NIS says Avanquest website has virus

When I went to the Avanquest.com website to check something about its Driver Genius product on my PC, NIS opened a window cautioning that it was infected!  Even stranger, the details section pointed to a filename on my HD but listed it's location as the Avanquest website:

 

Threat Name: Trojan Horse

File name: c:\program files\driver-soft\drivergenius\is-7e475.tmp

Location: http://download4.avanquestXcom/file.php?id=55f0f03482121b1b7bf0a50eaf80ccb22694626

 

I'm using NIS 16.7.2.11 on Vista 64-bit Home Premium edition.

 

What's going on here?  Tell me this is a false positive!  Do I need to do anything?

 

 

[edit:Please do not post hazardous links per the Participation Guidelines and Terms of Service.]

Message Edited by shannons on 11-17-2009 07:55 PM

HI mazorj,

 

Welcome to Norton Community!

 

In rare cases where a legitimate file has been misidentified and subsequently quarantined, your computer may behave abnormally or you may find that one or more applications no longer function as expected. In such rare situations, you should open the Quarantine in your antivirus product. From here, you may review the list of all files detected as dangerous/threats and, if you identify a potential misidentification, restore the file from quarantine and allow it to run normally. If you are sure about the authenticity of the file, and confident that it is a false positive, then submit that file(is-7e475.tmp) to Symantec:

https://submit.symantec.com/false_positive/index.html

 

If it is found clean during the analysis by Symantec Security response and can be trusted as authenticated one, then Symantec will update the definitions for the detection to exclude those files and then release a patch with updated definition(white list). So, after that LiveUpdate patch, Norton program won't detect it as dangerous/threat.

 

Yogesh

Message Edited by yogesh_mohan on 11-18-2009 05:33 AM

Hi mazorj,

 

If you think that the website has been labelled as a false positive, please report it over here to Symantec:

https://submit.symantec.com/antifraud/false_positive.cgi

Message Edited by Yaso_Kuuhl on 11-18-2009 01:03 AM

I can confirm that, not jsut on the French Avanquest your link went to but the one I normally use where it came up on the www.avanquest.com front page.

 

For some reason Irfanview is not being allowed to make the screenshot but here's the guts:

 

 


                  
                  
                  
  Viruses (what's this?)
Threats found: 1
Here is a complete list:             
  Threat Name:  Trojan Horse            
  File name:  c:\program files\driver-soft\drivergenius\is-7e475.tmp            
  Location:  download4.avanquestXcom/file.php?id=55f0f03482121b1b7bf0a50eaf80ccb22694626            
  
 
         
©1995-2009 Symantec Corporation
about
privacy policy
terms of service
492b9b7c60c6c335406e38ff9d11769d0438b5d5
3.0.33-49

More later when I come back on line -- dinner calls!

 

[edit: Fixed link in quote.]

Message Edited by shannons on 11-17-2009 07:58 PM

huwyngr wrote:

I can confirm that, not jsut on the French Avanquest your link went to but the one I normally use where it came up on the www.avanquest.com front page.

 

For some reason Irfanview is not being allowed to make the screenshot but here's the guts:

 


       
 Viruses (what's this?)
Threats found: 1
Here is a complete list:             
  Threat Name:  Trojan Horse            
  File name:  c:\program files\driver-soft\drivergenius\is-7e475.tmp            
  Location:  download4.avanquestXcom/file.php?id=55f0f03482121b1b7bf0a50eaf80ccb22694626            
  
 
         
©1995-2009 Symantec Corporation
about
privacy policy
terms of service
492b9b7c60c6c335406e38ff9d11769d0438b5d5
3.0.33-49

More later when I come back on line -- dinner calls!

Well, I'm impressed!  Three responsive replies within minutes!  Thanks to all.

 

I hadn't bothered to follow the link that NIS identified - how odd that it went to the French version of the Avanquest website!  Maybe that's a clue to the problem, since I'm a U.S. user registered in English.

 

For now I will consider it a false positive and report it back to Norton as such, using the link provided here.  If nothing else pops up to interfere, I'll come back and mark it Solved.  Again, thanks much.

 

[edit: Fixed link.]

 

Message Edited by shannons on 11-17-2009 08:00 PM

I went to http://www.avanquest.com/ but since  Avanquest is a French company it is possible that their download servers are in France.

 

Please let Symntec know because they know Avanquest only too well -- there's a long history of a context menu crash with Norton 360 that everyone was blaming on Norton, including Microsoft, which in the end turned out to be an out of date bit of programming code in one of the Avanquest utilities -- PowerDesk -- that some of us use as a file manager. It turned up in one or two other applications from other sources too!


huwyngr wrote:

I went to http://www.avanquest.com/ but since  Avanquest is a French company it is possible that their download servers are in France.

 

Please let Symntec know because they know Avanquest only too well -- there's a long history of a context menu crash with Norton 360 that everyone was blaming on Norton, including Microsoft, which in the end turned out to be an out of date bit of programming code in one of the Avanquest utilities -- PowerDesk -- that some of us use as a file manager. It turned up in one or two other applications from other sources too!


Another PowerDesk fan!  I started with it in 4.0, have followed it all the way to 7.0, and wish they had kept it up instead of orphaning it a few years ago.  It's still my go-to disk manager despite a few problems - like when its ZIP extractor suddenly and inexplicably went whacky two months ago and I had to get Stuff-It for opening ZIPs and doing archiving work.  If they'd fix these few minor quirks, I'd buy an 8.0 in a heartbeat - at full list!  Even with the quirks, it's still the first app I load after booting.  Except for the extra context links you sometimes get in a Windows Explorer window, PD is far superior for doing nuts-and-bolts file work.

 

Anyway, to stay on topic:  Yeah, I realized later that Avanquest's servers are in France.  That still doesn't explain why NIS went "j'accuse" to the Driver Genius file on my HD, or tied it to a presumably clean server in France.

Yes I wish they'd kept updating PowerDesk -- or Symantec brought back Norton Desktop for Windows <g>

 

Have you notified Symantec of the problem?

 

I just checked and it's still flagged -- my URL is said to be in the UK <s>

 

I found out why my Irfanview hotkey didn't --- the keyboard had turned off it's F key active and switched to the alternative media row!

 

Here are the two parts of the detailed screen.

 

I suppose one could download the file and then use the context menu to check it -- if NIS didn't quarantine/delete it first?capture_18112009_102413.jpg

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

capture_18112009_102459.jpg