Page 2 of 2

Posted: Sun Jan 03, 2010 12:47 pm
by olugu
Datei ProgDVB6.30Std.exe empfangen 2010.01.03 12:12:19 (UTC)

Ergebnis: 5/40 (12.5%)

Antivirus Version letzte aktualisierung Ergebnis

Avast 4.8.1351.0 2010.01.02 Win32:Malware-gen
AVG 8.5.0.430 2010.01.02 IRC/BackDoor.SdBot4.PIZ

GData 19 2010.01.03 Win32:Malware-gen
Ikarus T3.1.1.79.0 2009.12.31 Backdoor.Bot

McAfee+Artemis 5849 2010.01.02 Artemis!88254D556CA7






Avira AntiVir Personal Virus Definition 7.10.02.111 (01.01.2010)
Erstellungsdatum der Reportdatei: Sonntag, 3. Januar 2010 13:28

Beginne mit der Suche in 'E:\dls\ProgDVB6.30Std.exe'
E:\dls\ProgDVB6.30Std.exe
[0] Archivtyp: NSIS
--> ProgramFilesDir/PidRecorder.Module
[FUND] Enthält ein Erkennungsmuster des (gefährlichen) Backdoorprogrammes BDS/Bot.111303



Beginne mit der Suche in 'E:\dls\ProgDVB6.25.1Std.exe'
E:\dls\ProgDVB6.25.1Std.exe
[0] Archivtyp: NSIS
--> ProgramFilesDir/PidRecorder.Module
[FUND] Enthält ein Erkennungsmuster des (gefährlichen) Backdoorprogrammes BDS/Bot.111303




Beginne mit der Suche in 'H:\dls\ProgDVB6.23.1Std.exe'
0 Viren bzw. unerwünschte Programme wurden gefunden

AVAST! Antivirus

Posted: Sun Jan 03, 2010 10:27 pm
by cynik909
AVAST! Antivirus - the same problem:
Sign of "Win32:Malware-gen" has been found in "http://update-progdvb.com/download/Prog ... der.Module" file.
Virus database from 3.01.2010.

Please resolve it.

.

Posted: Mon Jan 04, 2010 7:54 am
by Prog
2 all users: Please mail about this problem to avast and avira. It is bug of antivirus and I am not can fix that on my side.

false alarm

Posted: Mon Jan 04, 2010 6:17 pm
by Rschnauzer
Prog wrote:...Please mail about this problem to avast and avira. It is bug of antivirus and I am not can fix that on my side.
I reported this to Avira but did not get a final answer about false alarm.

Can you give me an answer, what the modules PidRecorder.Module and TBS.eBDA are doing and under which condition these are called?

.

Posted: Mon Jan 04, 2010 6:26 pm
by Prog
Module for recording and some BDA module for TBS. Both module is total simple and small. Without keyboard hooks or other system functions.


ps: Some antivirus can detect spy in HID module, because it use hook for keyboard.

Posted: Mon Jan 04, 2010 8:04 pm
by Rschnauzer
@Prog: thanks

Posted: Mon Jan 04, 2010 10:19 pm
by cynik909
Hi Prog,
Of course yesterday I have reported false alarm to AVAST!

***************************************************
EDIT:
Good evening,
In virus database of AVAST! from 5.01.2009 this issue is corrected.

Best regards

Posted: Wed Jan 06, 2010 12:25 pm
by sroc
The heuristic alarm in Avira is gone with the current update, so everything's back to normal.