Go Back   CA Home and Home Office Forum > Product Questions > CA Anti-Virus
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Closed Thread
 
Thread Tools Search this Thread Display Modes
  #1  
Old 07-08-2009, 06:47 PM
exhaling_c02 exhaling_c02 is offline
Junior Member
 
Join Date: Jun 2009
Posts: 14
exhaling_c02 is on a distinguished road
Exclamation Win/32AMalum.ZZOSC Virus Alert

Hello...

Just received a virus alert named, 'Win32/AMalum.ZZOSC'. 'RealOneMessageCenter.exe' was the culprit, according to my CA Anti-Virus 2009. Is this a false-postive alert? The alert just popped up out of nowhere. I couldn't find any information about Win32/AMalum.ZZOSC on CA's website.

Thanks for any help/advice given, in advance.

Last edited by exhaling_c02; 07-08-2009 at 08:21 PM. Reason: title
  #2  
Old 07-08-2009, 07:03 PM
exhaling_c02 exhaling_c02 is offline
Junior Member
 
Join Date: Jun 2009
Posts: 14
exhaling_c02 is on a distinguished road
Default

Quote:
Originally Posted by exhaling_c02 View Post
Hello...

Just received a virus alert named, 'Win32/AMalum.ZZOSC'. 'RealOneMessageCenter.exe' was the culprit, according to my CA Anti-Virus 2009. Is this a false-postive alert? The alert just popped up out of nowhere. I couldn't find any information about Win32/AMalum.ZZOSC on CA's website.

Thanks for any help/advice given, in advance.
____________________________________________

Update:

I also just received another new alert -- Win32/AMalum.ZZNWH due to 'rphelperapp.exe'.

Last edited by exhaling_c02; 07-08-2009 at 08:09 PM.
  #3  
Old 07-08-2009, 07:23 PM
NigelD NigelD is offline
Junior Member
 
Join Date: Jul 2009
Location: East Yorkshire
Posts: 13
NigelD is on a distinguished road
Default

I just got the same message with 19 files detected and 18 of them quarantined but one still infected. Any clues as to how I get rid?
  #4  
Old 07-08-2009, 07:26 PM
icflordlucan icflordlucan is offline
Junior Member
 
Join Date: Jul 2009
Posts: 27
icflordlucan is on a distinguished road
Default

Seems this is happening to a few of us. It can't be a coincidence, so my thoughts are that it's a false/positive. However, when CA was quarantining files, I was getting Windows system messages telling me the files being quarantined are genuine Windows files and my system may become unstable.
Does this mean it's safe to restore them from the quarantine bin (once CA is no longer popping infected messages)?
  #5  
Old 07-08-2009, 07:35 PM
spud's Avatar
spud spud is offline
Super Moderator
 
Join Date: Sep 2008
Location: Kent, UK
Posts: 2,652
spud is on a distinguished road
Default

Check again after the next update as this looks like a false positive.
__________________

IssViews website Free online scans, product Lists, utilities and advice.
IssViews Forum See and give feedback on security software, info to keep up with the latest threats on the net and links to Free Malware removal services.
IssViews Blog Product/security, info/updates, news, plus bits from around the net.
and to follow IssViews on Twitter
  #6  
Old 07-08-2009, 07:59 PM
PCdocnz PCdocnz is offline
Junior Member
 
Join Date: Jul 2009
Posts: 1
PCdocnz is on a distinguished road
Default

CA AV has to be DISABLED before restoring the files, otherwise it simply
re-quarantines them straight away.

This is a disaster, considering the number the number of PC's we have installed CA on, now starting to come up with this issue.
Will the new sig update automatically restore these files in quarantine or does every PC with this issue need to have the files manually restored??
  #7  
Old 07-08-2009, 08:06 PM
icflordlucan icflordlucan is offline
Junior Member
 
Join Date: Jul 2009
Posts: 27
icflordlucan is on a distinguished road
Default

How can one restore the files with CA AV disabled?
Anyone know how?
My guess would be that when the next definition comes out, these files will no longer set off alerts, so simply restoring them from quarantine should do the trick. However I could be wrong, but that just seems like common sense to me.
Nonetheless, this is a huge pain. I have now lost 2 working hours scanning my system with various products, reading this forum and searching online for answers.
Incidentally, the CA definition I have is 6604.
My wife has the same definition on her p.c and she's had no issues at all (so far).

Last edited by icflordlucan; 07-08-2009 at 08:09 PM.
  #8  
Old 07-08-2009, 08:19 PM
NigelD NigelD is offline
Junior Member
 
Join Date: Jul 2009
Location: East Yorkshire
Posts: 13
NigelD is on a distinguished road
Default

My infected file is called C:\WINDOWS\Installer\30d2a.msi<common\update.exe>. Should I try to delete this file or wait for CA to do a fix?

My definition also is 6604.

Last edited by NigelD; 07-08-2009 at 08:31 PM. Reason: Additional information
  #9  
Old 07-08-2009, 08:26 PM
eculli eculli is offline
Junior Member
 
Join Date: Jul 2009
Posts: 2
eculli is on a distinguished road
Default

I just got following message.

7/8/2009 16:58:31 PM File infection: C:\WINDOWS\system32\net.exe is Win32/AMalum.ZZNPB infection. Quarantined
7/8/2009 16:58:32 PM File infection: C:\WINDOWS\system32\netsh.exe is Win32/AMalum.ZZOKH infection. Quarantined
7/8/2009 16:58:38 PM File infection: C:\windows\SERVIC~1\i386\net.exe is Win32/AMalum.ZZNPB infection. Quarantined
7/8/2009 16:58:38 PM File infection: C:\windows\ServicePackFiles\i386\net.exe is Win32/AMalum.ZZNPB infection.
7/8/2009 16:58:38 PM File infection: C:\windows\SERVIC~1\i386\netsh.exe is Win32/AMalum.ZZOKH infection. Quarantined
7/8/2009 16:58:39 PM File infection: C:\windows\ServicePackFiles\i386\netsh.exe is Win32/AMalum.ZZOKH infection.
7/8/2009 16:58:42 PM File infection: C:\WINDOWS\system32\reg.exe is Win32/AMalum.ZZOAF infection. Quarantined
7/8/2009 16:58:47 PM File infection: C:\windows\SERVIC~1\i386\reg.exe is Win32/AMalum.ZZOAF infection. Quarantined
7/8/2009 16:58:47 PM File infection: C:\windows\ServicePackFiles\i386\reg.exe is Win32/AMalum.ZZOAF infection.
7/8/2009 16:58:49 PM File infection: C:\WINDOWS\system32\verclsid.exe is Win32/AMalum.ZZNRA infection. Quarantined

I just got an auto update from CA today & errors appeared. Is this false and if so how do I fix problem
  #10  
Old 07-08-2009, 08:36 PM
spud's Avatar
spud spud is offline
Super Moderator
 
Join Date: Sep 2008
Location: Kent, UK
Posts: 2,652
spud is on a distinguished road
Default

In answer to you all, make sure you disable automatic deletion of quarantined files so that you can restore them when the update comes out and its confirmed a false positive. I am sure CA will be quick to patch this issue.
__________________

IssViews website Free online scans, product Lists, utilities and advice.
IssViews Forum See and give feedback on security software, info to keep up with the latest threats on the net and links to Free Malware removal services.
IssViews Blog Product/security, info/updates, news, plus bits from around the net.
and to follow IssViews on Twitter
Closed Thread

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off

Forum Jump


All times are GMT -4. The time now is 01:55 AM.


Powered by vBulletin® Version 3.8.2
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.