Guidelines | CA Support Online | Community Events
CA Anti-Virus General Discussion
Register  ·  Sign In  ·  Help
Jump to Page:   1 · 2 · 3  |  Next Page
  Reply   Reply  

33.3.7051 Stdwin32 False Positives
Options    Options  
WhiteRoseRaven
Visitor
Posts: 1
Registered: 08-12-2009


WhiteRoseRaven

Message 1 of 24

Viewed 4,823 times


Since the signature update 33.3.7051 E-Trust is detecting *.dll files and *.exe files as being infected with the virus stdwin32. The files are then renamed to *.AVB

 

These files are not affected and are belonging to system application such as server OS amongst others.

 

Awaiting on CA support to resolve this fault as its a critical mistake made by CA.

 

See this webpage for further details - the fallout could be massive.

 

http://www.dynamoo.com/blog/2009/08/ca-etrust-goes-nuts-with-stdwin32-and.html

Kudos!
08-12-2009 05:59 AM
 
  Reply   Reply  

Re: 33.3.7051 Stdwin32 False Positives
Options    Options  
andymcknight
New Member
Posts: 20
Registered: 01-22-2008


andymcknight

Message 2 of 24

Viewed 4,765 times


Confirmed same problem here.  False detection on a Win7 box in a MS Visual Studio file which crashed the application.  eTrust also crashed and machine required reboot.

 

Have set all real-time and scheduled scan polices to Read-Only for the moment.  Is there an easy way to reject a specific signature file?

Kudos!
08-12-2009 06:40 AM
 
  Reply   Reply  

Re: 33.3.7051 Stdwin32 False Positives
Options    Options  
andymcknight
New Member
Posts: 20
Registered: 01-22-2008


andymcknight

Message 3 of 24

Viewed 4,737 times


Further info on this; two files were picked up as false positives on this box.  One was an internally developed dll and the second was related to the AJAX Control Toolkit in VS 2008.
Kudos!
08-12-2009 06:53 AM
 
  Reply   Reply  

33.3.7051 Stdwin32 False Positives
Options    Options  
Mar
Visitor
Posts: 1
Registered: 08-12-2009


Mar

Message 4 of 24

Viewed 4,709 times


I have the same problem.
Kudos!
08-12-2009 07:01 AM
 
  Reply   Reply  

Re: 33.3.7051 Stdwin32 False Positives
Options    Options  
StevenH
New Member
Posts: 2
Registered: 06-04-2008


StevenH

Message 5 of 24

Viewed 4,704 times


If you log this with CA support they'll email you when the issue has been resolved.
Kudos!
08-12-2009 07:02 AM
 
  Reply   Reply  

Re: 33.3.7051 Stdwin32 False Positives
Options    Options  
JohnL
Visitor
Posts: 1
Registered: 08-12-2009


JohnL

Message 6 of 24

Viewed 4,686 times


ditto from oz...

 

doesn't look good.

Kudos!
08-12-2009 07:10 AM
 
  Reply   Reply  

Re: 33.3.7051 Stdwin32 False Positives
Options    Options  
DionM
Visitor
Posts: 2
Registered: 08-12-2009


DionM

Message 7 of 24

Viewed 4,672 times


Ditto from New Zealand.

 

The "cure" of files on one of our client's servers killed Exchange and ArcServe. Fortunately renaming the .avb's back to original files and restarting the services sparked it back into life.

 

Have disabled realtime sitewide for all clients.

 

Looking forward to the fix. This one is going to be NASTY. :(

Kudos!
08-12-2009 07:13 AM
 
  Reply   Reply  

Re: 33.3.7051 Stdwin32 False Positives
Options    Options  
Dynamoo
New Member
Posts: 3
Registered: 04-09-2008


Dynamoo

Message 8 of 24

Viewed 4,642 times


I have the Realtime behaviour set to "Rename" rather than Cure or Delete, it makes recovery a lot easier. I'm guessing that it's 33.3.7051 causing the problem, looks like a BIG update. It may have happened when it was tranistioning from one version to another.

 

It started here about 0625 UK time (0525 GMT). It seems pretty random, it first ate our Sophos installation before turning on wireless NIC drivers, Nokia software, VNC, printer drivers and it even deleted some of its own binaries. Nice. I think it just deleted whatever it was accessing at the time rather than it being a specific false positive. 

Kudos!
08-12-2009 07:22 AM
 
  Reply   Reply  

Re: 33.3.7051 Stdwin32 False Positives
Options    Options  
andymcknight
New Member
Posts: 20
Registered: 01-22-2008


andymcknight

Message 9 of 24

Viewed 4,630 times


I can also confirm I've seen a couple of Microsoft files show up as false positives.  Mqgentr.dll and Msrdp.ocx.  Realtime picked these up in the SoftewareDistribution folders, not in the live OS.

 

I've currently left Realtime running on all my clients but it's set to Report Only to see how far this one has spread.

Kudos!
08-12-2009 07:25 AM
 
  Reply   Reply  

Re: 33.3.7051 Stdwin32 False Positives
Options    Options  
andymcknight
New Member
Posts: 20
Registered: 01-22-2008


andymcknight

Message 10 of 24

Viewed 4,561 times



Dynamoo wrote:

I have the Realtime behaviour set to "Rename" rather than Cure or Delete, it makes recovery a lot easier. I'm guessing that it's 33.3.7051 causing the problem, looks like a BIG update.


Yeah, this is a massive jump, it's not just an incremental signature update, it's a full update to the VET engine by the looks of it.

 

We've gone, what, a little over a month since this previously happened?  You'd think CA would be testing these releases thoroughly after the last fiasco.

Kudos!
08-12-2009 07:45 AM
 
Jump to Page:   1 · 2 · 3  |  Next Page