PDA

View Full Version : Fixed: False Positive ? Win32.Luder.B?



JackSnap
2011-03-31, 19:42
I have only spybot reporting I have this malware?
No others report the same files as infected.

I have also tried scanning from a confirmed non infected boot CD.

Spybot is the only one that reports thise infection, even copying clean files from another machine and then re-scannng on mine reports the infection again.

If you want me to provide the files I can , im almost certain its a flase positive?

Jacksnap

tashi
2011-03-31, 21:03
Hello JackSnap,

How to report Possible False Positives (http://forums.spybot.info/showthread.php?t=19117)

Best regards. :)

Yodama
2011-04-01, 09:51
there is a high probability for false positives in this case, to make sure please send in the files in question for analysis to detections@spybot.info with a reference to this thread.

Yodama
2011-04-01, 13:11
received files and logs from user, confirmed false positive.

Fix for detection rules will be released with next detection update scheduled for Wednesday 2011-04-06.

JackSnap
2011-04-01, 18:11
Many Thanks,

I will download the updates on wednesday/Thursday and run the exact same check, just to confirm.

Thanks again

Jacksnap

doriang
2011-04-03, 15:36
Hi there,
I think I may have created a potential problem for myself.

I did delete Win32.luder.B when it was highlighted by Spybot.

Would you please advise the implications of this (what this file is there for, what it does, how potential problems may arise, etc.) and how I am able to repair this (where I'm able to get a replacement file; where it's situated, how to go about it, etc.).

For some odd reason, there is no back-up in Spybot so I'm not able to restore it by using the Spybot software.

Thanking you in anticipation.

With kind regards,
Dorian

Yodama
2011-04-04, 10:14
@doriang
if you had the same findings as JackSnap, the files should have been restored by Windows itself so there should not be any need to recover the files.

JackSnap
2011-04-07, 19:46
Many Thanks

The latest updates didnt detect anything at all. looks like the false positive has cleared.


Great software!
Jacksnap