Help - Search - Members - Calendar
Full Version: Gen:trojan.heur.564e44? File Incriminated Nil32.dll
BitDefender Forum > English > Old Forum Topics > Malware Talk > False positive reporting
depassage
Hi!
Got this so called Trojan bloked as I tried to load Civilisation III from Infogrammes.
I know it cannot come from the game, as I have reinstalled it, and BDF still blocks it. I think it is a false positive, but I cannot do anything about it as the "suspicious" file is created at the application launch.
Therefore I cannot even send the file NIL32.dll.
Also, this Trojan appears on your German subjects bank with a de"scription link, but detail link for this subject isn't working: http://forum.bitdefender.com/index.php?showtopic=11283

Question: is this not obviously a false positive? If this is the case, how do I go about solving the problem in order to plan Civilisation III?
If it is indeed a Trojan, how come it pops up with the launching of Civilisaation III?
Thank you for your feedback.
depassage
QUOTE (depassage @ Jan 12 2009, 12:54 PM) *
Hi!
Got this so called Trojan bloked as I tried to load Civilisation III from Infogrammes.
I know it cannot come from the game, as I have reinstalled it, and BDF still blocks it. I think it is a false positive, but I cannot do anything about it as the "suspicious" file is created at the application launch.
Therefore I cannot even send the file NIL32.dll.
Also, this Trojan appears on your German subjects bank with a de"scription link, but detail link for this subject isn't working: http://forum.bitdefender.com/index.php?showtopic=11283

Question: is this not obviously a false positive? If this is the case, how do I go about solving the problem in order to plan Civilisation III?
If it is indeed a Trojan, how come it pops up with the launching of Civilisaation III?
Thank you for your feedback.


Hi,

I've just seen that I forgot to send you the file. So here is a copy of the file and its attachement in the quarantine folder.
Also, I've seen this lab has also been working on it: http://analysis.avira.com/samples/details....cidentid=166543

Thank you in advance for the follow up.
Regards.
danton
We're working on it. Thanks for the report.
depassage
QUOTE (danton @ Jan 13 2009, 01:01 PM) *
We're working on it. Thanks for the report.


Thank you for keeping me posted. Good work.
danton
QUOTE (depassage @ Jan 13 2009, 12:03 PM) *
Thank you for keeping me posted. Good work.

Detection will be removed after next update. That should be in a few hours.
Have a nice day!
depassage
QUOTE (danton @ Jan 13 2009, 01:26 PM) *
Detection will be removed after next update. That should be in a few hours.
Have a nice day!


Thanks Danton. Euh, question: do you also cut off heads? lol!
Have a nice day!
Chris

P.S.: how do I close post with resolved?
danton
QUOTE (depassage @ Jan 13 2009, 12:29 PM) *
Thanks Danton. Euh, question: do you also cut off heads? lol!
Have a nice day!
Chris

P.S.: how do I close post with resolved?

I cut off heads only when I'm really pissed. smile.gif
Don't worry about the topic/post.
depassage
QUOTE (danton @ Jan 13 2009, 01:35 PM) *
I cut off heads only when I'm really ######. smile.gif
Don't worry about the topic/post.


OK Thanks Danton. Keep up the good work and humour!
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2009 Invision Power Services, Inc.