Pingplotter trojan??

Posted by: Thandir

Pingplotter trojan?? - 01/12/10 11:08 AM

I've had Ping Plotter standard (licensed) installed for quite some time but just last night my virus scanner smoked it and gave me this:
C:\Program Files\PingPlotter Standard\PingPlotter.exe: Trojan.Libix FOUND

I re-downloaded Ping Plotter (from www.pingplotter.com) and installed it again, ran the antivirus again, and it did the same thing. Is anyone else seeing this?
Posted by: Pete Ness

Re: Pingplotter trojan?? - 01/12/10 12:00 PM

We have had some false positives on PingPlotter recently. What virus scanner are you using?

Without knowing your virus scanner brand, I can't verify 100% that it's a false positive, but the download on our site is virus/Trojan free.

If you want to make sure, you can check the code sign on the install and the binary - they are both signed by Nessoft LLC in late 2008.

- Pete
Posted by: Thandir

Re: Pingplotter trojan?? - 01/12/10 12:07 PM

Thanks Pete. I'm using ClamWin antivirus version 0.95.3
I've added PingPlotter.exe to the list of exceptions so hopefully it will stop bugging me.
Posted by: Fritz

Re: Pingplotter trojan?? - 03/09/10 09:47 AM

I am getting what I hope is a false positive on PingPlotter Standard 3.30.3s using F-Prot antivirus for windows wirh signature file from 3/8/2010 11:30 PM. The report is:
Quote:
[Found application] <W32/Themida_Packed!Eldorado (not disinfectable, generic)> C:\Program Files\PingPlotter Standard\PingPlotter.exe->(Themida)

Fritz
Posted by: Pete Ness

Re: Pingplotter trojan?? - 03/09/10 10:33 PM

We occasionally get false positives on PingPlotter, but the current build (3.30.1s) looks pretty clean at the moment with most virus scanners as of right now. Here's a Virus Total report:

http://www.virustotal.com/analisis/94839...141d-1268191289

If you have 3.30.0s installed still, that might be getting some false positives. We use a binary integrity verifying tool, "Themida" to make sure PingPlotter is a valid image, and some virus scanners occasionally misunderstand that and report it as Unknown/Packed or similar.

If you're still using 3.30.0s, try upgrading to 3.30.1s (http://www.pingplotter.com/files.html).

- Pete