Welcome Guest Search | Active Topics | Members | Log In | Register

Virus found by Forefront when downloading RCF+ Options · View
ckirkland
Posted: Tuesday, September 22, 2009 1:12:12 PM
Rank: Member

Joined: 9/22/2009
Posts: 2
Location: Birmingham, AL
Category:
Worm

Description:
This program is dangerous and self-propagates over a network connection.

Advice:
Remove this software immediately.

Programs that may compromise your privacy or damage your computer were detected. You can still access the file without removing the threat, although this is not recommended. To do so, select "Always Allow" as the action and click the "Apply Actions" button. If this option is not available, log on as an administrator or ask an administrator for help.

Detected by:
Definition file

Resources:
file:
C:\Users\ckirkland\Desktop\r-c-f-plus.gadget->include/grcfplus.vbe->(EncScript)

file:
C:\Users\ckirkland\Desktop\r-c-f-plus.gadget->include/File.History->090921-1509.grcfplus.vbs

file:
C:\Users\ckirkland\Desktop\r-c-f-plus.gadget->include/File.History->090826-1112.grcfplus.vbs

file:
C:\Users\ckirkland\Desktop\r-c-f-plus.gadget->include/File.History->090824-1307.grcfplus.vbs

file:
C:\Users\ckirkland\Desktop\r-c-f-plus.gadget->include/File.History->090820-2117.grcfplus.vbs

file:
C:\Users\ckirkland\Desktop\r-c-f-plus.gadget->include/File.History->090818-2246.grcfplus.vbs

file:
C:\Users\ckirkland\Desktop\r-c-f-plus.gadget->include/File.History->090601-1128.rcf.vbs

containerfile:
C:\Users\ckirkland\Desktop\r-c-f-plus.gadget

View more information about this item online

Any thoughts?
-Clay
LeeLaboy
Posted: Tuesday, September 22, 2009 7:00:08 PM
Rank: Advanced Member

Joined: 5/21/2009
Posts: 14
Location: Menomonee Falls, Wisconsin
This is likely a false positive. I am having trouble trying to figure out why Forefront detects this as a virus but McAfee and AVG do not. I have scanned this gadget package with both anti-virus products and it comes up clean. Only Forefront is reporting this as a virus - frustrating!

Can you try this again? I removed the file.history files from the gadget could you see if that helps? Let me know your results again. Thanks.


Lee M. Laboy

ScriptingPod.com
ckirkland
Posted: Wednesday, September 23, 2009 9:18:48 AM
Rank: Member

Joined: 9/22/2009
Posts: 2
Location: Birmingham, AL
Thanks for your response, Lee.

I downloaded it again and the same thing happens. I even tell forefront to ignore it and when I install the gadget I get a message that says "unable to load 'c:\......\r-c-f-plus.gadget'." All the machine inside our domain have Forefront so I can't install it as long as this keeps happening. I had been using v1.25 but I wanted to try out the new features.

Thanks,
-Clay

Here's the info from Forefront

Category:
Worm

Description:
This program is dangerous and self-propagates over a network connection.

Advice:
Remove this software immediately.

Programs that may compromise your privacy or damage your computer were detected. You can still access the file without removing the threat, although this is not recommended. To do so, select "Always Allow" as the action and click the "Apply Actions" button. If this option is not available, log on as an administrator or ask an administrator for help.

Detected by:
Definition file

Resources:
file:
C:\Users\ckirkland\AppData\Local\Microsoft\Windows Sidebar\Gadgets\r-c-f-plus.gadget.~0000\include\grcfplus.vbe->(EncScript)

containerfile:
C:\Users\ckirkland\AppData\Local\Microsoft\Windows Sidebar\Gadgets\r-c-f-plus.gadget.~0000\include\grcfplus.vbe

Summary:
On Access Protection change occurred.

This agent scans software just before it runs. You are alerted if the software has a high potential for harming your computer.

Checkpoint:
On Access Antivirus Protection

View more information about this item online

ldp711
Posted: Wednesday, September 23, 2009 2:34:05 PM
Rank: Member

Joined: 9/23/2009
Posts: 1
Location: USA
I have the same problem with Forefront, really enjoyed the first version. I hope 2.0 gets fixed soon...
wilsonchris
Posted: Tuesday, October 06, 2009 10:25:01 AM
Rank: Member

Joined: 10/6/2009
Posts: 1
Location: Arlington, VA
ldp711 wrote:
I have the same problem with Forefront, really enjoyed the first version. I hope 2.0 gets fixed soon...


I can report the same behaviour with ForeFront. I just downloaded it today, and upon trying to install it, it reportled detects the worm. Like you said, it's likely a false positive, but it's preventing installation on clients with ForeFront.

FYI, I have another computer that already had RCF installed BEFORE ForeFront was rolled out, and that installation/program still works great. It's just that I can no longer install RCF on "fresh" computers that already have ForeFront.

Thanks,
Chris
Users browsing this topic
Guest


Forum Jump
You cannot post new topics in this forum.
You cannot reply to topics in this forum.
You cannot delete your posts in this forum.
You cannot edit your posts in this forum.
You cannot create polls in this forum.
You cannot vote in polls in this forum.

Main Forum RSS : RSS

SoClean Theme Created by Jaben Cargman (Tiny Gecko)
Powered by Yet Another Forum.net version 1.9.1.8 (NET v2.0) - 3/29/2008
Copyright © 2003-2008 Yet Another Forum.net. All rights reserved.
This page was generated in 0.537 seconds.