hear AVG and Avast turned into aids in the last 2 years and MSE is the new antivirus everyone uses
Re: AVG false positive flag?
Posted: Thu Aug 22, 2013 11:17 am
by liverpooljim
ok final report
MSE, superantispyware malwarebytes and MWBanti rootkit all find nowt wrong at all. I have killed AVG for good and will use MSE from now on. Defo a false positive on the bot and whatever files avg was worried about have nothing wrong with them.
Now to wait for swtor to bring the servers back up so I can lvl my low lvl sorc, got about 2 full levels during the night as a test run
Re: AVG false positive flag?
Posted: Fri Aug 30, 2013 6:45 pm
by se7enthsin
I use avast, and have no problems.