Since the file is encrypted anti-vir just cant say whats in it
and thats why it sounds the alarm. Add it to encryption.
This has been known since release ...and has been posted
multiple times.
Announcement
Collapse
No announcement yet.
Antivir Virus found in Daemon Tools Pro
Collapse
X
-
In Antivir's options you can exclude files from scans and the resident guard. I have done that since I was also getting the warning and only with Antivir. Avira needs to update their definitions and detection algorithms to exclude this file.
Leave a comment:
-
Could be due to extra encryption, but the adware is definately not physically in the library.Maybe it's not really adware either, again I don't know. I can see why the content can seem suspicious anyway.
Leave a comment:
-
Sorry, I was talking about the dll I have on my pc, and I have the DT PRO retail. I never installed the adware version.Originally Posted by Sir Camehan View PostMaybe, since thats for the adware version, thats what its also wrapped with. With the retail however, its wrapped in something a lot stronger......in addition to UPX.
Reading this thread and since I saw the strings I mentioned, I supposed it's the same dll in both cases. Maybe I'm wrong, I never saw the adware version as I said.
Addendum: just tried with virustotal too. I got the same results reported here previously, so I really believe the dll it's the same. Maybe it's inactive in the retail version. I don't know. Maybe it's not really adware either, again I don't know. I can see why the content can seem suspicious anyway.Last edited by lmgava; 11.07.2007, 11:00.
Leave a comment:
-
Maybe, since thats for the adware version, thats what its also wrapped with. With the retail however, its wrapped in something a lot stronger......in addition to UPX.
Leave a comment:
-
Well, the DLL seems to be in fact packed with UPX. When unpacked you find these strings inside :Originally Posted by Sir Camehan View PostKnowing the DT team, its more than wrapped with UPX, since UPX is incredibly easy to unwrap
WHENU.COM INC VeriSign Class 3 Code Signing 2004 CADAEM Partner InstallTime SOFTWARE\WhenUSave\Partners Save.exe none wusa
ve wubar wusv
br whse.exe
So probaby it's why the AV is reporting it.Last edited by lmgava; 11.07.2007, 00:07.
Leave a comment:
-
its because of this post.... and its kinda fishy putting the adware in a .dll that appears to be related to help for DT Pro, they could have made it plain in sight the name of the adware or something along those lines, why go through all the trouble to make it in to something else?Originally Posted by LocutusofBorg View Postplease WHAT??
Damn, that guys at Avira soon drives us nuts!
We even have a customer who is in beta-team there.
Maybe we now have to announce to not use Avira anymore
but something else when you plan to use DT Pro. It is obvious
they are not capable to handle complex process to identify
real spyware/adware and a LICENSEkeyfile which has ABSOLUTLEY
NO adware NOR spyware in it.
My goodness
Leave a comment:
-
The DTools team has always been upfront about the adware included in the standard and the ad-supported versions, so why would they try to hide it now?Originally Posted by blackkanto View PostI think you guys should just come clean and say that that file is where the adware is; because according to the latest beta of ESS ( Eset Smart Security), dtprohlp.dll is a variant of Win32/Adware.WhenU.SaveNow and heres a picture to prove it,
Leave a comment:
-
Is it maybe because you are using an adware version of DT?Originally Posted by blackkanto View Post
Leave a comment:
-
Latest from Avira :-
File ID Filename Size (Byte) Result
1098649 dtprohlp.dll 367.95 KB FALSE POSITIVE
Please find a detailed report concerning each individual sample below:
Filename Result
dtprohlp.dll FALSE POSITIVE
The file 'dtprohlp.dll' has been determined to be 'FALSE POSITIVE'. In particular this means that this file is not malicious but a false alarm. Detection will be removed from our virus definition file (VDF) with one of the next updates.
Leave a comment:
-
-
Knowing the DT team, its more than wrapped with UPX, since UPX is incredibly easy to unwrap
I've been using Bitdefender 8 for ages and I havent ran into any false positives yet with packed/encrypted files
That says something about this Avira crap which I tried in the past...
Leave a comment:
-
Obviously if the malware is found via heuristics, then it's just an assumption. IMAO, their heuristics engine is flawed.
Leave a comment:
-
maybe you can try to get in touch with them.. and explain them that it is definitely not malware!
Leave a comment:



Leave a comment: