PDA

View Full Version : Fixed: Definite false positive Win32.Agent.yjl



DavidWHodgins
2012-06-22, 04:19
XP Pro Service pack 3
Search & Destroy version: 1.6.2 (build: 20090126)
Last update today, just before scan.

Win32.Agent.yjl: [SBI $07E4AFDB] Text file (File, nothing done)
c:\ip.txt
Properties.size=2108
Properties.md5=77467D2DCA32C518DCC29D817297B382
Properties.filedate=1228941552
Properties.filedatetext=2008-12-10 16:39:12

The file contains the output of "ifconfig -a", and "route -n", run on my linux
system, copied to the c: drive, so I would have the info available in windows,
after I replaced a failing router. The full contents of that file ...
C:\>type ip.txt
br0 Link encap:Ethernet HWaddr 00:11:5B:C2:BB:E9
inet addr:192.168.10.101 Bcast:192.168.10.255 Mask:255.255.255.0
inet6 addr: fe80::211:5bff:fec2:bbe9/64 Scope:Link
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:62 errors:0 dropped:0 overruns:0 frame:0
TX packets:104 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:0
RX bytes:12918 (12.6 KiB) TX bytes:9459 (9.2 KiB)

eth0 Link encap:Ethernet HWaddr 00:11:5B:C2:BB:E9
inet6 addr: fe80::211:5bff:fec2:bbe9/64 Scope:Link
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:164 errors:0 dropped:0 overruns:0 frame:0
TX packets:100 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:1000
RX bytes:19906 (19.4 KiB) TX bytes:9291 (9.0 KiB)
Interrupt:23 Base address:0xe800

lo Link encap:Local Loopback
inet addr:127.0.0.1 Mask:255.0.0.0
inet6 addr: ::1/128 Scope:Host
UP LOOPBACK RUNNING MTU:16436 Metric:1
RX packets:78 errors:0 dropped:0 overruns:0 frame:0
TX packets:78 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:0
RX bytes:6742 (6.5 KiB) TX bytes:6742 (6.5 KiB)

vbox0 Link encap:Ethernet HWaddr 62:4F:9B:96:46:43
inet6 addr: fe80::604f:9bff:fe96:4643/64 Scope:Link
UP BROADCAST RUNNING PROMISC MULTICAST MTU:1500 Metric:1
RX packets:0 errors:0 dropped:0 overruns:0 frame:0
TX packets:0 errors:0 dropped:9 overruns:0 carrier:0
collisions:0 txqueuelen:500
RX bytes:0 (0.0 b) TX bytes:0 (0.0 b)

Kernel IP routing table
Destination Gateway Genmask Flags Metric Ref Use Iface
192.168.10.0 0.0.0.0 255.255.255.0 U 10 0 0 br0
169.254.0.0 0.0.0.0 255.255.0.0 U 10 0 0 br0
0.0.0.0 192.168.10.11 0.0.0.0 UG 10 0 0 br0

Yodama
2012-06-25, 07:13
Thank you for reporting this issue, I can confirm this false positive.
It will be fixed with our next detection update scheduled for Wednesday 2012-06-27.