Announcement

Collapse
No announcement yet.

Antivir Virus found in Daemon Tools Pro

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

  • Sabrehawk
    replied
    Since the file is encrypted anti-vir just cant say whats in it
    and thats why it sounds the alarm. Add it to encryption.

    This has been known since release ...and has been posted
    multiple times.

    Leave a comment:


  • y0himba
    replied
    In Antivir's options you can exclude files from scans and the resident guard. I have done that since I was also getting the warning and only with Antivir. Avira needs to update their definitions and detection algorithms to exclude this file.

    Leave a comment:


  • Sir Camehan
    replied
    Maybe it's not really adware either, again I don't know. I can see why the content can seem suspicious anyway.
    Could be due to extra encryption, but the adware is definately not physically in the library.

    Leave a comment:


  • lmgava
    replied
    Originally Posted by Sir Camehan View Post
    Maybe, since thats for the adware version, thats what its also wrapped with. With the retail however, its wrapped in something a lot stronger......in addition to UPX.
    Sorry, I was talking about the dll I have on my pc, and I have the DT PRO retail. I never installed the adware version.

    Reading this thread and since I saw the strings I mentioned, I supposed it's the same dll in both cases. Maybe I'm wrong, I never saw the adware version as I said.

    Addendum: just tried with virustotal too. I got the same results reported here previously, so I really believe the dll it's the same. Maybe it's inactive in the retail version. I don't know. Maybe it's not really adware either, again I don't know. I can see why the content can seem suspicious anyway.
    Last edited by lmgava; 11.07.2007, 11:00.

    Leave a comment:


  • Sir Camehan
    replied
    Maybe, since thats for the adware version, thats what its also wrapped with. With the retail however, its wrapped in something a lot stronger......in addition to UPX.

    Leave a comment:


  • lmgava
    replied
    Originally Posted by Sir Camehan View Post
    Knowing the DT team, its more than wrapped with UPX, since UPX is incredibly easy to unwrap
    Well, the DLL seems to be in fact packed with UPX. When unpacked you find these strings inside :

    WHENU.COM INC VeriSign Class 3 Code Signing 2004 CADAEM Partner InstallTime SOFTWARE\WhenUSave\Partners Save.exe none wusa
    ve wubar wusv
    br whse.exe

    So probaby it's why the AV is reporting it.
    Last edited by lmgava; 11.07.2007, 00:07.

    Leave a comment:


  • blackkanto
    replied
    Originally Posted by LocutusofBorg View Post
    please WHAT??
    Damn, that guys at Avira soon drives us nuts!
    We even have a customer who is in beta-team there.
    Maybe we now have to announce to not use Avira anymore
    but something else when you plan to use DT Pro. It is obvious
    they are not capable to handle complex process to identify
    real spyware/adware and a LICENSEkeyfile which has ABSOLUTLEY
    NO adware NOR spyware in it.
    My goodness
    its because of this post.... and its kinda fishy putting the adware in a .dll that appears to be related to help for DT Pro, they could have made it plain in sight the name of the adware or something along those lines, why go through all the trouble to make it in to something else?

    Leave a comment:


  • Jito463
    replied
    Originally Posted by blackkanto View Post
    I think you guys should just come clean and say that that file is where the adware is; because according to the latest beta of ESS ( Eset Smart Security), dtprohlp.dll is a variant of Win32/Adware.WhenU.SaveNow and heres a picture to prove it,
    The DTools team has always been upfront about the adware included in the standard and the ad-supported versions, so why would they try to hide it now?

    Leave a comment:


  • DariusIII
    replied
    Originally Posted by blackkanto View Post
    I think you guys should just come clean and say that that file is where the adware is; because according to the latest beta of ESS ( Eset Smart Security), dtprohlp.dll is a variant of Win32/Adware.WhenU.SaveNow and heres a picture to prove it,
    Is it maybe because you are using an adware version of DT?

    Leave a comment:


  • obvious
    replied
    Latest from Avira :-
    File ID Filename Size (Byte) Result
    1098649 dtprohlp.dll 367.95 KB FALSE POSITIVE


    Please find a detailed report concerning each individual sample below:
    Filename Result
    dtprohlp.dll FALSE POSITIVE

    The file 'dtprohlp.dll' has been determined to be 'FALSE POSITIVE'. In particular this means that this file is not malicious but a false alarm. Detection will be removed from our virus definition file (VDF) with one of the next updates.

    Leave a comment:


  • blackkanto
    replied
    Hmmm...

    I think you guys should just come clean and say that that file is where the adware is; because according to the latest beta of ESS ( Eset Smart Security), dtprohlp.dll is a variant of Win32/Adware.WhenU.SaveNow and heres a picture to prove it,

    Leave a comment:


  • Sir Camehan
    replied
    Knowing the DT team, its more than wrapped with UPX, since UPX is incredibly easy to unwrap

    I've been using Bitdefender 8 for ages and I havent ran into any false positives yet with packed/encrypted files That says something about this Avira crap which I tried in the past...

    Leave a comment:


  • obi1kenobi
    replied
    Obviously if the malware is found via heuristics, then it's just an assumption. IMAO, their heuristics engine is flawed.

    Leave a comment:


  • obvious
    replied
    The majority of scanners get it right :-

    Shot at 2007-07-07

    Leave a comment:


  • chrashoverraid
    replied
    maybe you can try to get in touch with them.. and explain them that it is definitely not malware!

    Leave a comment:

Working...
X