Mozy backup

Hey guys,

Ive been looking through for backup for files and on Download.com got Mozy online backup and well I was doing a recent scan yesterday with Avira (I feel like a traitor :() and it detected DR/WSearch.BL in the downloaded Mozy File (not installed yet) and just a few minutes ago it was detected in a restore point (I’m guessing from a few days ago) so I cleared out all my restore points and made a new one, in quarantine I scanned and rescanned in case of false positive but each time reported the same infection. I know this isn’t the avira forums but I love this forum. So does anyone have any idea on this?

Hey… you’ve give up on us ::slight_smile:
Do you mean a restore backup from Mozy or the setup (install) of it?

No ive not give up on you guys im just using it for right now because of symantec being on here (disabled) it stinks though compared to avast (doesn’t block downloads) and no IM shield either but first it detected the setup file on my desktop and then just about 30 min ago when i posted it detected again in System Volume Information so im guessing it was a backup of the file

Mozy is a clean software. It seems a clearly false positive.
If you want to be sure, use www.virustotal.com :wink:

alright ill re-download the file and submit it then post back if anything comes back

Alright that was fun everytime i did anything with the file it set avira off I was to lazy to turn it off for a second =P but heres what came up, its funny Avira didnt detect it on VirusTotal

File mozy-1_8_4_3-279.exe received on 03.31.2008 17:20:33 (CET)
Current status: finished
Result: 2/32 (6.25%)
Compact Compact
Print results Print results
Antivirus Version Last Update Result
AhnLab-V3 2008.4.1.0 2008.03.31 -
AntiVir 7.6.0.78 2008.03.31 -
Authentium 4.93.8 2008.03.30 -
Avast 4.7.1098.0 2008.03.30 -
AVG 7.5.0.516 2008.03.31 -
BitDefender 7.2 2008.03.31 -
CAT-QuickHeal 9.50 2008.03.31 -
ClamAV 0.92.1 2008.03.31 -
DrWeb 4.44.0.09170 2008.03.31 -
eSafe 7.0.15.0 2008.03.30 -
eTrust-Vet 31.3.5658 2008.03.31 -
Ewido 4.0 2008.03.31 -
F-Prot 4.4.2.54 2008.03.30 -
F-Secure 6.70.13260.0 2008.03.31 -
FileAdvisor 1 2008.03.31 -
Fortinet 3.14.0.0 2008.03.31 -
Ikarus T3.1.1.20 2008.03.31 -
Kaspersky 7.0.0.125 2008.03.31 not-a-virus:AdWare.Win32.WSearch.bl
McAfee 5262 2008.03.28 -
Microsoft 1.3301 2008.03.31 -
NOD32v2 2987 2008.03.31 -
Norman 5.80.02 2008.03.31 -
Panda 9.0.0.4 2008.03.31 -
Prevx1 V2 2008.03.31 Heuristic: Suspicious File With Bad Parent Associations
Rising 20.38.01.00 2008.03.31 -
Sophos 4.28.0 2008.03.31 -
Sunbelt 3.0.978.0 2008.03.18 -
Symantec 10 2008.03.31 -
TheHacker 6.2.92.259 2008.03.30 -
VBA32 3.12.6.3 2008.03.25 -
VirusBuster 4.3.26:9 2008.03.31 -
Webwasher-Gateway 6.6.2 2008.03.31 -

Another reason to think it’s a false positive…
Why don’t you come back to avast? ;D ;D

Im going to as soon as the IT guys unlock our computers after I buy It. I have tried to remove Symatec Antivirus but its locked, it requires a password which I don’t have and Avast and Symantec conflicted to a point it was bothersom and Avira doesnt (well not so obvious) but im going back to avast asap

Ridiculous… Another Symantec joke…

Yeah, It stinks, I tried for about 30 minutes a variety of different passwords with no luck so i just gave up and went into msconfig and unchecked it from startup so I dont have to deal with it, Oh might I add that upon startup RTVscan (from symantec) takes 45K?, now thats what I call a resource hog

Or were you saying I was making a symantec joke Tech? sorry cause I wasnt =[ it really is locked

I believe it’s locked… I believe any mad thing that come with Symantec software…
I suppose you’ve tested ‘admin’ as a password…
Is there any tip into Symantec website about OEM installations?

Yeah I cant stand Symantec the bloat and all of it sucks not only that but it misses a few common trojan’s but anyways yeah I tested Admin its still locked, but no I havent checked the website ill have to look around, thanks

Maybe this helps…
http://www.softpedia.com/get/Security/Decrypting-Decoding/OEM-Password-Recovery.shtml
At least, Google says…

Also
http://www.mydigitallife.info/2007/05/05/hack-to-removeuninstall-symantec-norton-antivirus-sav-client-without-password/

Seems that symantec is the password.

ooh, thats a nice little piece of software =) thanks again

Be very careful about uninstalling or disabling symantec. Fighting the IT department on Security issues is not wise. Some companies penalize employees who compromise the security of the network. Even though we may think avast is better, if your IT department chose Syamntec that should be on that PC and chances are its reporting back to a Windows server and they will know if its uninstalled

True, luckily Im not a employee now that ive learned that

Justin_xp,

Always remember this is NEVER mess around with a company work computer and it not your problems to go chasing around fixing it, let the company IT deal with the problem not you doesn’t matter what software they used.

I’ve been through this many many time with my IT when they installed a Symatec Antivirus network platform to all company computers, only problem you get a trojan’s when you open an email or a zip file by mistake the virus can spread through the network and pass through the staff computers.

Most IT companies don’t keep the security patches up to date can be a real pain in the A$$, and the only worst nightmare when it spread is some knuckle head in the office open the file by mistake and it takes a long time to go chasing around to every computer to clean them out.

Believe me this I’ve lost over million dollars worth a project CAD drawings file data working in an engineering firm, when IT don’t do an everyday network backup and when the virus spread depend how bad it is some drawings file data can never be recovered cause some knuckle head in the office open the file by mistake.

IF you own your PC at home than yes you can remove Symatec Antivirus, as long it a home computer not a company computer as Mac said fighting the IT department on Security issues is not wise.

Well, does the second work for you?

Yeah it worked thanks again Tech and ive read what everyone else said as soon as they unlock the computers on May 9th im giving symantec the boot and putting on Avast, Superantispyware, spware terminator, Spybot, and Comodo for a firewall