Download TrojanHunter Now
Free 30-day trial!
Latest TrojanHunter Version:
TrojanHunter 5.0
Order Now
License file delivered within minutes.
Welcome, Guest. Please Login or Register.
Jul 5th, 2008, 7:13pm
   Mischel Internet Security Forum
   TrojanHunter
   TrojanHunter Guard
(Moderators: Helena, Gavin_Coe, Magnus)
   Possible false positive (iesdsg.dll)
« Previous topic | Next topic »
Pages: 1  Reply Reply  Notify of replies Notify of replies   Send Topic Send Topic   Print Print
   Author  Topic: Possible false positive (iesdsg.dll)  (Read 373 times)
Nella
Newbie
*





   


Posts: 37
Possible false positive (iesdsg.dll)
« on: May 10th, 2007, 2:25pm »
Quote Quote  Modify Modify

Today as soon as I updated my TH definitions (running Ver. 4.6 Build 930) on my stand alone PC running XP Pro SP2, I received a warning that TH had removed a trojan named (I didn't write down the name unfortunately) from memory and that I should reboot and run a full scan with TH, which I did (results were clean).
 
After the scan, I found the file containing the virus had been quarantined.  The original file name was iesdsg.dll and the path was f:\spyware doctor\tools\iesdsg.dll.  A brief search on the internet indicates a file with this name is a legitimate file for the program Spyware Doctor (which is installed on my PC), which of course doesn't mean the file itself was not a trojan.
 
I will be submitting the file to TH for analysis in a few minutes.  But in the meantime, I'm trying to find a TH Log file created when I received the TH alert (which wasn't during a normal TH scan, which I know does create a report when finished), which would tell me the name of the trojan which TH thinks the file contained.  I would have thought the virus name which I mistakenly didn't write down when TH first alerted would be available to see if I highlighted the errant file in the TH quarantine but I can't find it.
 
I can't find any documentation in the Help file or the FAQ webpage for ascertaining the location of a TH logfile on my PC created when TH alerted on, immediately after an update, not during a TH scan, on what it believed to be a trojan.  Any ideas?  Nella
IP Logged
siliconman01
Global Moderator
*****



Trojans! Chew 'em Up, Spit 'em Out...

   


Gender: male
Posts: 5468
Re: Possible false positive (iesdsg.dll)
« Reply #1 on: May 10th, 2007, 11:10pm »
Quote Quote  Modify Modify

Unfortunately TH V4.6.930 does not maintain a running log of its activities.  A log can be generated for a scan (look under FILE in the top menu bar of TH scanner).  
 
I recommend that you uncheck the "Automatically remove trojans" option in THG so that it will just alert you that it has found something and needs your permission to proceed with the removal.  That gives you a chance to investigate before the removal.  
 
Thanks for submitting the FP file so that Gavin can fix the rule that caused the False Positive.
IP Logged

______
TrojanHunter V5.0.962...No. 1 AT in my Book and on my Box!
Nella
Newbie
*





   


Posts: 37
Re: Possible false positive (iesdsg.dll)
« Reply #2 on: May 11th, 2007, 8:16am »
Quote Quote  Modify Modify

Siliconman01,
 
Thanks for letting me know more about how TH operates. I'm glad my particular issue yesterday was a false alarm; Gavin responded to my e-mail with the questionable file attached, quickly and with the good news.
 
I have followed your recommendation to go from automatic to manual, so to speak.  That should work great if it happens again.
 
I'm very happy with TH's excellent protection of my PC over all these years, and with the excellent customer support.  Nella
IP Logged
siliconman01
Global Moderator
*****



Trojans! Chew 'em Up, Spit 'em Out...

   


Gender: male
Posts: 5468
Re: Possible false positive (iesdsg.dll)
« Reply #3 on: May 11th, 2007, 1:55pm »
Quote Quote  Modify Modify

You are most welcome,  Cheesy
 
Keep a watch out for a new TH version to be issued when Magnus is ready for taking on Vista.  It'll probably have other enhancements that apply to other Window OS's.   Wink
IP Logged

______
TrojanHunter V5.0.962...No. 1 AT in my Book and on my Box!
Pages: 1  Reply Reply  Notify of replies Notify of replies   Send Topic Send Topic   Print Print

« Previous topic | Next topic »
Search
Members
Login
Register