in
Support Center

Virus Warning

Last post 05-12-2008 3:43 PM by Nate. 12 replies.
Page 1 of 1 (13 items)
Sort Posts: Previous Next
  • 05-12-2008 8:04 AM

    • RodNH
    • Top 25 Contributor
    • Joined on 09-23-2007
    • Posts 39

    Virus Warning

    This morning I was greated with the above warning from AVAST anti-virus concerning ShadowProtectSvc.exe. I deleted SPD3.2 and reinstalled (had to stop AVAST protection to do so) only to get the same warning. Furthermore AVAST will not permit SPD3.2 to run at all (from windows) because of this Trojan Horse detection. I am assuming this is a false positive due to the recent (yesterday) update of the AVAST virus database - but am not sure. I have had no problems with 3.2 before today. In any event, AVAST and SPD3.2 cannot currently coexist in windows. It makes no difference if the reinstall of SP is done from the downloaded trial or from the CD made from the 3.2 ISO. Please advise.

  • 05-12-2008 9:20 AM In reply to

    • John
    • Top 10 Contributor
    • Joined on 02-16-2008
    • Posts 98

    Re: Virus Warning

    Yes, it is a false positive. This has been reported in other forums as well. AVAST is complaining about the "ShadowProtectSvc.Exe" file. I'm not familiar with AVAST, so I'm not sure whether or not you can place "ShadowProtectSvc.Exe" on an "exemption" list or not. Hopefully AVAST will update their database VERY soon.

  • 05-12-2008 9:23 AM In reply to

    • Moglie
    • Top 500 Contributor
    • Joined on 05-09-2008
    • Posts 4

    Re: Virus Warning

    I have a similar message popping up from F-Secure Client Security 7.11:

    Virus & Spy Protection has detected Backdoor.Win32. Rbot.pia in file shadowprotectsvc.exe  

    They also seem to have updated their sginature based about an hour ago, since then the message appears.
  • 05-12-2008 10:46 AM In reply to

    Re: Virus Warning

     Kaspersky IS 7

     

  • 05-12-2008 10:55 AM In reply to

    Re: Virus Warning

     Send it to Kaspersky, so they can correct this behaviour in their signatures.

  • 05-12-2008 11:21 AM In reply to

    • John
    • Top 10 Contributor
    • Joined on 02-16-2008
    • Posts 98

    Re: Virus Warning

    Obviously there is something peculiar to that file that is triggering these warnings from several different AV products. Hopefully someone from Storagecraft reads this thread and is able to offer an explanation or a solution.

  • 05-12-2008 12:05 PM In reply to

    • bsdice
    • Top 10 Contributor
    • Joined on 09-21-2007
    • Germany
    • Posts 215

    Re: Virus Warning

    Well I could tell you what's happening but then I'd have to shoot you all... ;)

    The binary mistaken for malware is protected by a software copy protection system to hinder unauthorized modification and it seems some virus writer got clever and also used this scheme in his own creation. Then some sloppy/dumb persons at virus companies added a pattern identifying the protection shell as "the malware" even though the real malware lies encrypted and obfuscated in the binary's guts.

    You got some options:

    - Contact AV vendor and tell them that they created a false positive

    - White list the flagged binary and put it into trusted zone (at least of KAV I know this is possible)

    - Switch back to 3.1 for the time being 

    - Deinstall ShadowProtect and switch to Acronis (just kidding)

    This is one among a few reasons we do no longer put AV on servers because one day a sloppy AV pattern curator will release something that will put a bunch of vital windows files into quarantine...
     

    Jack of many trades, master of none.
  • 05-12-2008 12:36 PM In reply to

    Re: Virus Warning

    ShadowProtectSvc.exe (ShadowProtect's NT service) incorporates security mechanisms which occasionally cause anti-virus products to mis-classify the file ShadowProtectSvc.exe as malware.

    The 3.2 (and greater) versions of ShadowProtectSvc.exe are digitally signed with a Class-3 Software Publisher's Certificate (SPC) from Verisign.  You can use this to determine if the ShadowProtectSvc.exe file has been altered since it came from StorageCraft.  If the digital signature of ShadowProtectSvc.exe is OK then you know that the anti-virus warning is a false positive, and that the ShadowProtectSvc.exe file is okay.  However, if the digital signature is invalid, then you know that the file ShadowProtectSvc.exe has been altered since it was created by StorageCraft, and may indeed be infected with malware.

    To test the digital certificate, use File Explorer to right-click on the file ShadowProtectSvc.exe (in the directory C:\Program Files\StorageCraft\ShadowProtect) and in the Properties dialog click on the Digital Signatures tab.  If this tab is missing then your version of ShadowProtectSvc.exe is not digitally signed.  Note, again, that StorageCraft started signing ShadowProtectSvc.exe starting with version 3.2, so you will not find a digital signature for version 3.1. In the Digital Signatures tab, select the  StorageCraft signature in the list and click on the Details button.  At the top of the General tab of the Digital Signature Details dialog it will either say that "The digital signature is OK." or that it is invalid.

    After you have verified that the digital signature of ShadowProtectSvc.exe is valid, you can safely add it to your anti-virus product's exception list (hopefully your AV product has such a feature). 

  • 05-12-2008 12:44 PM In reply to

    Re: Virus Warning

     Got response from Kaspersky:

     

    Hello.
    Sorry, it's false alarm. It's detection will be deleted in the next update. Thank you for your help.

     

  • 05-12-2008 12:56 PM In reply to

    Re: Virus Warning

    Great!  Thanks for that!  These AV companies share virus signatures (which is why today four of them suddenly decided to mis-classify ShadowProtectSvc.exe as malware) and so we should see this issue go away within a day or so on all of these AV products.
  • 05-12-2008 12:59 PM In reply to

    • John
    • Top 10 Contributor
    • Joined on 02-16-2008
    • Posts 98

    Re: Virus Warning

    AVAST has also updated to exclude the false positive.

  • 05-12-2008 1:19 PM In reply to

    • RodNH
    • Top 25 Contributor
    • Joined on 09-23-2007
    • Posts 39

    Re: Virus Warning

    I just got the updated AVAST signatures (5/12/08) and the problem has been corrected.

  • 05-12-2008 3:43 PM In reply to

    Re: Virus Warning

    Cool.  This is quickly becoming a non-issue.
Page 1 of 1 (13 items)
(c) StorageCraft Technology Corporation 2008