buyerninety
Joined: 03 Jan 2013 |
Posts: 0 |
Location: ************ |
|
 |
Posted: Thu Jan 03, 2013 11:21 am |
|
 |
 |
 |
 |
This seems rather unlikely so I'll run it by the forum first.
nVidia driver for the nforce4/500 series chipsets for W2K/XP, Version 6.86,
downloadable through here;
https://www.nvidia.com/object/nforce_nf4_win2k_6.86.html
"Primary Download Site" leads to here;
https://www.nvidia.com/content/license/location_0605.aspx?language=&url=https://download.nvidia.com/Windows/nForce/standalone/6.86/6.86_nforce_win2kxp_international_whql.exe
Clicking the Licence "Accept" button downloads this driver file;
6.86_nforce_win2kxp_international_whql.exe
Running ClamWin [specifically ClamAV 0.97.1 , Virus DB version (main:54;daily:16318)] on
a Windows ME 4.90.3000 system, identifies that driver file as "WIN.Trojan.Agent-51606 FOUND".
Also, downloading that file through this;
ftp://download.nvidia.com/Windows/nForce/standalone/6.86/6.86_nforce_win2kxp_international_whql.exe
also gives the same virus infection found.
The system finds Trojan.Agent-51606 only in that file on my home PC.
I have never run the file (the drvr is not for my home PC, but rather another I had
intended to start-up sometime in the future).
The file is a bit larger than 42Mb, but downloads fairly snappily.
As a quick control test, I immediately downloaded a different file;
nForce4/500 series - Windows XP Professional x64, version 6.86
through;
https://www.nvidia.com/content/license/location_0605.aspx?language=&url=https://download.nvidia.com/Windows/nForce/standalone/6.86/6.86_nforce_winxp64_international_whql.exe
to check if maybe something on my home PC was adding the virus to downloaded exe's,
the result was that '6.86_nforce_winxp64_international_whql.exe' not found to have the virus!
COULD SOMEONE download the file giving the 'Trojan.Agent-51606' result to check if
they also get that result, hopefully someone with a Windows ME system will also try.
(Note; I only downloaded from the "Primary Download Site" & also FTP as above, didn't
try from the three mirror sites.)
Cheers
P.S if it's a real virus on NVIDIA download site, feel free to claim glory & informing
rights for it yourself.
|
|
GuitarBob
Joined: 09 Jul 2006 |
Posts: 9 |
Location: USA |
|
 |
Posted: Thu Jan 03, 2013 2:04 pm |
|
 |
 |
 |
 |
From what you said, it's probably a false positive. There have been a lot of them lately for Trojan.Agents. We used to be able to give large false positive files to one of the original Clam AV team, but I don't know if that is still possible with Sourcefire running things now. Joel Esler is the open source rep at Clam AV now. I'll reference this post to him.
I suggest that you upgrade to the latest version of ClamWin from the ClamWin web site, since detection between versions can sometimes vary. If the date of that file hasn't changed since you put it on the computer, it is probably okay. I don't see many viruses in files that large.
Regards,
|
|
GuitarBob
Joined: 09 Jul 2006 |
Posts: 9 |
Location: USA |
|
 |
Posted: Thu Jan 03, 2013 6:10 pm |
|
 |
 |
 |
 |
You can send files that are too large to submit thru the Clam AV submission system to Alain zidouemba at Sourcefire. That is azidouemba at sourcefire dotcom (I am showing the address differently to stymie any robots mining for email addresses here).
Keep in mind that the Sourcefre personnel have other duties, and they will process false positives as soon as possible.
By the way, you can scan files up to 40 megabytes in size with Metascan at https://www.metascan-online.com/en on the web.
Regards,
|
|