Page 1 of 1

UniExtract contains trojan?

Posted: Wed Jun 28, 2006 7:47 am
by Toxteth O'Grady
UniExtract comes with a file called "IsXunpack.exe". For some reason Antivir reported a trojan in that file this morning. As this never happened before and Antivir is know to report false positives now and again, I sent the file to the makers of Antivir for analyses. I always do this in case of a positive and the usual reply is that it is not really a virus and it will be fixed in one the the next updates.

Not this time. This was their reply:
"Thank you for your recent inquiry.
In the attachment you have sent us we found the virus Trojan/Crypt.F.Gen. The current version of AntiVir already detects this virus.
Please note, that this is not a false positive.
We thank you for your assistance."


Well, the answer is very clear, but what is it all about?
Does anyone else get the same result with another AV?

Posted: Wed Jun 28, 2006 8:13 am
by Darkbee
I ran a scan on the file you mentioned with AVG (virus database 368.9.5/377) and found no such trojan. I dnwnloaded the UniExtract application some time ago, so if you recently downloaded it from their website it may be possible that it has a virus. Either that of your computer has recently caught a cold!

Posted: Wed Jun 28, 2006 9:02 am
by Toxteth O'Grady
Or it is faking having a cold. :)
I just found this: http://www.msfn.org/board/index.php?sho ... 418&st=120

There seem to be many AVs reporting false positives with this program.
Two online scans with other scanners I just did were "clean", so in spite of what Antivir says, I still think that file is OK.

Posted: Wed Jun 28, 2006 3:55 pm
by Darkbee
Toxteth O'Grady wrote:Or it is faking having a cold. :)
I just found this: http://www.msfn.org/board/index.php?sho ... 418&st=120

There seem to be many AVs reporting false positives with this program.
Two online scans with other scanners I just did were "clean", so in spite of what Antivir says, I still think that file is OK.
Well I did have AntiVir report a false positive once with a program called TimeCore Solo. However, in this instance the AntiVir team did confirm that this was a false positive rather than a truly infected file. The point is, it is more than possible, its happened to me.

Why don't you try an online scan to see what result you get. I would recommend HouseCall from TrendMicro.