Help - Search - Members - Calendar
Full Version: Bd 2008 Alerting To Ipoint.exe Being A Trojan...
BitDefender Forum > English > Old Forum Topics > Malware Talk > False positive reporting
Canonman
This morning I received the following virus warning from BD 2008 stating that ipoint.exe is infected with Trojan.Patched.DB. Has anyone else had this issue. I honestly think that it is a false alarm, but I am unsure what I should do to verify. Any help would be great. I can extract the file from an older ghost image if I need to, but I would rather find a way to verify whether or not the file is corrupt.

Thanks
donjuan87
QUOTE (Canonman @ Oct 31 2008, 07:40 PM) *
This morning I received the following virus warning from BD 2008 stating that ipoint.exe is infected with Trojan.Patched.DB. Has anyone else had this issue. I honestly think that it is a false alarm, but I am unsure what I should do to verify. Any help would be great. I can extract the file from an older ghost image if I need to, but I would rather find a way to verify whether or not the file is corrupt.

Thanks


I have got the exact same problem and I dont no what to do. Can anybody help with this issue?
Canonman
I pulled the file out of 2 separate ghost images and they both show as being the same Trojan. Please note that the oldest of the 2 images contains the original MS software files from the exact day that I installed the new mouse and its driver and it still shows as a Trojan. I think that this is a false alarm. If we can get more people to simply scan the ipoint.exe file, we can see if this is a widespread issue or not.
Cris
Hello,

Please find the suspected file, put it in a password-protected ZIP archive, and attach the ZIP to your next post here.
Temporarily disable BD Realtime Protection so you can be able to access the file (so you can archive it) and re-enable it afterwards.

Cris.
Canonman
Here is the zip file as requested Chris. Thanks for taking the time to look at this.
bobjohan
I am having the same issue. I bought a new Microsoft desltop Laser keyboard and mouse combo. Bitdefender 2009 identifies ipoint.exe as having the Trojan.patched.db problem. I also went to the Microsoft site and downloaded the drivers and encounter the same problem.
David L
I'm a BD 2009 user and I'm having the same problem trying to set up Microsoft wireless keyboard and laser mouse. The setup aborts. Can I disengage Bitdefender, perform the installations and turn it back on?



Object Name Threat Name Final Status
E:\IPoint\Setup\Files\ipoint.exe Trojan.Patched.DB Disinfect Failed
Canonman
David L, I would think that you could simply disable the BD Real-time protection and then install the software; but I'm no expert. Don't forget to re-enable the Real-time protection once the software is installed.

For the moment, I have simply added the folder that contains ipoint.exe to the exceptions list. This was not a problem until 10-31-08 so it must be caused by a current virus definition file or other update. I was getting the file blocked every time that I logged on so my mouse was not working correctly; slow to move and very slow to scroll. As I previously mentioned, I added the "C:\Program Files\Microsoft IntelliPoint" folder to the exceptions listing and that seems to at least temporarily corrected the issue. However, I would think that BD would want to correct this issue ASAP. I would think that if it is indeed from a recent update, then we should see a large quantity of people with this problem. If the numbers do not increase then I would tend to think that we are having a unique issue that has only affected a small portion of the users.
Henrik H
QUOTE (Canonman @ Oct 31 2008, 10:40 AM) *
This morning I received the following virus warning from BD 2008 stating that ipoint.exe is infected with Trojan.Patched.DB. Has anyone else had this issue. I honestly think that it is a false alarm, but I am unsure what I should do to verify. Any help would be great. I can extract the file from an older ghost image if I need to, but I would rather find a way to verify whether or not the file is corrupt.

Thanks


Same problem here. I will wait till BD resolves the problem, then re-install the mouse. - Henrik
Cris
For Virus Analysts: The archive attached by Canonman has the password request (sent by PM).

@Canonman: the files posted on Malware Talk are private, and can be downloaded by Virus Analysts only. Password protection is required only to prevent gateway-antiviruses from corrupting the file (if they try to clean it) when you send it to the forum server. But you can write the password in your posts, so the Virus Analysts can use it to unpack the file.

Cris.
Catalin Salgau
The signature should now only detect a modified version of that file. Thank you for reporting.
Canonman
Good deal. Thanks for the help. Everything seems fine now.

Thanks again,
Canonman
Henrik H
QUOTE (Catalin Salgau @ Nov 3 2008, 02:56 PM) *
The signature should now only detect a modified version of that file. Thank you for reporting.


Thank you, installed it and it's working. - Henrik
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2009 Invision Power Services, Inc.