Jump to content

Recommended Posts

Posted (edited)

Sophos has just flagged up a virus on an AQA disk we got in the post. It one of those Mal/Generic-A ones which resembles a virus/malware.

 

The disk contains loads of password protected EXE files and 2 have flagged up with virus alerts, the folder contains 20 or so similar files.

 

Anyone else found a problem with the disks? I've had false results before but I am wary as its the exams machine.

Edited by Simcfc73
  • 6 months later...
Posted

*resurrects thread*

We've just had the same happen with an AQA ISA cd for GCSE - four of the marking guidelines files are showing as infected by our av and virustotal is reporting a 50-65% probability of "yup, that's dodgy".

 

Anyone know if AQA recycle the marking guideline files if they haven't changed, or is it down to the way those particular files are packed?

Posted

This happened to us too earlier in the year. It's down to the way they are packed. AVG have since updated their definitions after our report, but clearly other vendors haven't.

 

What's more concerning to me is that last time I checked the password-protected .EXEs steadfastly refused to open on any Vista machine (they simply run and then die without ever showing any GUI or error message). I tried several time to contact AQA but never had a response.

Posted
Also had this problem with Symantec AV, rang AQA and they said they used a password on some of the password protected files that AV scanners report as a virus. They offered to send me a revised disk. Can't remember receiving it though.
Posted
Hmm, just checked the Mcafee "dispute file result" page and it needs to come from AQA, not me, and will take 4-6 weeks to sort out, which isn't great. I've phoned AQA to request a new cd from them, we'll see if that one's been fixed.
Posted

Last time I tried to report a false positive to McAfee via their online chat support, I spent 10 minutes trying to explain the very concept of a false positive to the retard on the other end. "No sir, if it says there is a virus then there is a virus."

 

I gave up eventually and uninstalled McAfee.

Posted
AV companies are always going to be cagey about false positives. They even dream up little terms for them. If you contact Sophos mention "unwanted detection". lol
Posted

We had the same issues as above. I told them the head of science that was a virus on the disk and she didn't beleive me as it was from a decent company and that all schools would be sent it so wasn't true :eek:

 

I really hope she took it home! :p

Posted
The disk does not contain a virus. AV scanners flag the files as a virus as they have used a password on one or more of the protected files that are included in AV definitions as a possible virus.
Posted

As a temporary workaround until we get a new disk (I suspect that the new disk will have the same problem if this has been going on since the spring term) I unpacked the file with wine (self-extracting, password-protected .exe), scanned the contents (clean) and re-created the .exe using the original password and 7-zip (aes).

 

Mcafee didn't have a problem with the new file.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...