AVG AntiVirus Free detected a Trojan during Pelles C install

Started by rjh58, January 10, 2014, 08:49:05 AM

Previous topic - Next topic

rjh58

I'm installing the latest 64 bit version of Pelles on my windows 7 home premium machine that has the latest AVG Free installed. Towards the end of the install a detection message popped up saying that hello.exe has the Trojan horse "BackDoor.Generic17.ADRE" in it. That scares me a bit. Is it a false positive?

I ran a scan of the setup program before installing on VirusTotal with no detections.

Please let me know.

Thanks, Rich

P.S. I've attached a .jpg of the AVG alert.

jj2007

Rich,

First things first: Welcome to the forum!

Hello.exe is an example file. Probably you'll find its source in the same folder - have a look, then recompile it and ask yourself why certain crappy AV software finds a trojan there...

Heuristic scanners are trying to guess what malicious programmers could have intended. They are not very good at guessing, though, and therefore produce such false positives which scare away the average user. Which damages the business of honest small software companies who cannot afford threatening AVG with a lawsuit...

Bitbeisser

Quote from: rjh58 on January 10, 2014, 08:49:05 AM
I'm installing the latest 64 bit version of Pelles on my windows 7 home premium machine that has the latest AVG Free installed. Towards the end of the install a detection message popped up saying that hello.exe has the Trojan horse "BackDoor.Generic17.ADRE" in it. That scares me a bit. Is it a false positive?
Yes, that's a false positive. There are some AV programs out there that just keep identifying parts of Pelle's C itself or any generated program as a possible virus. They seem to identify this by a part of the default runtime library that gets linked in rather than code actually associated with any virus itself...

AVG, Avast and AVira annoyingly seem to be on the top of the list of AV software that don't like to play ball...

Ralf

rjh58

Thanks for the welcome,

and thanks for your replies.

Puts me at ease.

Rich