Results 1 to 7 of 7

Thread: Possible false positive - Win32.Agent.bzs

  1. #1
    Junior Member
    Join Date
    Dec 2008
    Posts
    3

    Default Possible false positive - Win32.Agent.bzs

    Hi - I got this result repeatedly in scans since 4/12 (after the last set of updates). I am currently using Firefox 3.0.4. Here's the log:


    --- Report generated: 2008-12-06 20:21 ---

    Win32.Agent.bzs: [SBI $3E293BA0] Executable (File, nothing done)
    C:\WINDOWS\system32\userinit.exe

    Cache: Cache (801) (Cache, nothing done)

    --- Spybot - Search & Destroy version: 1.6.0 (build: 20080604) ---




    And here is the fix log:

    --- Report generated: 2008-12-06 20:48 ---

    Win32.Agent.bzs: [SBI $3E293BA0] Executable (File, fixed)
    C:\WINDOWS\system32\userinit.exe

    Cache: Cache (801) (Cache, nothing done)


    My problem is that on scanning with Spybot after a reboot, the problem file reappears. I have looked at the executable userinit.exe before and after clicking to fix the problem in Spybot. There doesn't appear to be any change and the files properties remain unchanged. No other scanner highlights any problem.

    Is this result a false positive?

  2. #2
    Senior Member Yodama's Avatar
    Join Date
    Oct 2005
    Location
    Buchenheim
    Posts
    1,110

    Default

    hello,
    to analyze this issue we will require the userinit.exe in question.
    Please copy it to your desktop and zip it. Then email it to detections-at-spybot.info (please replace -at- with @) with a reference to this thread.
    born in the shadow to die in the shadow, that is the fate of the shinobi

    Spybot S&D Downloads

    Please help us improve Spybot and download our distributed testing client.

  3. #3
    Junior Member
    Join Date
    Dec 2008
    Posts
    1

    Default

    Quote Originally Posted by bobajob61 View Post
    My problem is that on scanning with Spybot after a reboot, the problem file reappears. I have looked at the executable userinit.exe before and after clicking to fix the problem in Spybot. There doesn't appear to be any change and the files properties remain unchanged. No other scanner highlights any problem.
    Same happens to me, any news about this?

  4. #4
    Junior Member
    Join Date
    Dec 2008
    Posts
    3

    Default

    OK - I have sent the userinit.exe zip file to detections-at-spybot.info.

    Hope you can evaluate whether this one was a f/p.
    Last edited by bobajob61; 2008-12-08 at 20:07.

  5. #5
    Senior Member Yodama's Avatar
    Join Date
    Oct 2005
    Location
    Buchenheim
    Posts
    1,110

    Default

    thank you for sending in the file,
    it looks like a false positive, correction will be made with the update today.
    born in the shadow to die in the shadow, that is the fate of the shinobi

    Spybot S&D Downloads

    Please help us improve Spybot and download our distributed testing client.

  6. #6
    Junior Member
    Join Date
    Dec 2008
    Posts
    3

    Default

    You're welcome. Glad to be of some assistance. Thanks for looking into this for me.

  7. #7
    Junior Member
    Join Date
    Dec 2008
    Posts
    1

    Default

    This one turned up in a scan on Sunday, I've been trying unsuccessfully to get rid of it since then. Hope it is a FP !!

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •