ClamWin Free Antivirus Forum Index
ClamWin Free Antivirus
Support and Discussion Forums
Reply to topic
NVidia drvr nForce4/500series -W2K/XP,= Trojan.Agent-51606 ?
buyerninety


Joined: 03 Jan 2013
Posts: 0
Location: ************
Reply with quote
This seems rather unlikely so I'll run it by the forum first.
nVidia driver for the nforce4/500 series chipsets for W2K/XP, Version 6.86,
downloadable through here;
https://www.nvidia.com/object/nforce_nf4_win2k_6.86.html
"Primary Download Site" leads to here;
https://www.nvidia.com/content/license/location_0605.aspx?language=&url=https://download.nvidia.com/Windows/nForce/standalone/6.86/6.86_nforce_win2kxp_international_whql.exe
Clicking the Licence "Accept" button downloads this driver file;
6.86_nforce_win2kxp_international_whql.exe
Running ClamWin [specifically ClamAV 0.97.1 , Virus DB version (main:54;daily:16318)] on
a Windows ME 4.90.3000 system, identifies that driver file as "WIN.Trojan.Agent-51606 FOUND".
Also, downloading that file through this;
ftp://download.nvidia.com/Windows/nForce/standalone/6.86/6.86_nforce_win2kxp_international_whql.exe
also gives the same virus infection found.
The system finds Trojan.Agent-51606 only in that file on my home PC.
I have never run the file (the drvr is not for my home PC, but rather another I had
intended to start-up sometime in the future).
The file is a bit larger than 42Mb, but downloads fairly snappily.
As a quick control test, I immediately downloaded a different file;
nForce4/500 series - Windows XP Professional x64, version 6.86
through;
https://www.nvidia.com/content/license/location_0605.aspx?language=&url=https://download.nvidia.com/Windows/nForce/standalone/6.86/6.86_nforce_winxp64_international_whql.exe
to check if maybe something on my home PC was adding the virus to downloaded exe's,
the result was that '6.86_nforce_winxp64_international_whql.exe' not found to have the virus!
COULD SOMEONE download the file giving the 'Trojan.Agent-51606' result to check if
they also get that result, hopefully someone with a Windows ME system will also try.
(Note; I only downloaded from the "Primary Download Site" & also FTP as above, didn't
try from the three mirror sites.)
Cheers
P.S if it's a real virus on NVIDIA download site, feel free to claim glory & informing
rights for it yourself.
View user's profileSend private message
GuitarBob


Joined: 09 Jul 2006
Posts: 9
Location: USA
Reply with quote
From what you said, it's probably a false positive. There have been a lot of them lately for Trojan.Agents. We used to be able to give large false positive files to one of the original Clam AV team, but I don't know if that is still possible with Sourcefire running things now. Joel Esler is the open source rep at Clam AV now. I'll reference this post to him.

I suggest that you upgrade to the latest version of ClamWin from the ClamWin web site, since detection between versions can sometimes vary. If the date of that file hasn't changed since you put it on the computer, it is probably okay. I don't see many viruses in files that large.

Regards,
View user's profileSend private message
GuitarBob


Joined: 09 Jul 2006
Posts: 9
Location: USA
Reply with quote
You can send files that are too large to submit thru the Clam AV submission system to Alain zidouemba at Sourcefire. That is azidouemba at sourcefire dotcom (I am showing the address differently to stymie any robots mining for email addresses here).

Keep in mind that the Sourcefre personnel have other duties, and they will process false positives as soon as possible.

By the way, you can scan files up to 40 megabytes in size with Metascan at https://www.metascan-online.com/en on the web.

Regards,
View user's profileSend private message
NVidia drvr nForce4/500series -W2K/XP,= Trojan.Agent-51606 ?
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
All times are GMT  
Page 1 of 1  

  
  
 Reply to topic