PDA

View Full Version : possible false positive from anti-virus


glo_kidd
05/12/2007, 10:53 pm
Hi all, today when booting up my pc i got a warning from my Anti-virus (telus) saying the following:

A virus has been found

virus name:
W32/Downloader.DHA

Infected file:
D:\PROGRAM FILES\TELLTALE GAMES\SAM AND MAX - ABE LINCOLN MUST DIE\UNINSTALL SAM AND MAX - ABE LINCOLN MUST DIE.EXE

details:
The file couldn't be disinfected, and was deleted instead. Run the virus scan to verify that other files on your system are not infected.


Im pretty much 100% sure that this must be a false positive, i mean if you cant trust telltale who can you :P I just thought that i should let you guys know.

Also it seems that i no longer have the UNINSTALL SAM AND MAX - ABE LINCOLN MUST DIE.EXE file on my computer which will make it hard to unninstall when the need arises, should i still be able to do this with the add/remove progams dialog? or can i just get a replacement for the file itself?

jmm
05/12/2007, 11:40 pm
It looks like it. That virus is an "old" (2005) trojan. Just to be sure:

a) Check your registry.
Go to:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Curr entVersion\Run
If you find an entry called ".svchost" (note the point)
which points to %SYSTEMROOT%\System\CSRSS.EXE (Replace %SystemRoot% with the directory where you installed Windows)

b) Search for a file called 'UDP_0001.exe' (number could change), at C:\TEMP

c) Search for a file named CSRSS.EXE at C:\Windows\System (change the disk drive with your windows disk) If you have Windows 2000/XP and you have that file at the System folder then it is a virus, do not attempt to delete the file on the System32 folder (This is a key OS file!)

If you find any of those your system is infected.

glo_kidd
05/13/2007, 12:26 am
okay thanks for the tips :D
i checked in all the places you mentioned and it all checks out, my system seems fine, ive had a few bizzare false positives with this isp specific anti-virus
Hopefully i can figure out how to uninstall when the time comes, but i dont think that will be anytime soon
Thanks Again :D

tabacco
05/13/2007, 09:57 am
You should be able to reinstall the game to restore the uninstall app.