False Positive With PowerPoint?

Hello All,

I think my problem is this, I´m victim of false positives with PowerPoint from Microsoft.
I use Windows XP Home Edition with SP 3.0 in a laptop with Windows Firewall activated as the only firewall. Installed the Avast! v 4.8 Personal Edition and Lavasoft Ad-Aware v 7.1.0.12. No others security programs.

When I try to open a PowerPoint presentation, my Avast! says my system has traces of a malware named ‘Win32:Trojan-gen {Other}’ in C:\Archivos de programa\Microsoft Office\Office\POWERPNT.EXE and doesn´t open it.
I scanned the presentation apart and no viruses were found on it, and when I disabled the antivirus I am able to open the presentation easily. It happens with all of my powerpoint files.

My PowerPoint version is from Microsoft Office 2000 Premium.

Has anybody had the same problem? And how I could fix it?

Thanks in advance.

kudo

Try update you version of powerpoint.

First, I’m going to say that unfortunately Ad-Aware isn’t exactly the best program out there (anymore) for malware detection / removal. I’d uninstall that.

Replace it with Malwarebytes from http://www.malwarebytes.org and / or Super Anti-spyware http://www.superantispyware.com

Now, as for the detected file, is it really powerpnt.exe that’s being detected? Has Avast put that file in the quarantine?

If not, please upload that particular file to http://www.virustotal.com and paste the log here.

I can’t remember what the filenames for office 2000 programs are, but I thought office 2k’s version of power point’s exe file was powerpoint.exe. I could be wrong.

Anyway, let us know what virustotal.com says about that file.

We may have a rootkit here, and you’ll have to download hijackthis so we can get a better idea of what’s infected.

Hi again,

Avast! didn´t put the file in quaratine, so I sent my POWERPNT.EXE to Virustotal and this is the result:

http://www.virustotal.com/es/analisis/d4fcad1c61602e75a19693b761971704

I can´t paste the full log because it exceeds the maximum allowed lenght for the posts.

It seems that it has been reported before and only 13 of the 40 antivirus programs detected it as a virus.

I also noticed that the POWERPNT.EXE icon disappears in the Office folder and is replaced by a windows generic icon when Avast! is activated and remains ok when Avast! is deactivated.

And surprise!..in my desk computer running the same Windows XP Home Edition SP 3.0 with the same Avast! version nothing happens. The same POWERPNT.EXE from the same installation disk in running happily without any problem. How can you explain that?.. ??? ??? ???

kudo

Seems an infected file. The correct file could be in a subfolder of that particular one, at least it seems for Office 2003 and Office 2007.

Yes, it is in a subfolder named ‘Office’ of a folder named ‘Microsoft Office’.

And here is my my Hijackthis log. Again, sorry for not paste the entire document. It exceeds the allowed lenght.

Thanks so much for your help.

kudo

kudo, I’m not an expert on HijackThis. Hope someone else could help.


Welcome to the forums, kudo. :slight_smile:

An analysis of your HJT log shows the following :

We didn’t detect any active process of a firewall on your system. Reasons maybe:
(1.) You are using the windows firewall or a hardware firewall.
(2.) You are using a firewall of an unknown vendor.
(3.) You are using a firewall, but for unknown reasons it is disabled
(4.) You don’t use any firewall at all.
We recommend you to use a firewall.

These 2 entries should be fixed with HJT :

O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
Belongs to Windows Live Messenger add-on but has been deactivated.
http://www.systemlookup.com/CLSID/54865-wlchtc_dll.html

O20 - AppInit_DLLs:
http://blogs.msdn.com/oldnewthing/archive/2007/12/13/6648400.aspx


CharleyO, yes, I’m using windows firewall AND my router’s firewall.

But, what about my problem with Powerpoint? Fixing these two lines should resolve it? I have no idea of dealing with Hijackthis or programming at all, I’m only a basic user of windows and cannot understand the meaning of the links you posted. Sorry for my ignorance, but I need much more basic instructions… :-\

Anyway, thanks for your try!


I can not say that fixing the 2 entries will help your powerpoint problem but fixing those 2 entries will not hurt.

The first entry, 02, has nothing to do with it for sure, but, fixing this entry will clean out a registry entry that is no longer in use. At some time, you probably used Live Messenger but since this entry no longer has a file associated with it, it is of little use. So, fixing it with HJT removes an invalid registry entry.

The second entry, 020, is an “open door” for malware to do whatever it wants to. It is possible that if you do have an infection on your computer that has infected your powerpoint files, then this may be a way for it to happen.
An example of this can be found in the link below. Scroll down to be box labled Registry.
http://www.avira.com/en/threats/section/fulldetails/id_vir/3265/tr_drop.stration.677.html
This entry really does need to be fixed with HJT.


Hi CharleyO,

I´ve just deleted the two entries and I hope my computer be safer now. I was really afraid of making something wrong with HijackThis, but it has been easier than I expected. I´m very clumsy with computers… :-[

Sadly, my problem persists. I hope someone anywhere be able to explain what is happening to my powerpoint…I really cannot understand why it works well in my desktop but not in my laptop.

Again, thank you so much

kudo

Finally, I’ve desisted. After deeply cleaning my laptop I scanned with Avast and Kaspersky. All was ok. No virus found. But reinstalling Office the problem returned. Again the same supposed ‘virus’. Again a new cleaning.

At last, I replaced the POWERPNT.EXE file in the Office subfolder from the desktop to the laptop, and all worked well…!!! Avast remained quiet…!!! :o :o :o

May it be a matter of ‘environment’?. Why the same installation disk gives me a ‘virus’ in a computer but not in the other?

Is avast updated in both computers?

Yes, both they have the same last version.

kudo

So, remain a mystery for me… ::slight_smile:

Microsoft Security Advisory (969136)

http://www.microsoft.com/technet/security/advisory/969136.mspx