his is a multi-part message in MIME format.
Hi:
I found the Constructor.Win32.Downldr.ek virus in a MS file I had lying around in My Documents. Zone Alarm Security Suite 7.0.483.000 picked it up on a scheduled scan.
The file is named: WindowsXP-KB838079-SupportTools-ENU.exe
and can be downloaded from:
http://www.microsoft.com/downloads/details.aspx?FamilyID=49ae8576-9bb9-4126-9761-ba8011fabf38&DisplayLang=en
After it was quarantined, I tried downloading it again as a fresh copy from the MS download link above. It too showed the:
Constructor.Win32.Downldr.ek
virus.
I submitted the newly downloaded file to www.virustotal.com
It showed that both Kaspersky and F-Secure detect that same virus. F-Prot shows it to be a damaged file. The other 33 engines found nothing wrong in this file
I'm puzzled by these findings.
Could it be that Microsoft has an infected and/or damaged file on its download site?
Or is this a false positive?
Thanks in advance:
-Eli
================
Windows XP Profesional Edition SP3
Zone Alarm Security Suite 7.0.483.000
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML><HEAD>
<META http-equiv=Content-Type content="text/html; charset=iso-8859-1">
<META content="MSHTML 6.00.6000.16705" name=GENERATOR>
<STYLE></STYLE>
</HEAD>
<BODY>
<DIV><FONT face=Arial size=2>Hi:</FONT></DIV>
<DIV><FONT face=Arial size=2></FONT> </DIV>
<DIV><FONT face=Arial size=2>I found the
<STRONG>Constructor.Win32.Downldr.ek</STRONG> virus in a MS file I had
lying around in My Documents. Zone Alarm Security Suite 7.0.483.000 picked it up
on a scheduled scan.</FONT></DIV>
<DIV><FONT face=Arial size=2></FONT> </DIV>
<DIV><FONT face=Arial size=2>The file is named:
<STRONG>WindowsXP-KB838079-SupportTools-ENU.exe</STRONG></FONT></DIV>
<DIV><STRONG><FONT face=Arial size=2></FONT></STRONG> </DIV>
<DIV><FONT face=Arial size=2>and can be downloaded from:</FONT></DIV>
<DIV><FONT face=Arial size=2></FONT> </DIV>
<DIV><FONT face=Arial size=2><A
href="http://www.microsoft.com/downloads/details.aspx?FamilyID=49ae8576-9bb9-4126-9761-ba8011fabf38&DisplayLang=en">http://www.microsoft..com/downloads/details.aspx?FamilyID=49ae8576-9bb9-4126-9761-ba8011fabf38&DisplayLang=en</A></FONT></DIV>
<DIV><FONT face=Arial size=2></FONT> </DIV>
<DIV><FONT face=Arial size=2>After it was quarantined, I tried downloading it
again as a fresh copy from the MS download link above. It too showed
the:</FONT></DIV>
<DIV><FONT face=Arial size=2></FONT> </DIV>
<DIV><FONT size=2><FONT
face=Arial><STRONG>Constructor.Win32.Downldr.ek</STRONG>
</FONT></FONT></DIV>
<DIV><STRONG><FONT face=Arial size=2></FONT></STRONG> </DIV>
<DIV><FONT face=Arial size=2>virus.</FONT></DIV>
<DIV><FONT face=Arial size=2></FONT> </DIV>
<DIV><FONT face=Arial size=2>I submitted the newly downloaded file to <