From: "G. Morgan" <sealteam6@osama-is-dead.net>

> G. Morgan wrote:
>
>> David H. Lipman wrote:
>>
>>> From: "G. Morgan" <sealteam6@osama-is-dead.net>
>>>
>>>> David H. Lipman wrote:
>>>>
>>>>> From: "G. Morgan" <sealteam6@osama-is-dead.net>
>>>>>
>>>>>>
>>>>>> All were false positives except this:
>>>>>> savedsites\hxxp___mynews.ath.cx\http://www.vanbasco.com\downloads\va...ad_chinese.exe
>>>>>> * Trojan.Crypt!IK
>>>>>>
>>>>>> It thought this file was bad :-(
>>>>>> http://www.virustotal.com/file-scan/...f96-1321894516
>>>>>>
>>>>>>
>>>>>
>>>>> Please submit that file, if you still have it, to http://www.uploadmalware.com/
>>>>
>>>> Done.
>>>>
>>>> Came from:
>>>>
>>>> C:\cygwin\lib\python2.6\lib-dynload\_functools.dll
>>>>
>>>> detected: Trojan.Win32.Possador.AMN!A2
>>>
>>>
>>> Looks like an Emsisoft (A2) False Positive detection. Cygwin tools are known for
>>> generating occasional False Positives.

>>
>> Thanks for the confirmation. I left it alone.

>
> BTW... Are you in a position to contact Emsisoft and get them to correct
> all these false-positives? They should not pick on Nirsoft or
> Sysinternals tools. Someone who just "selected all" could **** up their
> system based on all the false's. You really have to know what you're
> doing to use that utility safely.
>
> I give it a 7/10, for excellent detection but lost points for false
> positives.
>
> Can not recommend to end-users.
>


I could if you really want me to.



--
Dave
Multi-AV Scanning Tool - http://multi-av.thespykiller.co.uk
http://www.pctipp.ch/downloads/dl/35905.asp