FP: FraudTool.Win32.FakeVimes!delf (v) Engine in Norton 360?
Started by
BWarriner
, Apr 28 2012 08:44 AM
8 replies to this topic
#1
Posted 28 April 2012 - 08:44 AM
Currently residing in the Quarantine of Adaware, please let me know if this is a false positive. Based on what Adaware is telling me, will it automatically delete upon reboot?
#2
Posted 30 April 2012 - 08:23 AM
Hi BWarriner,
Thanks for your report. Can I ask you to upload the file from quaratine that looks like this:
e2f37708.tmp.<lots of number>.aawqff.
The .aawqff file is the quaratined file whereas the .aawqif just stores information about the quarantined file's original location. When I get a copy of the .aawqff file, I can check it out for you.
Thanks!
Regards,
Andy
Lavasoft Malware Labs
Thanks for your report. Can I ask you to upload the file from quaratine that looks like this:
e2f37708.tmp.<lots of number>.aawqff.
The .aawqff file is the quaratined file whereas the .aawqif just stores information about the quarantined file's original location. When I get a copy of the .aawqff file, I can check it out for you.
Thanks!
Regards,
Andy
Lavasoft Malware Labs
#3
Posted 01 May 2012 - 01:25 AM
Based on your guide for posting False Positives, the download instructions for XP state to navigate to: C:\Documents and Settings\All Users\Application Data\Lavasoft\Ad-Aware\Quarantine which is what I zipped above already.
The location that the potential FP was quarantined from within the Norton folder is unaccesible to me at all. I receive an "Access is Denied" message.
Should I be looking for this file somewhere else? I did a physical search for "e2f37708.tmp" and found nothing on the C drive.
I would like to add, it occured to me that about a week or so ago, Norton 360 stopped a trojan while browsing the internet via Sandboxie. Since this is the first time I have run across malware while sandboxed, how does that instance interact with Norton 360? I believe that once I close Sandboxie the malware is removed, or because Norton 360 caught it, it sill makes a record within it's own files possibly?
The location that the potential FP was quarantined from within the Norton folder is unaccesible to me at all. I receive an "Access is Denied" message.
Should I be looking for this file somewhere else? I did a physical search for "e2f37708.tmp" and found nothing on the C drive.
I would like to add, it occured to me that about a week or so ago, Norton 360 stopped a trojan while browsing the internet via Sandboxie. Since this is the first time I have run across malware while sandboxed, how does that instance interact with Norton 360? I believe that once I close Sandboxie the malware is removed, or because Norton 360 caught it, it sill makes a record within it's own files possibly?
#4
Posted 01 May 2012 - 10:10 AM
>>> Quarantined items:
>>> Description: c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\srtsp\srtetmp\e2f37708.tmp Family Name: FraudTool.Win32.FakeVimes!delf (v) Engine: 3 Clean status: Reboot required Item ID: 1 Family ID: 0 MD5: ADBBEC6897909D14C5DEF5E7C8E46D7
That you cannot find the file and with above information from the log: e2f37708.tmp is a temporary file and it is possible that the file did not exist after the reboot and therefore was never put in the quarantine. It is also possible that Norton protects that folder and stops Ad-Aware from removing any files from it. See http://community.nor...essed/td-p/8406 and http://www.symantec....spsrtetmpxxxtmp
I don't think this is the best place for questions regarding Sandboxie and Norton programs.
>>> Description: c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\srtsp\srtetmp\e2f37708.tmp Family Name: FraudTool.Win32.FakeVimes!delf (v) Engine: 3 Clean status: Reboot required Item ID: 1 Family ID: 0 MD5: ADBBEC6897909D14C5DEF5E7C8E46D7
That you cannot find the file and with above information from the log: e2f37708.tmp is a temporary file and it is possible that the file did not exist after the reboot and therefore was never put in the quarantine. It is also possible that Norton protects that folder and stops Ad-Aware from removing any files from it. See http://community.nor...essed/td-p/8406 and http://www.symantec....spsrtetmpxxxtmp
I don't think this is the best place for questions regarding Sandboxie and Norton programs.
#5
Posted 02 May 2012 - 12:32 AM
Ok, next question. I want to restore this instance back to the original Norton 360 location. Everytime I click on restore from the Quarantine tab in Ad-Aware, all it does is display 'Do Nothing' immediately afterwards. If I click on 'Custom' it adds the instance to the Ignore List. I am unable to remove or restore this instance at all from Ad-Aware.
Removing the file from C:Documents and Settings > Application Data > Lavasoft > Quarantine folder doesn't affect the listing, nor does removing C:Documents and Settings > Application Data > Lavasoft > Logs text file do anything to change what appears in the Quarantine GUI. Any advice?
Removing the file from C:Documents and Settings > Application Data > Lavasoft > Quarantine folder doesn't affect the listing, nor does removing C:Documents and Settings > Application Data > Lavasoft > Logs text file do anything to change what appears in the Quarantine GUI. Any advice?
#6
Posted 02 May 2012 - 09:51 AM
Since the file has not been quarantined, it cannot be restored.
#7
Posted 02 May 2012 - 03:15 PM
The problem now is that I am unable to remove, edit. modify the GUI listing under the Quarantine tab. Whatever I attempt to do to remove the listing doesn't work, it just reverts back to 'Do Nothing'. I thought it had fixed itself once I rebooted, but it simply reappeared under the Quarantine tab. How do I remove this listing from the GUI?
Attached Files
#8
Posted 03 May 2012 - 10:26 PM
I have asked my contact person at Lavasoft and they will investigate the issue.
#9
Posted 08 May 2012 - 09:52 PM
Lavasoft has not been able to reproduce the error. 
If it is important that the list is empty, you can try to uninstall Ad-Aware and then install it again. Maybe do an upgrade to Ad-Aware 10.1.
If it is important that the list is empty, you can try to uninstall Ad-Aware and then install it again. Maybe do an upgrade to Ad-Aware 10.1.
0 user(s) are reading this topic
0 members, 0 guests, 0 anonymous users














