Help - Search - Members - Calendar
Full Version: Acrord32.exe & Superantispyware.exe suddenly !
Lavasoft Support Forums > Archived Topics > Archives: Resolved/Inactive Topics > Resolved/Inactive False Postive Issues
PeterWorks
I have 3 files on my data (D:) drive which have been there for many months. Suddenly, after updating AdAware 2008's definition file yesterday and doing a scan it reported problems with the topic title files. Upto then no problems when scanning with AdAware. I downloaded AdAware anniversary edition and the files were seen as okay (no reported problem). Also my AV app (Avir Antivirus), SpyBot and SuperAntiSpyware found nothing.

I have uploaded the log and the files.

Peter
LS Anders
Hello PeterWorks

Thank you for reporting this. We will re-investigate the files and if they are found to be false positives they will be removed from detection in the next definition file update.

Regards
LS Anders
PeterWorks
All fixed in the latest update - thanks for your rapid response...

Peter
LS Pekka
Thanks for reporting the issue smile.gif
MikeBOD
Same edition and signatures reported my (adobe acrobat reader) acrord32.exe as win32.worm.viking. Is this a false positive?

LS Pekka
QUOTE(MikeBOD @ Feb 3 2009, 05:32 PM) *
Same edition and signatures reported my (adobe acrobat reader) acrord32.exe as win32.worm.viking. Is this a false positive?


Hi MikeBOD!

The files referred to and uploaded by PeterWorks, see earlier posts in this thread, has been removed from detection and the issue was solved (as of 0146.0003). Would it be possible for you to post the complete log file from the scan from where the win32.worm.viking object was detected? We would need that log-file, or the file sample, in order to investigate this issue further.

Regards,

LS Pekka
MikeBOD
Unfortunately the log file has been replaced but the file is attached
Click to view attachment

Norton 2008 did not pick it up as a virus. I ran it through virustotal.com with only one positive result.

Many Thanks

MikeB

Virus Total
Virustotal is a service that analyzes suspicious files and facilitates the quick detection of viruses, worms, trojans, and all kinds of malware detected by antivirus engines. More information...
File AcroRd32.exe received on 02.02.2009 07:59:10 (CET)
Current status: finished
Result: 1/39 (2.56%)
Compact Compact
Print results Print results
Antivirus Version Last Update Result
a-squared 4.0.0.93 2009.02.02 -
AhnLab-V3 5.0.0.2 2009.02.02 -
AntiVir 7.9.0.70 2009.02.01 -
Authentium 5.1.0.4 2009.02.01 -
Avast 4.8.1281.0 2009.02.01 -
AVG 8.0.0.229 2009.02.01 -
BitDefender 7.2 2009.02.02 -
CAT-QuickHeal 10.00 2009.02.02 -
ClamAV 0.94.1 2009.02.02 -
Comodo 957 2009.02.01 -
DrWeb 4.44.0.09170 2009.02.02 -
eSafe 7.0.17.0 2009.02.01 -
eTrust-Vet 31.6.6335 2009.01.29 -
F-Prot 4.4.4.56 2009.02.01 -
F-Secure 8.0.14470.0 2009.02.02 -
Fortinet 3.117.0.0 2009.02.02 -
GData 19 2009.02.02 -
Ikarus T3.1.1.45.0 2009.02.02 -
K7AntiVirus 7.10.612 2009.01.31 -
Kaspersky 7.0.0.125 2009.02.02 -
McAfee 5513 2009.02.01 -
McAfee+Artemis 5513 2009.02.01 -
Microsoft 1.4306 2009.02.02 -
NOD32 3817 2009.02.02 -
Norman 6.00.02 2009.01.31 -
nProtect 2009.1.8.0 2009.02.02 -
Panda 9.5.1.2 2009.02.01 -
PCTools 4.4.2.0 2009.02.01 -
Prevx1 V2 2009.02.02 -
Rising 21.14.61.00 2009.02.01 -
SecureWeb-Gateway 6.7.6 2009.02.01 -
Sophos 4.38.0 2009.02.02 -
Sunbelt 3.2.1835.2 2009.01.16 Worm.Win32.Viking.lj
Symantec 10 2009.02.02 -
TheHacker 6.3.1.5.243 2009.02.01 -
TrendMicro 8.700.0.1004 2009.02.02 -
VBA32 3.12.8.12 2009.02.01 -
ViRobot 2009.2.2.1584 2009.02.02 -
VirusBuster 4.5.11.0 2009.02.01 -
Additional information
File size: 4669511 bytes
MD5...: ba9a26a090809162ee06d6688f0ed4cf
SHA1..: ed768bc2092ecc7ae33d7b2adee44846cfd39491
SHA256: c68093d93eb17902e7a4854fd1bdc735edae2bc4deb4b94b750bdca0200946c0
SHA512: 863d99675c3e1a3d9a2baafe11efe0aa06f4037d27a9a14f83df8e8336f8e02e
fa276f1b6906f9fd8bc2bb2b80ad0d090d7b81ea4b4f8e82b2a3ce6193fe74f6
ssdeep: 98304:cXv/EfkR5oNVo8FZbYzyAjmRgE974E1c0Tn6Z6HDDkAJv:pqCGz3Z6HDv
PEiD..: Armadillo v1.71
TrID..: File type identification
Windows OCX File (71.0%)
Win32 Executable MS Visual C++ (generic) (21.6%)
Win32 Executable Generic (4.9%)
Generic Win/DOS Executable (1.1%)
DOS Executable Generic (1.1%)
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0x6bbed
timedatestamp.....: 0x3d86e6ce (Tue Sep 17 08:24:46 2002)
machinetype.......: 0x14c (I386)

( 5 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x2a8de9 0x2a9000 6.66 c4d3d8dddb15c92b65f6bab53d9b45e4
.rdata 0x2aa000 0x5cca5 0x5d000 4.16 59ee48ed98bf08d9b2162ba266b60e53
.data 0x307000 0x5312c 0x48000 5.87 45433aa38ebd1268c6265f3a307095dc
.rsrc 0x35b000 0xf2388 0xf3000 4.91 f4f58734d997244a8b4a71a96d1b38de
.reloc 0x44e000 0x3122a 0x32000 6.16 2865e709ef32cc7c2df5285df53eecb0

( 18 imports )
> CoolType.dll: -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -
> VERSION.dll: VerQueryValueA, GetFileVersionInfoSizeA, GetFileVersionInfoA
> USER32.dll: WindowFromPoint, GetWindowThreadProcessId, GetActiveWindow, RedrawWindow, SetScrollRange, ScrollWindow, InvalidateRgn, ScreenToClient, GetUpdateRect, GetUpdateRgn, BeginPaint, EndPaint, IsChild, SetCapture, GetSysColorBrush, GetWindowLongA, GetDoubleClickTime, GetCursor, MessageBeep, LoadImageA, LoadBitmapA, EnableScrollBar, GetScrollInfo, SetScrollInfo, SetWindowLongA, CallWindowProcA, InvalidateRect, GetDlgItem, GetMenuItemInfoA, GetMenuItemRect, TrackPopupMenu, GetMenuItemCount, GetMenuItemID, DispatchMessageA, ModifyMenuA, InsertMenuItemA, RemoveMenu, InsertMenuA, GetMenu, TranslateMDISysAccel, SetMenu, CreateMenu, GetCursorPos, GetIconInfo, TabbedTextOutA, GetDCEx, GetClipboardData, IsIconic, IsZoomed, ValidateRect, SetFocus, DdeClientTransaction, CharNextA, DeleteMenu, CreatePopupMenu, AppendMenuA, IsWindowEnabled, IsDialogMessageA, SetCursor, wsprintfA, UnregisterClassA, DrawMenuBar, SetActiveWindow, GetCapture, ReleaseCapture, DrawIcon, DestroyIcon, GetSystemMetrics, GetWindow, GetClassNameA, GetForegroundWindow, SetRect, MapWindowPoints, SetWindowTextA, KillTimer, GetWindowPlacement, ShowOwnedPopups, UnhookWindowsHookEx, SetWindowsHookExA, CallNextHookEx, RegisterWindowMessageA, FindWindowA, LoadStringA, SystemParametersInfoA, GetWindowDC, GetMenuCheckMarkDimensions, OemToCharA, GetLastActivePopup, SetDlgItemTextA, GetWindowTextA, GetWindowTextLengthA, MoveWindow, CharUpperA, TranslateMessage, GetMessageA, DeferWindowPos, LoadAcceleratorsA, TranslateAcceleratorA, LoadMenuA, GetClassInfoA, WinHelpA, ReuseDDElParam, UnpackDDElParam, GetSubMenu, EqualRect, IntersectRect, GetClassLongA, SetWindowPlacement, GetTopWindow, EndDeferWindowPos, BeginDeferWindowPos, AdjustWindowRectEx, DrawTextA, GrayStringA, CreateDialogIndirectParamA, EndDialog, DefFrameProcA, GetNextDlgGroupItem, GetTabbedTextExtentA, CopyAcceleratorTableA, PostThreadMessageA, LockWindowUpdate, GetMenuStringA, MapDialogRect, SetWindowContextHelpId, SetParent, IsRectEmpty, InSendMessage, DefMDIChildProcA, GetMessagePos, InflateRect, FrameRect, IsWindow, PtInRect, GetNextDlgTabItem, EnableMenuItem, CheckMenuItem, SetMenuItemBitmaps, GetMenuState, OffsetRect, SetTimer, GetMessageTime, DestroyMenu, GetKeyboardLayout, ActivateKeyboardLayout, SetPropA, CopyRect, OemToCharBuffA, CharUpperBuffA, CharToOemBuffA, HideCaret, ShowCaret, ExcludeUpdateRgn, DefDlgProcA, IsWindowUnicode, RegisterClipboardFormatA, BringWindowToTop, GetWindowRect, PostMessageA, DestroyWindow, RegisterClassA, DefWindowProcA, GetParent, ShowWindow, CreateWindowExA, GetClientRect, ReleaseDC, GetDC, CloseClipboard, SetClipboardData, EmptyClipboard, OpenClipboard, SendMessageA, GetCaretPos, SetRectEmpty, LoadCursorA, LoadIconA, SetWindowPos, ClientToScreen, FillRect, IsWindowVisible, EnableWindow, MessageBoxA, DdeInitializeA, DdeUninitialize, DdeNameService, DdeCreateStringHandleA, DdeFreeStringHandle, PeekMessageA, DdeGetData, PostQuitMessage, SetForegroundWindow, DdeAddData, DdeCreateDataHandle, DdeConnect, DdeDisconnect, VkKeyScanExA, MapVirtualKeyExA, GetKeyState, GetDesktopWindow, GetKeyboardLayoutList, IsClipboardFormatAvailable, UpdateWindow, GetAsyncKeyState, RemovePropA, GetPropA, GetFocus, DrawFocusRect, GetDlgCtrlID, SendDlgItemMessageA, GetSysColor
> KERNEL32.dll: GetEnvironmentStringsW, IsBadReadPtr, IsDBCSLeadByteEx, HeapCompact, RemoveDirectoryA, _lopen, FreeResource, _lwrite, GetSystemTimeAsFileTime, _llseek, DuplicateHandle, IsValidCodePage, EnumResourceNamesA, LoadLibraryExA, GetSystemDefaultLangID, GlobalUnlock, GlobalLock, GetPrivateProfileStringA, GetVersionExA, FreeLibrary, GetProcAddress, GetLastError, LoadLibraryA, FindClose, FindNextFileA, FindFirstFileA, InitializeCriticalSection, DeleteCriticalSection, InterlockedIncrement, InterlockedDecrement, MultiByteToWideChar, GetProfileStringA, lstrcmpiA, lstrlenA, _lread, _lclose, OpenFile, lstrcatA, GetWindowsDirectoryA, GlobalFree, WideCharToMultiByte, GetACP, GlobalAlloc, GetLocaleInfoA, GetLocaleInfoW, GetModuleFileNameA, GetUserDefaultLCID, lstrcpyA, CloseHandle, CreateSemaphoreA, lstrcpynA, GetCurrentThreadId, WinExec, GetTickCount, GlobalReAlloc, GetVersion, lstrcmpA, FindResourceA, LockResource, LoadResource, SizeofResource, IsDBCSLeadByte, GlobalMemoryStatus, ReleaseSemaphore, OpenSemaphoreA, WaitForSingleObject, GetSystemInfo, SetCurrentDirectoryA, GetCurrentDirectoryA, CopyFileA, DeleteFileA, GetFileAttributesA, HeapDestroy, lstrlenW, Sleep, CreateDirectoryA, GetTempPathA, GlobalSize, VirtualQuery, GlobalHandle, MulDiv, GetPrivateProfileIntA, GetProfileIntA, GetTimeFormatA, GetDateFormatA, GetModuleHandleA, FormatMessageA, GetCurrentProcessId, FileTimeToSystemTime, FileTimeToLocalFileTime, GetFileTime, CreateFileA, LocalFree, CompareStringW, GetCurrentProcess, ReadFile, WriteFile, SetFilePointer, FlushFileBuffers, LockFile, UnlockFile, SetEndOfFile, MoveFileA, GetVolumeInformationA, GetFullPathNameA, GetStringTypeExA, GetThreadLocale, GetShortPathNameA, IsBadWritePtr, RtlUnwind, CompareFileTime, GlobalAddAtomA, GlobalGetAtomNameA, GlobalDeleteAtom, GlobalFindAtomA, SetLastError, GetTempFileNameA, SetFileTime, GetDiskFreeSpaceA, GetCurrentThread, WritePrivateProfileStringA, LeaveCriticalSection, EnterCriticalSection, GetProcessVersion, GlobalFlags, LocalAlloc, TlsAlloc, TlsFree, TlsSetValue, LocalReAlloc, TlsGetValue, GetFileSize, LocalFileTimeToFileTime, SystemTimeToFileTime, SetFileAttributesA, SetErrorMode, GetCPInfo, GetOEMCP, SetHandleCount, RaiseException, GetDriveTypeA, HeapFree, ExitProcess, TerminateProcess, HeapReAlloc, HeapAlloc, GetStartupInfoA, GetCommandLineA, GetTimeZoneInformation, GetSystemTime, GetLocalTime, HeapSize, SetUnhandledExceptionFilter, SetStdHandle, GetFileType, GetStringTypeA, GetStdHandle, LCMapStringA, LCMapStringW, GetEnvironmentVariableA, HeapCreate, VirtualFree, VirtualAlloc, UnhandledExceptionFilter, GetEnvironmentStrings, GetStringTypeW, FreeEnvironmentStringsA, FreeEnvironmentStringsW, SetEnvironmentVariableA, IsBadCodePtr, CompareStringA
> GDI32.dll: PatBlt, GetTextFaceA, CreateScalableFontResourceA, GetFontData, GetBkColor, GetTextAlign, CopyMetaFileA, CreateRectRgnIndirect, GetTextExtentPointA, CreateMetaFileA, CloseMetaFile, DeleteMetaFile, ExtTextOutA, RectVisible, PtVisible, GetWindowExtEx, GetViewportExtEx, IntersectClipRect, ExcludeClipRect, ScaleWindowExtEx, SetWindowExtEx, ScaleViewportExtEx, SetViewportExtEx, OffsetViewportOrgEx, SetViewportOrgEx, GetDCOrgEx, GetTextColor, GetTextExtentExPointA, GetCurrentPositionEx, SetDIBitsToDevice, EnumFontFamiliesA, EnumFontsA, GetRgnBox, CreateEnhMetaFileA, CloseEnhMetaFile, DeleteEnhMetaFile, DPtoLP, AbortDoc, EndDoc, StartDocA, SetAbortProc, Escape, StartPage, EndPage, ExtEscape, ResetDCA, CreateICA, SetTextCharacterExtra, CombineRgn, OffsetRgn, SelectPalette, RealizePalette, StretchBlt, GetMapMode, SetMapMode, CreateDIBSection, GetObjectType, GetClipBox, SetRectRgn, GetClipRgn, SetBkMode, SetTextAlign, GetPolyFillMode, CreatePolygonRgn, MoveToEx, LineTo, FillRgn, CreateBitmap, CreatePatternBrush, GetWindowOrgEx, Polyline, GdiFlush, SetROP2, CreatePen, CreateFontA, GetTextMetricsA, RemoveFontResourceA, AddFontResourceA, CreatePalette, CreateDIBitmap, GetTextExtentPoint32A, BitBlt, GetDIBits, LPtoDP, CreateSolidBrush, SetBkColor, TextOutA, EnumFontFamiliesExA, GetDeviceCaps, CreateFontIndirectA, GetStockObject, GetObjectA, CreateDCA, CreateCompatibleDC, CreateCompatibleBitmap, SelectObject, SetTextColor, Rectangle, SetWindowOrgEx, DeleteDC, SaveDC, CreateRectRgn, SelectClipRgn, RestoreDC, DeleteObject
> ADVAPI32.dll: RegDeleteKeyA, RegCloseKey, RegQueryValueExA, RegOpenKeyExA, RegSetValueExA, RegEnumKeyExA, RegDeleteValueA, RegEnumValueA, RegOpenKeyA, RegEnumKeyA, RegSetValueA, RegCreateKeyA, RegQueryValueA, GetUserNameA, SetFileSecurityA, GetFileSecurityA, RegCreateKeyExA, RegQueryInfoKeyA
> COMCTL32.dll: -
> ole32.dll: OleIsCurrentClipboard, CLSIDFromString, OleInitialize, OleFlushClipboard, CLSIDFromProgID, OleUninitialize, OleDuplicateData, CoTaskMemAlloc, CreateBindCtx, CoFreeUnusedLibraries, DoDragDrop, StringFromCLSID, CreateGenericComposite, CreateDataAdviseHolder, StgCreateDocfile, OleRun, OleIsRunning, WriteClassStm, CreateILockBytesOnHGlobal, StgCreateDocfileOnILockBytes, StgIsStorageFile, StgOpenStorage, CreateOleAdviseHolder, OleSaveToStream, CoGetClassObject, OleLockRunning, CreateItemMoniker, GetRunningObjectTable, CreateFileMoniker, OleRegGetMiscStatus, OleRegGetUserType, OleRegEnumVerbs, CoDisconnectObject, CreateStreamOnHGlobal, OleGetClipboard, ReleaseStgMedium, RevokeDragDrop, CoLockObjectExternal, RegisterDragDrop, CoTaskMemFree, CoRevokeClassObject, CoRegisterClassObject, WriteClassStg, CoInitialize, CoCreateInstance, StgOpenStorageOnILockBytes, CoRegisterMessageFilter
> SHELL32.dll: ShellExecuteA, SHChangeNotify, DragQueryFileA, DragFinish, ShellExecuteExA, FindExecutableA, SHGetPathFromIDListA, SHBrowseForFolderA, DragQueryPoint, DragAcceptFiles, SHGetDesktopFolder, SHGetMalloc, SHGetFileInfoA, ExtractIconA
> comdlg32.dll: GetSaveFileNameA, PrintDlgA, GetFileTitleA, GetOpenFileNameA, CommDlgExtendedError
> WINSPOOL.DRV: EnumJobsA, ClosePrinter, GetPrinterDriverDirectoryA, GetPrinterDriverA, OpenPrinterA, DocumentPropertiesA, EnumPrintersA
> OLEAUT32.dll: -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -
> oledlg.dll: -
> BIB.dll: -, -
> ACELite.dll: -, -
> OPP.dll: -, -
> AGM.dll: -, -
> MPR.dll: WNetOpenEnumA, WNetEnumResourceA, WNetCloseEnum, WNetAddConnection2A, WNetGetConnectionA

( 0 exports )
LS Pekka
Hi MikeBOD!

Thanks for posting!
The object will be removed from detection as of the next definition file update.

Regards,

LS Pekka
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2010 Invision Power Services, Inc.