derekgale Posted July 9, 2010 Report Posted July 9, 2010 Hi,Just run a virus scan with the current (9.0.839) Pro version of AVG, and it's moved 19 of my PTE (made with v.5.6) .exe files to the Virus Vault. It says they have a Trojan Horse infection with "BackDoor.Hupigon5.BAKO". I've read that AVG does generate false positives from time to time. Is this another one?If not, what do I do? Just restore them to their original location?ThanksDerek. Quote
Ken Cox Posted July 9, 2010 Report Posted July 9, 2010 SEEhttp://www.virustotal.com/http://www.picturestoexe.com/forums/index.php?showtopic=11558&pid=74909&st=20entry74909KEN Quote
Ken Cox Posted July 9, 2010 Report Posted July 9, 2010 I JUST UPDATED MY AVG9.0.830_271.1.1/2991 _ JULY 9 07:55 EDSTRAN TESTS ON RECENT AND VERY OLD EXE'S AND ALL TESTED OKKEN Quote
derekgale Posted July 10, 2010 Author Report Posted July 10, 2010 Ran one of the "infected files" on Virustotal and about 3 or 4 picked up the presence of the Trojan; most recorded nothing. What does this mean?Moved "infected" files back from Virus Vault and rescanned. AVG picked up the same files as before as "infected". Clicked on link to AVG for more information about the Trojan, and I get a message saying it's not in their Virus Encyclopedia. How can that be if the program is finding it?Derek. Quote
Ken Cox Posted July 10, 2010 Report Posted July 10, 2010 did you update AVG? to latest version --do so and rerundo you still have ver 5.6?do you still have the original components -- re make the exe and retestseems strange that it " Ran one of the "infected files" on Virustotal and about 3 or 4 picked up the presence of the Trojan; most recorded nothing. What does this mean?"infected files -- what files - the exe'sseparate the ones that are saying ok from the rest onto different foldersyour statements are not making sense to me if you could supply screenshots of the affect files it may helpken Quote
Ken Cox Posted July 10, 2010 Report Posted July 10, 2010 you could also do a free "on Line " scan from herehttp://housecall.trendmicro.com/and see what turns upken Quote
derekgale Posted July 13, 2010 Author Report Posted July 13, 2010 "did you update AVG?to latest version --do so and rerun"I am using the latest updates to AVG. Same problem - a number of apparently infected .exe files "do you still have ver 5.6?do you still have the original components -- re make the exe and retest"I'm still using v 5.6, and have had no virus problems in the past. I don't really want to spend lots of time rebuilding the sequences and then remaking the .exe files. Many of the original image folders have been moved, renamed or archived."you could also do a free "on Line " scan from here http://housecall.trendmicro.com/ and see what turns up"AVG moved the files it flagged as "Infected" to the Virus Vault. I have restored those files to the folder they were in before AVG moved them. I've then scanned that folder with House Call - no threats were found.I have now got the same problem on my laptop. I turned it on today after a couple of weeks not using it, and AVG did a big update. AVG has now "found" the Trojan in some .exe files and won't let me run them. I have had no problems on my laptop before this update. I cannot have a machine that won't let me run these files, as I use these .exe files in talks that I give. I have disabled AVG's Resident Shield feature (and turned off my Internet Connection),and that allows me to run the .exe's. Not a good long term measure.It's clear to me that AVG is generating a false positive for this Trojan. Quote
Ken Cox Posted July 13, 2010 Report Posted July 13, 2010 TRY the latest pte beta 6.5 b10make a show from an archived filethen run avg on that exe and see what happensyou have pro version so you get free support from AVG - have you contacted them?ken Quote
fh1805 Posted July 13, 2010 Report Posted July 13, 2010 This sounds very similar to what happened when Symantec introduced their SONAR technology in Norton Internet Security 2010. Lot's of false detections because of code that was attempting to second-guess what might be a virus rather than identifying what definitely was a virus.regards,Peter Quote
Ken Cox Posted July 13, 2010 Report Posted July 13, 2010 i found a folder cw the exe in itthe file was made with 5.6.4I just ran a scan with latest avg free 9.0.830 271.1.1/3002tested cleanfyiwebsite: http://www.avg.commailto: support@avg.com ken Quote
Ken Cox Posted July 13, 2010 Report Posted July 13, 2010 some history of the problem herehttp://www.picturestoexe.com/forums/index.php?showtopic=5434ken Quote
Mike Reed Posted July 16, 2010 Report Posted July 16, 2010 Hi AllI have just upgraded my AVG virus software on my lap top and am now told that I have a bucket full of Trojans known as Backdoor Hupigon5 BAKO. They all seem to relate to previous exe files of sequences I have made. Does anybody have knowledge of this beastie or is it the usual anti virus awareness of exe files?Mike Reed Quote
Ronniebootwest Posted July 16, 2010 Report Posted July 16, 2010 Hi Mike,This sounds like the usual problem of 'False Positives' that AVG is fond of reporting. One of the reasons that I have switched to using the free version provided by 'Avast' thier latest version is much improved.You seem to have quadrupled your post, perhaps you could delete the other three!Ron Quote
Igor Posted July 16, 2010 Report Posted July 16, 2010 I just intalled latest AVG free antirus and it doesn't show false positives for any executable slideshow created in version 5.6 (all revisions from 5.6.0 to 5.6.4).Here you can download and test these slideshows:http://www.wnsoft.com/test/Slideshows_560.zip (3 MB)Please make sure that latest updates are installed.Could you please upload your sample slideshow into Mediafire.com I'll check up again.If it possible write to AVG company to inform them about this false positive with PicturesToExe's slideshows. Quote
Ken Cox Posted July 16, 2010 Report Posted July 16, 2010 please see Igors entry re test fileshttp://www.picturestoexe.com/forums/index.php?showtopic=12096ken Quote
Mike Reed Posted July 17, 2010 Report Posted July 17, 2010 Hi IgorI see that Derek gale has also reported this problem with AVG Pro. HIs explanation is exactly what I experienced. It would seem that AVG are reporting false positives with PTE exe files. I will report this matter to AVG.Ronnie I cannot see that my message has been repeated three times.Thanks allMike Reed Quote
Mike Reed Posted July 17, 2010 Report Posted July 17, 2010 Hi DerekI too use AVG pro on my lap top and have experienced exactly the same problem as you. It followed an AVG update when the lap top was turned on after a week or so of non use.As my lap top is rarely connected to the web and until this upgrade showed no signs of problems for now I shall ignore the advice report the matter to AVG and hope for the best. You are right the Trojan does not show in AVGs dictionary of viruses so how can they detect it I ask myself!MIke Reed Quote
Mike Reed Posted July 21, 2010 Report Posted July 21, 2010 Hi AllAVG have confirmed to me on the 19th july that the Trojan Derek and I picked up was indeed a false positive. They say that it will be removed on the next Definitions update.Mike Reed Quote
derekgale Posted July 30, 2010 Author Report Posted July 30, 2010 Haven't looked at this thread for a little while.I sent one of the "infected" files to AVG for analysis; heard nothing back from them.A scan yesterday did not pick up any infection, so clearly it was a false positive. Thanks for all your help Mike.Cheers,Derek. Quote
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.