PDA

View Full Version : Virus messages?



Oreb
April 12th, 2006, 02:25 PM
I've removed eTrust EZantivirus from my machines (at least for now) but it's been a good security app and I'm trying to find out what happened.

It started when I clicked on my shortcut for Downloader Pro (the last one before the paid upgrade). I got a warning message and the executable for DLP was deleted.

Then I clicked on my shortcut for BreezeBrowserPro and the same thing happened. It deleted my executable as it gave me warning messages.

Stupidly, I didn't keep the error log before I uninstalled the antivirus so I could get on with my work.

Has anyone had any experience with false (hopefully not real!) antivirus reports from these programs?

Thanks.

Oreb :confused:

Oreb
April 12th, 2006, 02:48 PM
Yuck. The AV company has told me to discontinue the heuristic scan until they get back to me. A known problem they say. Took me 12 minutes of explaining to get her to realize it's a known problem. Sheesh.

Anyway, I'll give it a try and see what happens.

Could be this will be helpful to someone else hereabouts.

O.

robkipp
April 12th, 2006, 02:50 PM
The same thing happened to me only with BreezeBrowser Pro and RawShooter Premium. I am not sure what is going on with this.

I wrote CA about this and have not heard back from them yet.
I am sure they will "pass the buck" on to someone or something
else.

With so much spam out there, you need an antivirus software.
Too bad I just upgraded for another year a month ago. :mad:

Rob Kipp
http://robkipp.com/

Oreb
April 12th, 2006, 03:42 PM
Sorry for your trouble but it's kind of nice to have company. :o

I've used this AV for years and years but now get it free through RoadRunner. A nice perk. Actually they give the whole security package but I only install the AV.

Anyway, here's my work around and it seems to do the trick. I went into the settings and added breezebrowser.exe (I use Pro on this machine and the old BB on another one - but the filename's the same) and downloader.exe to the on-demand and real-time modifications exclusions lists. That's worked on both computers I've adjusted so far.

That way all my other protection is there. If something else shows up, I'll evaluate it's worth to me and, if necessary, do the same thing.

If they should ever get back to me (I ain't holding my breath), I'll post it here.

Oreb

robkipp
April 12th, 2006, 04:31 PM
Thanks for your help ideas. I will add some programs to my list and see
if that helps. The Antivirus program removed the programs all together so I need to re-install them.

What a pain. I will let you know what I find if I hear from them too.
Rob Kipp

Oreb
April 12th, 2006, 06:04 PM
Reinstalling was a breeze (pun intended). For me, anyway, EZ just removed the exe file so I used my installation file but clicked on repair when that option came up. All settings and plugins were still intact and I was good to go in very little time.

O.

robkipp
April 12th, 2006, 06:14 PM
Same with me. I did a reinstall but chose repair option.
I guess everything is OK for now but still have not heard
from CA Associates.

Rob

Chris Breeze
April 12th, 2006, 07:47 PM
Clearly this is a false alarm but it is extremely annoying. I believe it may be related to the software protection scheme used by BBPro, DLPro and DSLR Remote Pro (and possibly also Raw Shooter Premium). I have contacted CA to try to resolve the problem and will also contact the suppliers of the software protection library so that they can apply pressure too.

robkipp
April 12th, 2006, 11:27 PM
Thanks for your help on this Chris.
Still - No word from ComputerAssociates on this issue.

Rob Kipp

Chris Breeze
April 13th, 2006, 03:36 PM
It appears Computer Associates have fixed the problem. If you download the latest antivirus files it will no longer report that BBPro contains a virus.

BTW They also advise turning off heuristic scanning as this is more likely to produce false positives than to actually catch something new.

robkipp
April 20th, 2006, 01:18 PM
Hi Chris,

I added CA option to not bother scaning my c:/Breeze folders
If I have time I may try and see if latest update works on my
computer, but may just leave everything the way it is.

Thanks for your help with this.
Rob Kipp

robkipp
April 25th, 2006, 11:22 AM
The latest update from CA did not delete BB-Pro. However, I am not sure what you mean by "turning off heuristic scanning. Could you tell me how to do this, I looked but found no reference setting in CA for this.

Thanks for your help,
Rob Kipp
http://robkipp.com/
------------

BTW They also advise turning off heuristic scanning as this is more likely to produce false positives than to actually catch something new.[/QUOTE]

Chris Breeze
April 26th, 2006, 06:01 AM
Sorry, I was just passing on what they said and don't know how to do this. I use a different antivirus app to protect my PCs.

icpix
May 10th, 2006, 04:14 PM
Heuristic scanning is a sort of fuzzy learning search facility. Such a facility is supposed to maximise your chances of detecting an as-yet-undetected piece of malware ie one that is able to disguise its signature to escape 'regular' detection. Mostly it maximises false positive alarms and, as a by product, nicely serves to exacerbate any existing user fear or promote any such where none previously existed. This is so that users continue to willingly purchase the so-called protection and updates.

ClamWIN (Google for it or its parent ClamAV) is Open Source (aka free) and can be set to update its signature payload every hour if necessary. My workstation's copy of ClamWIN has never false positived my licensed copy of BBpro. My server's use of ClamAV has been largely uneventful. I have no connection with the people developing ClamWIN/ClamAV other than being thoroughly thankful for their existence.

----best wishes, Robert