<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
	<title type="html"><![CDATA[DriverPacks.net Forum - [SLVD] False Pos. - Win32:Trojan-gen in LAN driverpack?]]></title>
	<link rel="self" href="http://forum.driverpacks.net/extern.php?action=feed&amp;tid=4104&amp;type=atom"/>
	<updated>2009-10-27T07:28:14Z</updated>
	<generator>PunBB</generator>
	<id>http://forum.driverpacks.net/viewtopic.php?id=4104</id>
		<entry>
			<title type="html"><![CDATA[Re: [SLVD] False Pos. - Win32:Trojan-gen in LAN driverpack?]]></title>
			<link rel="alternate" href="http://forum.driverpacks.net/viewtopic.php?pid=34652#p34652"/>
			<content type="html"><![CDATA[<p>LOL, thanks OverFlow, not sure whether to be flattered or embarassed now <img src="http://forum.driverpacks.net/img/smilies/smile.png" width="15" height="15" alt="smile" /><br />Marko</p>]]></content>
			<author>
				<name><![CDATA[marko2002]]></name>
				<uri>http://forum.driverpacks.net/profile.php?id=7804</uri>
			</author>
			<updated>2009-10-27T07:28:14Z</updated>
			<id>http://forum.driverpacks.net/viewtopic.php?pid=34652#p34652</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Re: [SLVD] False Pos. - Win32:Trojan-gen in LAN driverpack?]]></title>
			<link rel="alternate" href="http://forum.driverpacks.net/viewtopic.php?pid=34645#p34645"/>
			<content type="html"><![CDATA[<p>It is always good to err on the side of caution. No harm no foul!</p><p>You did exactly what I would expect anyone to do, if you smell smoke pull the fire alarm.</p><p>Thank you for reporting. Thank you even more for following up!</p><p>Have an awesome day!</p><p>By the By you have used some of the best posting technique i have ever seen...<br />almost as if you wrote <a href="http://www.catb.org/~esr/faqs/smart-questions.html">How To Ask Questions The Smart Way</a></p>]]></content>
			<author>
				<name><![CDATA[OverFlow]]></name>
				<uri>http://forum.driverpacks.net/profile.php?id=1097</uri>
			</author>
			<updated>2009-10-27T02:42:26Z</updated>
			<id>http://forum.driverpacks.net/viewtopic.php?pid=34645#p34645</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Re: [SLVD] False Pos. - Win32:Trojan-gen in LAN driverpack?]]></title>
			<link rel="alternate" href="http://forum.driverpacks.net/viewtopic.php?pid=34640#p34640"/>
			<content type="html"><![CDATA[<p>OK, I now find myslef apologizing profusely for this matter because I can now download the LAN driverpack without any problem at all after rebuild which has me baffled immensely.&nbsp; &nbsp;In my haste, I binned the XP build that affected my PC so I can&#039;t even scan it!.&nbsp; &nbsp;I can&#039;t possibly imagine where I&#039;ve picked this virus up from and Avast certainly didn&#039;t flag anything other than the LAN driverpack but it&#039;s now apparent this is not the case.&nbsp; &nbsp;Egg on my face somewhat, I&#039;m nevertheless relieved the driverpacks aren&#039;t affected and I think it&#039;s definately time for a new antivirus product as Avast obviously hasn&#039;t done it&#039;s job - moreso it was giving me wrong information the first time round, still can&#039;t put my finger on why it reported such and wrongly allowed what appears to be a Trojan into my system to do it&#039;s damage but hope I didn&#039;t cause any inconvenience to anyone here.<br />Somewhat embarassed, Marko</p><p>PS, just to be double certain I even scanned the pack using VirusTotal and clean bill of health throughout <img src="http://forum.driverpacks.net/img/smilies/smile.png" width="15" height="15" alt="smile" /></p>]]></content>
			<author>
				<name><![CDATA[marko2002]]></name>
				<uri>http://forum.driverpacks.net/profile.php?id=7804</uri>
			</author>
			<updated>2009-10-26T23:25:40Z</updated>
			<id>http://forum.driverpacks.net/viewtopic.php?pid=34640#p34640</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Re: [SLVD] False Pos. - Win32:Trojan-gen in LAN driverpack?]]></title>
			<link rel="alternate" href="http://forum.driverpacks.net/viewtopic.php?pid=34639#p34639"/>
			<content type="html"><![CDATA[<p>Guys, first off I will be the first to apologize if I have this totally wrong, but as I say in my post I can really only go on what I have at the moment and circumstances which at the moment only lead me to one possibility, the LAN driverpack.&nbsp; &nbsp;I will, holding my breath!!!!, download the LAN pack again and flag the alert to Avast and will help in any way I can as your driverpacks have been of immense use to me in the past and hopefully will continue to do so therefore it&#039;s really the least I can do.&nbsp; &nbsp;I will, of course, keep you updated on my progress and report from Avast.<br />Cheers the now<br />Marko</p>]]></content>
			<author>
				<name><![CDATA[marko2002]]></name>
				<uri>http://forum.driverpacks.net/profile.php?id=7804</uri>
			</author>
			<updated>2009-10-26T23:07:45Z</updated>
			<id>http://forum.driverpacks.net/viewtopic.php?pid=34639#p34639</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Re: [SLVD] False Pos. - Win32:Trojan-gen in LAN driverpack?]]></title>
			<link rel="alternate" href="http://forum.driverpacks.net/viewtopic.php?pid=34619#p34619"/>
			<content type="html"><![CDATA[<p>Marko, </p><p>RE: I don&#039;t know how else you could double check the LAN pack.</p><p>As suggested, the best way to deal with this, and put all of our minds at ease, is for you submit the specific file that was flagged to Avast for review. I am sure they have a procedure for this... and since you are their customer you should be supported.<br />alternately you could link them to the packs download...</p><p>A copy of your report from Avast (either clean or dirty) will put us all on the right track.</p><p>It never hurts to be careful and vigilant.</p><p>Thank you for Reporting it makes DriverPacks better for everyone.</p><p>We are now waiting for your response from Avast support... <br />If they are the first ones to identify this threat then perhaps we may see some new fans for Avast. <br />There are not many now because of its past history with providing false positives. <br />the only thing worse than a positive is a false positive <img src="http://forum.driverpacks.net/img/smilies/wink.png" width="15" height="15" alt="wink" />. because it wastes huge amounts of time.<br />Some other popular scanners are also known for wasting our time quite often and are also not used by many of us.</p><p>one of two things will result <br />a. we have a nasty we need to address<br />b. they have a definition that needs updated.</p><p>We are in a holding pattern waiting for your trouble ticket with avast to be answered.<br />We are unable, internaly, to confirm your report useing other scanners...<br />Avast is the only avenue that I am aware of to get a resolution at this point. </p><p>I agree the coinsidence is huge and worthy of our full attention. <br />however many of us host sites too...<br />Me for example, who has every pack ever relelased extracted on his machine.<br />none of my machines or servers has been compromized - not ever for that matter.<br />although I do often have some fun with the IPs that appear more than a few thousand times in my logs.<br />You would be amazed how many would be hackers out there who don&#039;t use proxy or a zombie.<br />Mmmm... script kiddy its whats for dinner... <img src="http://forum.driverpacks.net/img/smilies/wink.png" width="15" height="15" alt="wink" /></p><br /><p>PS I almost never load a machine with the network cable connected. <br />(Except on a well protected private corporate network with hardware and software firewalls Including gateway and per machine virus scanning) <br />It is almost impossable to load a machine these days without getting a virus during the installation , if direct internet access is available to the machine. No protection is in place during this time and patches may not yet be applied.</p><p>If we do have a nasty then we would like to know ASAP, Will you continue to help us to help you?</p><p>Jeff</p>]]></content>
			<author>
				<name><![CDATA[OverFlow]]></name>
				<uri>http://forum.driverpacks.net/profile.php?id=1097</uri>
			</author>
			<updated>2009-10-25T20:03:12Z</updated>
			<id>http://forum.driverpacks.net/viewtopic.php?pid=34619#p34619</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Re: [SLVD] False Pos. - Win32:Trojan-gen in LAN driverpack?]]></title>
			<link rel="alternate" href="http://forum.driverpacks.net/viewtopic.php?pid=34618#p34618"/>
			<content type="html"><![CDATA[<p>Just to be certain, I&#039;m tearing into the LAN dp now (release/nightlies).&nbsp; <br />Shields up!&nbsp; Arm the photon torpedoes!&nbsp; &nbsp;Fire all weapons!!!! <img src="http://forum.driverpacks.net/img/smilies/big_smile.png" width="15" height="15" alt="big_smile" /></p><p>Just completed scans.<br />DriverPack LAN 8.12.1 -- Clean<br />DriverPack LAN 9.09.04 -- Clean<br />Used both Eset NOD32 and Symantec Endpoint Security (both updated to latest engines/defs).</p>]]></content>
			<author>
				<name><![CDATA[mr_smartepants]]></name>
				<uri>http://forum.driverpacks.net/profile.php?id=1602</uri>
			</author>
			<updated>2009-10-25T16:47:57Z</updated>
			<id>http://forum.driverpacks.net/viewtopic.php?pid=34618#p34618</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Re: [SLVD] False Pos. - Win32:Trojan-gen in LAN driverpack?]]></title>
			<link rel="alternate" href="http://forum.driverpacks.net/viewtopic.php?pid=34617#p34617"/>
			<content type="html"><![CDATA[<p>OK, PC rebuilt, passwords all changed and breathing normally once again!.</p><p>Now as I say, I can&#039;t put the LAN pack at fault for the virus we received but as this has never happened to us before I&#039;m merely going on circumstances, that being when I integrated the LAN pack into a new build of XP yesterday and rebuilt my machine we all of a sudden had our main site taken down and compromised.&nbsp; &nbsp;Our host has confirmed that in his experience the problem could only have been caused by &quot;a trojan/virus has obtained your FTP password and as such your files have been downloaded+modified+uploaded&quot;.</p><p>Our index file was downloaded and uploaded again in a matter of 3 seconds and many files on the server were modified to render the site useless.&nbsp; &nbsp;They also attempted to include an iFrame in the site to potentially send our members viruses or redirect them to an undesireable site but they basically made a complete ass of things, bottom line is the succeeded in causing us grief.</p><p>I don&#039;t know how else you could double check the LAN pack and I understand it&#039;s obviously checked and used by many many people but in my case I can&#039;t put the Trojan down to anything else, I&#039;ve trawled my own movements and can&#039;t recall any such warning on my AV for a long time - I sincerely hope it proves not to be the LAN pack but I thought I&#039;d update you anyway, just in case.</p><p>Cheers<br />Marko</p>]]></content>
			<author>
				<name><![CDATA[marko2002]]></name>
				<uri>http://forum.driverpacks.net/profile.php?id=7804</uri>
			</author>
			<updated>2009-10-25T16:28:12Z</updated>
			<id>http://forum.driverpacks.net/viewtopic.php?pid=34617#p34617</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Re: [SLVD] False Pos. - Win32:Trojan-gen in LAN driverpack?]]></title>
			<link rel="alternate" href="http://forum.driverpacks.net/viewtopic.php?pid=34615#p34615"/>
			<content type="html"><![CDATA[<p>OF, I&#039;m not sure if this is connected but the coincedence is a little too strong for my liking - basically I&#039;m now just about to rebuild my computer after integrating the LAN pack into my latest build and using that to rebuild as one of my most successful sites (<a href="http://www.freewarebb.com">www.freewarebb.com</a>) has been taken down by a hacker and we have full logs, etc that clearly show FTP connections using passwords only I would know - this has never happened before and I can only presume the alert was a real one and not a false positive as we first thought.&nbsp; &nbsp;Our host was quick to respond and has went into lockdown and is restoring the site as we speak and once I have rebuilt my comp I will PM you the details if you wish for further analysis.<br />Cheers<br />Marko</p>]]></content>
			<author>
				<name><![CDATA[marko2002]]></name>
				<uri>http://forum.driverpacks.net/profile.php?id=7804</uri>
			</author>
			<updated>2009-10-25T14:49:44Z</updated>
			<id>http://forum.driverpacks.net/viewtopic.php?pid=34615#p34615</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Re: [SLVD] False Pos. - Win32:Trojan-gen in LAN driverpack?]]></title>
			<link rel="alternate" href="http://forum.driverpacks.net/viewtopic.php?pid=34588#p34588"/>
			<content type="html"><![CDATA[<p>I was waiting to see if anyone else posted <img src="http://forum.driverpacks.net/img/smilies/wink.png" width="15" height="15" alt="wink" /></p><p>since the DriverPacks are worked on and then tested by a large team and then released to a large audience Many different virus scanners get a crack at the packs at every stage of development and release... if only one AV program is reporting a result then there is a 99.99 percent likelyhood that it is a false positive.</p><p>On the other hand there are hundreds of new viruses and trojans each month... <br />There is the .01 percent chance that your AV / defs is the first one to be able to detect it...&nbsp; </p><p>I would submit to them for review... why take our word for it?... go straight to the source and get the poop.<br />it would be even better if you could reply here that they responded to you taht they thought it was a false positive.<br />then you have saved not only yourself, but others in your situation. (they update the definitions for everyone)<br />&quot;Help us to help you&quot; is the spirit of DriverPacks, a spirit you obviously share with us.</p><p>I would have seemed a little daft if I had simply dissmissed you without considering the .01 probablity and anounced there was no virus... and then got bitten by that .01 LOL</p><p>Well Done! Excellent report!</p><p>Welcome to DriverPacks and we are glad you&#039;re here!</p><p>PS you never told us which LAN pack version?</p>]]></content>
			<author>
				<name><![CDATA[OverFlow]]></name>
				<uri>http://forum.driverpacks.net/profile.php?id=1097</uri>
			</author>
			<updated>2009-10-23T21:53:52Z</updated>
			<id>http://forum.driverpacks.net/viewtopic.php?pid=34588#p34588</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Re: [SLVD] False Pos. - Win32:Trojan-gen in LAN driverpack?]]></title>
			<link rel="alternate" href="http://forum.driverpacks.net/viewtopic.php?pid=34578#p34578"/>
			<content type="html"><![CDATA[<p>Thought that, but would av looked a little daft if I didn&#039;t ask and allowed a virus in knowlingly - I&#039;ve used the driverpacks in the past no problem, just this version of Avast is shouting but hopefully he&#039;ll flag it to Avast and have it sorted <img src="http://forum.driverpacks.net/img/smilies/smile.png" width="15" height="15" alt="smile" /><br />Cheers<br />Marko</p>]]></content>
			<author>
				<name><![CDATA[marko2002]]></name>
				<uri>http://forum.driverpacks.net/profile.php?id=7804</uri>
			</author>
			<updated>2009-10-23T17:16:29Z</updated>
			<id>http://forum.driverpacks.net/viewtopic.php?pid=34578#p34578</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Re: [SLVD] False Pos. - Win32:Trojan-gen in LAN driverpack?]]></title>
			<link rel="alternate" href="http://forum.driverpacks.net/viewtopic.php?pid=34574#p34574"/>
			<content type="html"><![CDATA[<p>Trust me.&nbsp; All the DriverPacks are clean!</p>]]></content>
			<author>
				<name><![CDATA[mr_smartepants]]></name>
				<uri>http://forum.driverpacks.net/profile.php?id=1602</uri>
			</author>
			<updated>2009-10-23T14:37:42Z</updated>
			<id>http://forum.driverpacks.net/viewtopic.php?pid=34574#p34574</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Re: [SLVD] False Pos. - Win32:Trojan-gen in LAN driverpack?]]></title>
			<link rel="alternate" href="http://forum.driverpacks.net/viewtopic.php?pid=34572#p34572"/>
			<content type="html"><![CDATA[<p>OverFlow, I&#039;m guessing this is a false positive then and not some unexpected addition to the LAN driverpack? Just wanted to make sure before I turned off the web-shield for Avast <img src="http://forum.driverpacks.net/img/smilies/smile.png" width="15" height="15" alt="smile" /><br />Cheers<br />Marko</p>]]></content>
			<author>
				<name><![CDATA[marko2002]]></name>
				<uri>http://forum.driverpacks.net/profile.php?id=7804</uri>
			</author>
			<updated>2009-10-23T14:26:19Z</updated>
			<id>http://forum.driverpacks.net/viewtopic.php?pid=34572#p34572</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Re: [SLVD] False Pos. - Win32:Trojan-gen in LAN driverpack?]]></title>
			<link rel="alternate" href="http://forum.driverpacks.net/viewtopic.php?pid=34523#p34523"/>
			<content type="html"><![CDATA[<p>Avast 21/10/2009 18:03:08<br />Version 091021-0<br />It&#039;s Avast Home Edition Beta</p><p>Hope that helps <img src="http://forum.driverpacks.net/img/smilies/smile.png" width="15" height="15" alt="smile" /><br />Cheers<br />Marko</p>]]></content>
			<author>
				<name><![CDATA[marko2002]]></name>
				<uri>http://forum.driverpacks.net/profile.php?id=7804</uri>
			</author>
			<updated>2009-10-22T06:32:57Z</updated>
			<id>http://forum.driverpacks.net/viewtopic.php?pid=34523#p34523</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Re: [SLVD] False Pos. - Win32:Trojan-gen in LAN driverpack?]]></title>
			<link rel="alternate" href="http://forum.driverpacks.net/viewtopic.php?pid=34521#p34521"/>
			<content type="html"><![CDATA[<p>It is known now <img src="http://forum.driverpacks.net/img/smilies/wink.png" width="15" height="15" alt="wink" />...</p><p>Thanks for reporting!</p><p>Welcome to DriverPacks and have a great day.</p><p>PS which definition version gave the false positive... (date/ver)</p>]]></content>
			<author>
				<name><![CDATA[OverFlow]]></name>
				<uri>http://forum.driverpacks.net/profile.php?id=1097</uri>
			</author>
			<updated>2009-10-21T21:30:59Z</updated>
			<id>http://forum.driverpacks.net/viewtopic.php?pid=34521#p34521</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[[SLVD] False Pos. - Win32:Trojan-gen in LAN driverpack?]]></title>
			<link rel="alternate" href="http://forum.driverpacks.net/viewtopic.php?pid=34519#p34519"/>
			<content type="html"><![CDATA[<p>Hi, I&#039;m downloading the LAN driverpack though I&#039;m being told by Avast that the download contains Win32:Trojan-gen and thus aborts the download.&nbsp; &nbsp;Is this a known false-positive or is there something else amiss here?<br />Thanks in advance<br />Marko</p>]]></content>
			<author>
				<name><![CDATA[marko2002]]></name>
				<uri>http://forum.driverpacks.net/profile.php?id=7804</uri>
			</author>
			<updated>2009-10-21T18:53:24Z</updated>
			<id>http://forum.driverpacks.net/viewtopic.php?pid=34519#p34519</id>
		</entry>
</feed>
