AVAST kills LogMeIn software

I saw this with my own PC last night (running LMI Free) when I was stuck at the “Connecting … Please wait while a connection to My PC is established” screen for over 5 min and then couldn’t break the failed connection from my PC once I got home because I had enabled remote screen blanking so I was forced to shutdown my computer by pressing-holding my power button for 8 sec.

When I tried rebooting the PC this morning, it locked up as well. As expected, avast kicked in and flagged the two LMI*.dll files but I was able to tell avast to do nothing with them. I then disabled and re-enabled LMI and all is good again … for now.

Virus database @ VPS 071102-0 …

BTW, there is an active thread over at the LMI forum about this issue:

https://secure.logmein.com/forum/tm.aspx?m=11338 (you have to be logged in as a registered user to view it)

Maxx… thanks a bunch… you guys are doing great. The new release took care of everything. Best part is the LMI app was not affected as long as a connection attempt was not tried or if the PC was not rebooted…

In other words… no LMI connect or reboot, no problem! Some of the PCs I were concerned with are safe and didnt even notice the issue. Others can be addressed, but for the most part, this FP was nowhere near as damaging as it could have been for me and probably others, and even if it had been, it was nothing like I have experienced with other AV providers. Thanks again for the lightning fast response and attention to this issue.

Jason

Hi all, i have the same problem :

01/11/2007 19:10:25 SYSTEM 596 Sign of “Win32:Lmir-PG [Rtk]” has been found in “C:\WINDOWS\system32\LMIRfsClientNP.dll” file.
01/11/2007 19:10:53 SYSTEM 596 Sign of “Win32:Agent-MVH [Rtk]” has been found in “C:\WINDOWS\system32\LMIport.dll” file.
01/11/2007 19:12:18 admin 1884 Sign of “Win32:Vundo-gen53 [Adw]” has been found in “c:\windows\system32\lmiinit.dll” file.

I have sent an email to logmein customer support and this is their answer :

Hi,

As of 10/31/07, the latest version of Avast’s virus definitions has falsely identified some versions of the LogMeIn executables as being a virus. This is not the case, and your computer has not been infected by any malware in relation to this warning.

Avast has been notified of this false-positive, and is working to correct the error. Please disregard any messaging in Avast regarding LogMeIn until your next definition update.

More information on their issue can be found in there support forum’s posting on this:
http://forum.avast.com/index.php?topic=31255.0

I hope this helps. Please let us know if you have any further questions.

Thank you,
Wendy Merrifield
LogMeIn Customer Support

I’m also using LogMeIn (Free) and i haven’t encountered any problems with FP detection.

I would like to add something to this thread. I too had this problem, I was alerted and did the necessary steps to detect and moved said files to the “virus chest”. It was then suggested to do a “boot” virus scan which I did and it successfully found all files that were being called “ad-ware/key logger” or whatever the problem was. It moved the files to the chest that I agreed upon, finished and then booted up. :o

What I want to compliment on is that this is the first time, other than testing with “eicar” files, that I have seen how well this program works. It was great, it stepped you through all the processes and posted the information that you needed to know in a timely manner. It returned the system to login and went from there! :slight_smile:

I want to thank you guys for making a great product! ;D This is fantastic that I got to see what a great amount of effort on your part is put into this application! ;D

Keep up the good work!! :slight_smile:

Here, running Vista 32 bits, LogMeIn free, no problems with false positives.
Are you using the last virus database version?

The computer that I had this on was XPSP2 with LogMeIn Free and IT. I had what I thought were the latest at that point but I didn’t put the version down. I still have all the files in the “virus chest” and the program is operational. I didn’t know if someone wanted to look at them so I kept them until such time.

I came home today and I checked everything that was reporting problems yesterday, it had updated and there were no further problems. :slight_smile:

If you right click the files and scan them again, are they shown as infected?

Glad they seem to be corrected the false positive…

What I did today when I got home was do just that, I went and scanned the files that were giving me a problem and it didn’t show as being infected. :slight_smile:

It just updated again as I am writing this so I believe we are past the issues. :slight_smile:

One thing that I did want to say though is that when a virus is found and the option to send it to Avast is there, the file and a note, it doesn’t go through MAPI at all, this is what happens everytime. Is this address still the correct one?

“Your message did not reach some or all of the intended recipients.”

  Subject:	avast!
  Sent:	11/2/2007 6:38 PM

The following recipient(s) cannot be reached:

  [u]'virus@avast.com' [/u]  on 11/2/2007 6:38 PM
        None of your e-mail accounts could send to this recipient.

Did you try SMTP?
You must set your SMTP settings (right click the ‘a’ blue icon > Program settings > STMP).

That is weird as I can’t send using SMTP only MAPI, but I never get any error like email accounts couldn’t send to recipients.

I used to have similar errors not relating to sending to avast, but with a dial-up account if I tried to send an email where the account didn’t match the ISP I had connected to, changing the From email address (email account) to match the ISP I was connected to resolved the problem.

The other aspect is if your email account requires authentication, that may cause the send to fail, but I’m not sure if this would give the same result. Check the SMTP settings match your default account in your email client.

It sent that way, just wanted to see what was going on with doing it email. All the files currently in the “virus chest” have now been scanned and show “no virus”.

Another proof of the false positive nature of that alarm.