2013. március 29., péntek

Is hwinfo.com infected?

My story starts with my mother's problem. She complained me about her computer which turned off after several minutes of working. I decided to clean its heatsink, but it was pretty clean, so I decided to not take apart the notebook, because I didn't yet have any thermal paste.
Well this isn't special thing, but I really wanted to make sure, that the CPU's overheating, so I downloaded and sent her the hwinfo32 application, which I use to monitor the CPU temperature. Then surprise happened:


I downloaded and sent the portable version over Skype ( quite a modern family, isn't? :D ). When she tried to use the program the AVG antivirus warned her. What the heck? The antivirus detected some trojan in the executable.
OK, shit happens, I have little beasts on my computer.Since I insisted on measuring the CPU temp, I decided to use her computer for downloading the program and guess what? Yes, it was infected again. Hmmm, that was very strange. I supposed that my computer with Microsoft Security Essentials has no trojans and her notebook with AVG antivirus has got some, that makes the false warnings appear. But the really weird stuff came up, when I checked the hwinfo's homepage in AVG's online link checker and taddam: it says that several threats were reported from this site involving Win/Heur trojan.Ahh, that's not cool.

I considered the hwinfo as a safe program and I run it in administrator mode ( which is of course needed to detect the system properties ). MSE didn't do anything, maybe it's waiting for some updates. Now I don't know what is the truth. I doubt that the hwinfo team intentionally spreads a virus. Maybe, someone hacked their site or maybe some false positive alert?
At least I try to investigate something about this case.

Nincsenek megjegyzések:

Megjegyzés küldése