Gnutella Forums  

Go Back   Gnutella Forums > Current Gnutella Client Forums > LimeWire+WireShare (Cross-platform) > Technical Support > General Windows Support
Register FAQ The Twelve Commandments Members List Calendar Arcade Find the Best VPN Today's Posts

General Windows Support For questions about Windows issues regarding LimeWire or WireShare or related questions


Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old March 14th, 2007
Disciple
 
Join Date: March 7th, 2007
Posts: 19
sparky_05084 is flying high
Exclamation antivirus worries

Hey all. New day, new problem!
I recently posted on here saying I was worried my bullguard antivirus was picking up suspected spyware/malware whenever I run LW and I was told it may be a "false positive" (not sure what exactly this means). I get it everytime I do a scan and it seems to be coming from LW. Anyways I will show you a log of what bullguard is saying:


Infected Files
__________________________________________________ _________

----[ Infected Registry Entries ]------------

Malware: magne2t
<System>=>HKEY_CLASSES_ROOT\MAGNET
<System>=>HKEY_CLASSES_ROOT\MAGNET\DEFAULTICON
<System>=>HKEY_CLASSES_ROOT\MAGNET\SHELL
<System>=>HKEY_CLASSES_ROOT\MAGNET\SHELL\OPEN
<System>=>HKEY_CLASSES_ROOT\MAGNET\SHELL\OPEN\COMM AND

Malware: magne3t
<System>=>HKEY_LOCAL_MACHINE\SOFTWARE\MAGNET
<System>=>HKEY_LOCAL_MACHINE\SOFTWARE\MAGNET\HANDL ERS
<System>=>HKEY_LOCAL_MACHINE\SOFTWARE\MAGNET\HANDL ERS\LIMEWIRE
<System>=>HKEY_LOCAL_MACHINE\SOFTWARE\MAGNET\HANDL ERS\LIMEWIRE\TYPE

__________________________________________________ _________

Results after ROUND 0
__________________________________________________ _________

Scan started: Sunday, March 11, 2007 13:03:35
Scan duration: 0 days, 00 hours, 43 minutes, 21 seconds
Infections solved: 0
Infections left: 9
Viruses left: 2

----[ Registry Entries Still Infected ]------------

Malware: magne2t
<System>=>HKEY_CLASSES_ROOT\MAGNET
<System>=>HKEY_CLASSES_ROOT\MAGNET\DEFAULTICON
<System>=>HKEY_CLASSES_ROOT\MAGNET\SHELL
<System>=>HKEY_CLASSES_ROOT\MAGNET\SHELL\OPEN
<System>=>HKEY_CLASSES_ROOT\MAGNET\SHELL\OPEN\COMM AND

Malware: magne3t
<System>=>HKEY_LOCAL_MACHINE\SOFTWARE\MAGNET
<System>=>HKEY_LOCAL_MACHINE\SOFTWARE\MAGNET\HANDL ERS
<System>=>HKEY_LOCAL_MACHINE\SOFTWARE\MAGNET\HANDL ERS\LIMEWIRE
<System>=>HKEY_LOCAL_MACHINE\SOFTWARE\MAGNET\HANDL ERS\LIMEWIRE\TYPE

__________________________________________________ _________

Results after ROUND 1
__________________________________________________ _________

Scan started: Sunday, March 11, 2007 14:03:56
Scan duration: 0 days, 00 hours, 00 minutes, 06 seconds
Infections solved: 0
Infections left: 9
Viruses left: 2

----[ Registry Entries Still Infected ]------------

Malware: magne2t
<System>=>HKEY_CLASSES_ROOT\MAGNET
<System>=>HKEY_CLASSES_ROOT\MAGNET\DEFAULTICON
<System>=>HKEY_CLASSES_ROOT\MAGNET\SHELL
<System>=>HKEY_CLASSES_ROOT\MAGNET\SHELL\OPEN
<System>=>HKEY_CLASSES_ROOT\MAGNET\SHELL\OPEN\COMM AND

Malware: magne3t
<System>=>HKEY_LOCAL_MACHINE\SOFTWARE\MAGNET
<System>=>HKEY_LOCAL_MACHINE\SOFTWARE\MAGNET\HANDL ERS
<System>=>HKEY_LOCAL_MACHINE\SOFTWARE\MAGNET\HANDL ERS\LIMEWIRE
<System>=>HKEY_LOCAL_MACHINE\SOFTWARE\MAGNET\HANDL ERS\LIMEWIRE\TYPE


Does this mean anything to anyone? Bullguard support told me this was being generated by limewire itself and I can adjust settings so it isn't no longer detected. Can anyone help. Thanks
Reply With Quote
  #2 (permalink)  
Old March 14th, 2007
Grandpa's Avatar
Valued Member contributor
 
Join Date: February 20th, 2005
Location: Depends on the Day
Posts: 3,012
Grandpa will become famous soon enough
Default

It is not spyware or a Virus. Magnetic links are a search criteria
__________________

java.com - Hot Games, Cool Apps









A little common sense goes a long way

Later Grandpa
Reply With Quote
  #3 (permalink)  
Old March 15th, 2007
Disciple
 
Join Date: March 7th, 2007
Posts: 19
sparky_05084 is flying high
Question

ok. That may be the case then, however, why is it then Bullguard displays the message "spyware found!" after a system scan. If this magnet link/file is part of LW then why doesn't my antivirus simply ignore it if its safe? can I not change a setting in LW itself so that bullguard ignores them altogether?
Reply With Quote
  #4 (permalink)  
Old March 16th, 2007
Part Timer
 
Join Date: December 28th, 2006
Posts: 18
tomvee is a great assister to others; your light through the dark tunnel
Default

It's possible that it could be a false positive. Some programs produce them now & again. See here :

http://www.viruslist.com/en/glossary?glossid=153654932


It seems at one time I used Trend-Micro's antispyware & it would say that Limewire was spyware, somewhat similar to what Bullguard is doing for you. I'm not farmiliar with Bullguard (got these instructions from their forums) but try this: look under Antivirus > Protection, put a checkmark under Exclude Specific Files then click on Add Path. If you get the option to Browse then go down the list until you see Limewire , or you may have to copy/paste the actual target which would be this:

C:\Program Files\LimeWire\LimeWire.exe
Reply With Quote
  #5 (permalink)  
Old March 16th, 2007
Valued Member
 
Join Date: May 30th, 2004
Location: United Kingdom
Posts: 2,866
ukbobboy01 will become famous soon enough
Default

Sparky_05084

First of all, Tomvee has given you a good explanation of false positives, namely that some programs will wrongly identify certain parts of your P2P program as spyware.

Now I believe Anti-Virus and Anti-spyware apps give false positives because back in the dim and distant past P2P apps did contain spyware and adware as a means of generating funds (or advertising revenue) for their companies. Also there are some spyware out there that use some P2P coding as part of their make up.

The way to make sure that your Bullguard AV does not disable your LW is to read your AV log, as you have done, and identify the application (or parts of the application) that is being identified as spyware and get Bullguard to disregard those items in future scans.

I had a similar problem with Spybot identifying parts of my Windows XP SP2 update as spyware, until I got Spybot to exclude those SP2 bits from its scan.



UK Bob
Reply With Quote
  #6 (permalink)  
Old March 16th, 2007
Disciple
 
Join Date: March 7th, 2007
Posts: 19
sparky_05084 is flying high
Thumbs up

Ok. Thanks you guys. I will probably not risk excluding LW from a scan ( i know how to do it) as it would mean that maybe Bullguard would ignore it completely, which of course is major risky. I want it to monitor Lw all the time, even if it means that pesky file keeps popping up now and then. Yes, you are probably right, it seems by asking Bullguard support, it is a false positive generated by a legitimate part of limewire i.e the magnet file. Im not worried about this but I wanted to be sure. I will keep you posted if I do get any more problems. Thanks again for your advices.
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Why not antivirus quoc Site Feedback 8 August 2nd, 2006 12:11 AM
Worries Kezman Open Discussion topics 0 January 15th, 2006 07:56 AM
no worries: a 1628 error solution maxy General Windows Support 0 December 15th, 2004 06:52 PM
Update worries Dark Lady General Mac OSX Support 3 July 23rd, 2004 08:05 AM
AntiVirus Unregistered New Feature Requests 0 December 28th, 2001 11:51 AM


All times are GMT -7. The time now is 08:08 AM.


Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2024, vBulletin Solutions, Inc.
SEO by vBSEO 3.6.0 ©2011, Crawlability, Inc.

Copyright © 2020 Gnutella Forums.
All Rights Reserved.