PDA

View Full Version : Fixed: False positive: Fraud.Antivirus 2008



essami
2009-05-01, 12:03
Hi,

Running Windows Vista 64bit with Spybot 1.6.2.46.

I think this is a false positive:

Fraud.Antivirus2008: [SBI $53DB054A] Settings (Registry key, nothing done)
HKEY_USERS\S-1-5-21-1892808302-3848776602-329337650-1000\Software\AAV

This registry entry is for a video editing color correction plugin AavcolorLabPP.

Thanks,

Sami

Yodama
2009-05-04, 09:52
thank you for reporting this false positive, it will be corrected with the next detection update scheduled for Wednesday 2009-05-06

essami
2009-05-04, 20:14
Thanks Yodama,

Im having a problem. Antibot deleted some HKEY files apparently in regards to this plugin and now I cant use, repair or uninstall it.

I tried recovering the HKEY files with Spybot and it did it but it didnt help. The uninstall program says:

Could not open key:
HKEY_CURRENT_USER32\Software\AAV\AAVColorLab 1.0
rc1\{9871239871309....etc}

Any ideas on how to get this back to a working state?

Sami

essami
2009-05-04, 22:29
OK, new info, I think Spybot put back the files but lost some info. See here how there are no groups, administrator or my user name available to change permissions. I dont know how to add them back. Any help would be appreaciated.

Thanks!

Sami

Yodama
2009-05-05, 07:45
Click on the "add..." button below the "group or user names" field. On the next prompt you can directly enter the groups and users seperated by semicolon.
For instance: Administrators;User1;User2;
Once added you can set the permissions for each user group or user.

essami
2009-05-05, 10:13
Hi

It adds the users but when trying to save the permissions it says

"unable to save permission changes on AAV ColorLAb 1.0 rc1.
Access is denied"

Any further ideas how resolve this problem?

Thanks,

Sami

essami
2009-05-05, 10:48
OK got it!

right-click the key which access has been denied, choose permissions..., click advanced, click owner tab, change owner to your own account, click apply and then repeat for the revealed subkeys.

Now everything works a-ok.

Sami