<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0">
	<channel>
		<title><![CDATA[DriverPacks.net Forum - [SLVD] False Pos. - Win32:Trojan-gen in LAN driverpack?]]></title>
		<link>http://forum.driverpacks.net/viewtopic.php?id=4104</link>
		<description><![CDATA[The most recent posts in [SLVD] False Pos. - Win32:Trojan-gen in LAN driverpack?.]]></description>
		<lastBuildDate>Tue, 27 Oct 2009 07:28:14 +0000</lastBuildDate>
		<generator>PunBB</generator>
		<item>
			<title><![CDATA[Re: [SLVD] False Pos. - Win32:Trojan-gen in LAN driverpack?]]></title>
			<link>http://forum.driverpacks.net/viewtopic.php?pid=34652#p34652</link>
			<description><![CDATA[<p>LOL, thanks OverFlow, not sure whether to be flattered or embarassed now <img src="http://forum.driverpacks.net/img/smilies/smile.png" width="15" height="15" alt="smile" /><br />Marko</p>]]></description>
			<author><![CDATA[null@example.com (marko2002)]]></author>
			<pubDate>Tue, 27 Oct 2009 07:28:14 +0000</pubDate>
			<guid>http://forum.driverpacks.net/viewtopic.php?pid=34652#p34652</guid>
		</item>
		<item>
			<title><![CDATA[Re: [SLVD] False Pos. - Win32:Trojan-gen in LAN driverpack?]]></title>
			<link>http://forum.driverpacks.net/viewtopic.php?pid=34645#p34645</link>
			<description><![CDATA[<p>It is always good to err on the side of caution. No harm no foul!</p><p>You did exactly what I would expect anyone to do, if you smell smoke pull the fire alarm.</p><p>Thank you for reporting. Thank you even more for following up!</p><p>Have an awesome day!</p><p>By the By you have used some of the best posting technique i have ever seen...<br />almost as if you wrote <a href="http://www.catb.org/~esr/faqs/smart-questions.html">How To Ask Questions The Smart Way</a></p>]]></description>
			<author><![CDATA[null@example.com (OverFlow)]]></author>
			<pubDate>Tue, 27 Oct 2009 02:42:26 +0000</pubDate>
			<guid>http://forum.driverpacks.net/viewtopic.php?pid=34645#p34645</guid>
		</item>
		<item>
			<title><![CDATA[Re: [SLVD] False Pos. - Win32:Trojan-gen in LAN driverpack?]]></title>
			<link>http://forum.driverpacks.net/viewtopic.php?pid=34640#p34640</link>
			<description><![CDATA[<p>OK, I now find myslef apologizing profusely for this matter because I can now download the LAN driverpack without any problem at all after rebuild which has me baffled immensely.&nbsp; &nbsp;In my haste, I binned the XP build that affected my PC so I can&#039;t even scan it!.&nbsp; &nbsp;I can&#039;t possibly imagine where I&#039;ve picked this virus up from and Avast certainly didn&#039;t flag anything other than the LAN driverpack but it&#039;s now apparent this is not the case.&nbsp; &nbsp;Egg on my face somewhat, I&#039;m nevertheless relieved the driverpacks aren&#039;t affected and I think it&#039;s definately time for a new antivirus product as Avast obviously hasn&#039;t done it&#039;s job - moreso it was giving me wrong information the first time round, still can&#039;t put my finger on why it reported such and wrongly allowed what appears to be a Trojan into my system to do it&#039;s damage but hope I didn&#039;t cause any inconvenience to anyone here.<br />Somewhat embarassed, Marko</p><p>PS, just to be double certain I even scanned the pack using VirusTotal and clean bill of health throughout <img src="http://forum.driverpacks.net/img/smilies/smile.png" width="15" height="15" alt="smile" /></p>]]></description>
			<author><![CDATA[null@example.com (marko2002)]]></author>
			<pubDate>Mon, 26 Oct 2009 23:25:40 +0000</pubDate>
			<guid>http://forum.driverpacks.net/viewtopic.php?pid=34640#p34640</guid>
		</item>
		<item>
			<title><![CDATA[Re: [SLVD] False Pos. - Win32:Trojan-gen in LAN driverpack?]]></title>
			<link>http://forum.driverpacks.net/viewtopic.php?pid=34639#p34639</link>
			<description><![CDATA[<p>Guys, first off I will be the first to apologize if I have this totally wrong, but as I say in my post I can really only go on what I have at the moment and circumstances which at the moment only lead me to one possibility, the LAN driverpack.&nbsp; &nbsp;I will, holding my breath!!!!, download the LAN pack again and flag the alert to Avast and will help in any way I can as your driverpacks have been of immense use to me in the past and hopefully will continue to do so therefore it&#039;s really the least I can do.&nbsp; &nbsp;I will, of course, keep you updated on my progress and report from Avast.<br />Cheers the now<br />Marko</p>]]></description>
			<author><![CDATA[null@example.com (marko2002)]]></author>
			<pubDate>Mon, 26 Oct 2009 23:07:45 +0000</pubDate>
			<guid>http://forum.driverpacks.net/viewtopic.php?pid=34639#p34639</guid>
		</item>
		<item>
			<title><![CDATA[Re: [SLVD] False Pos. - Win32:Trojan-gen in LAN driverpack?]]></title>
			<link>http://forum.driverpacks.net/viewtopic.php?pid=34619#p34619</link>
			<description><![CDATA[<p>Marko, </p><p>RE: I don&#039;t know how else you could double check the LAN pack.</p><p>As suggested, the best way to deal with this, and put all of our minds at ease, is for you submit the specific file that was flagged to Avast for review. I am sure they have a procedure for this... and since you are their customer you should be supported.<br />alternately you could link them to the packs download...</p><p>A copy of your report from Avast (either clean or dirty) will put us all on the right track.</p><p>It never hurts to be careful and vigilant.</p><p>Thank you for Reporting it makes DriverPacks better for everyone.</p><p>We are now waiting for your response from Avast support... <br />If they are the first ones to identify this threat then perhaps we may see some new fans for Avast. <br />There are not many now because of its past history with providing false positives. <br />the only thing worse than a positive is a false positive <img src="http://forum.driverpacks.net/img/smilies/wink.png" width="15" height="15" alt="wink" />. because it wastes huge amounts of time.<br />Some other popular scanners are also known for wasting our time quite often and are also not used by many of us.</p><p>one of two things will result <br />a. we have a nasty we need to address<br />b. they have a definition that needs updated.</p><p>We are in a holding pattern waiting for your trouble ticket with avast to be answered.<br />We are unable, internaly, to confirm your report useing other scanners...<br />Avast is the only avenue that I am aware of to get a resolution at this point. </p><p>I agree the coinsidence is huge and worthy of our full attention. <br />however many of us host sites too...<br />Me for example, who has every pack ever relelased extracted on his machine.<br />none of my machines or servers has been compromized - not ever for that matter.<br />although I do often have some fun with the IPs that appear more than a few thousand times in my logs.<br />You would be amazed how many would be hackers out there who don&#039;t use proxy or a zombie.<br />Mmmm... script kiddy its whats for dinner... <img src="http://forum.driverpacks.net/img/smilies/wink.png" width="15" height="15" alt="wink" /></p><br /><p>PS I almost never load a machine with the network cable connected. <br />(Except on a well protected private corporate network with hardware and software firewalls Including gateway and per machine virus scanning) <br />It is almost impossable to load a machine these days without getting a virus during the installation , if direct internet access is available to the machine. No protection is in place during this time and patches may not yet be applied.</p><p>If we do have a nasty then we would like to know ASAP, Will you continue to help us to help you?</p><p>Jeff</p>]]></description>
			<author><![CDATA[null@example.com (OverFlow)]]></author>
			<pubDate>Sun, 25 Oct 2009 20:03:12 +0000</pubDate>
			<guid>http://forum.driverpacks.net/viewtopic.php?pid=34619#p34619</guid>
		</item>
		<item>
			<title><![CDATA[Re: [SLVD] False Pos. - Win32:Trojan-gen in LAN driverpack?]]></title>
			<link>http://forum.driverpacks.net/viewtopic.php?pid=34618#p34618</link>
			<description><![CDATA[<p>Just to be certain, I&#039;m tearing into the LAN dp now (release/nightlies).&nbsp; <br />Shields up!&nbsp; Arm the photon torpedoes!&nbsp; &nbsp;Fire all weapons!!!! <img src="http://forum.driverpacks.net/img/smilies/big_smile.png" width="15" height="15" alt="big_smile" /></p><p>Just completed scans.<br />DriverPack LAN 8.12.1 -- Clean<br />DriverPack LAN 9.09.04 -- Clean<br />Used both Eset NOD32 and Symantec Endpoint Security (both updated to latest engines/defs).</p>]]></description>
			<author><![CDATA[null@example.com (mr_smartepants)]]></author>
			<pubDate>Sun, 25 Oct 2009 16:47:57 +0000</pubDate>
			<guid>http://forum.driverpacks.net/viewtopic.php?pid=34618#p34618</guid>
		</item>
		<item>
			<title><![CDATA[Re: [SLVD] False Pos. - Win32:Trojan-gen in LAN driverpack?]]></title>
			<link>http://forum.driverpacks.net/viewtopic.php?pid=34617#p34617</link>
			<description><![CDATA[<p>OK, PC rebuilt, passwords all changed and breathing normally once again!.</p><p>Now as I say, I can&#039;t put the LAN pack at fault for the virus we received but as this has never happened to us before I&#039;m merely going on circumstances, that being when I integrated the LAN pack into a new build of XP yesterday and rebuilt my machine we all of a sudden had our main site taken down and compromised.&nbsp; &nbsp;Our host has confirmed that in his experience the problem could only have been caused by &quot;a trojan/virus has obtained your FTP password and as such your files have been downloaded+modified+uploaded&quot;.</p><p>Our index file was downloaded and uploaded again in a matter of 3 seconds and many files on the server were modified to render the site useless.&nbsp; &nbsp;They also attempted to include an iFrame in the site to potentially send our members viruses or redirect them to an undesireable site but they basically made a complete ass of things, bottom line is the succeeded in causing us grief.</p><p>I don&#039;t know how else you could double check the LAN pack and I understand it&#039;s obviously checked and used by many many people but in my case I can&#039;t put the Trojan down to anything else, I&#039;ve trawled my own movements and can&#039;t recall any such warning on my AV for a long time - I sincerely hope it proves not to be the LAN pack but I thought I&#039;d update you anyway, just in case.</p><p>Cheers<br />Marko</p>]]></description>
			<author><![CDATA[null@example.com (marko2002)]]></author>
			<pubDate>Sun, 25 Oct 2009 16:28:12 +0000</pubDate>
			<guid>http://forum.driverpacks.net/viewtopic.php?pid=34617#p34617</guid>
		</item>
		<item>
			<title><![CDATA[Re: [SLVD] False Pos. - Win32:Trojan-gen in LAN driverpack?]]></title>
			<link>http://forum.driverpacks.net/viewtopic.php?pid=34615#p34615</link>
			<description><![CDATA[<p>OF, I&#039;m not sure if this is connected but the coincedence is a little too strong for my liking - basically I&#039;m now just about to rebuild my computer after integrating the LAN pack into my latest build and using that to rebuild as one of my most successful sites (<a href="http://www.freewarebb.com">www.freewarebb.com</a>) has been taken down by a hacker and we have full logs, etc that clearly show FTP connections using passwords only I would know - this has never happened before and I can only presume the alert was a real one and not a false positive as we first thought.&nbsp; &nbsp;Our host was quick to respond and has went into lockdown and is restoring the site as we speak and once I have rebuilt my comp I will PM you the details if you wish for further analysis.<br />Cheers<br />Marko</p>]]></description>
			<author><![CDATA[null@example.com (marko2002)]]></author>
			<pubDate>Sun, 25 Oct 2009 14:49:44 +0000</pubDate>
			<guid>http://forum.driverpacks.net/viewtopic.php?pid=34615#p34615</guid>
		</item>
		<item>
			<title><![CDATA[Re: [SLVD] False Pos. - Win32:Trojan-gen in LAN driverpack?]]></title>
			<link>http://forum.driverpacks.net/viewtopic.php?pid=34588#p34588</link>
			<description><![CDATA[<p>I was waiting to see if anyone else posted <img src="http://forum.driverpacks.net/img/smilies/wink.png" width="15" height="15" alt="wink" /></p><p>since the DriverPacks are worked on and then tested by a large team and then released to a large audience Many different virus scanners get a crack at the packs at every stage of development and release... if only one AV program is reporting a result then there is a 99.99 percent likelyhood that it is a false positive.</p><p>On the other hand there are hundreds of new viruses and trojans each month... <br />There is the .01 percent chance that your AV / defs is the first one to be able to detect it...&nbsp; </p><p>I would submit to them for review... why take our word for it?... go straight to the source and get the poop.<br />it would be even better if you could reply here that they responded to you taht they thought it was a false positive.<br />then you have saved not only yourself, but others in your situation. (they update the definitions for everyone)<br />&quot;Help us to help you&quot; is the spirit of DriverPacks, a spirit you obviously share with us.</p><p>I would have seemed a little daft if I had simply dissmissed you without considering the .01 probablity and anounced there was no virus... and then got bitten by that .01 LOL</p><p>Well Done! Excellent report!</p><p>Welcome to DriverPacks and we are glad you&#039;re here!</p><p>PS you never told us which LAN pack version?</p>]]></description>
			<author><![CDATA[null@example.com (OverFlow)]]></author>
			<pubDate>Fri, 23 Oct 2009 21:53:52 +0000</pubDate>
			<guid>http://forum.driverpacks.net/viewtopic.php?pid=34588#p34588</guid>
		</item>
		<item>
			<title><![CDATA[Re: [SLVD] False Pos. - Win32:Trojan-gen in LAN driverpack?]]></title>
			<link>http://forum.driverpacks.net/viewtopic.php?pid=34578#p34578</link>
			<description><![CDATA[<p>Thought that, but would av looked a little daft if I didn&#039;t ask and allowed a virus in knowlingly - I&#039;ve used the driverpacks in the past no problem, just this version of Avast is shouting but hopefully he&#039;ll flag it to Avast and have it sorted <img src="http://forum.driverpacks.net/img/smilies/smile.png" width="15" height="15" alt="smile" /><br />Cheers<br />Marko</p>]]></description>
			<author><![CDATA[null@example.com (marko2002)]]></author>
			<pubDate>Fri, 23 Oct 2009 17:16:29 +0000</pubDate>
			<guid>http://forum.driverpacks.net/viewtopic.php?pid=34578#p34578</guid>
		</item>
		<item>
			<title><![CDATA[Re: [SLVD] False Pos. - Win32:Trojan-gen in LAN driverpack?]]></title>
			<link>http://forum.driverpacks.net/viewtopic.php?pid=34574#p34574</link>
			<description><![CDATA[<p>Trust me.&nbsp; All the DriverPacks are clean!</p>]]></description>
			<author><![CDATA[null@example.com (mr_smartepants)]]></author>
			<pubDate>Fri, 23 Oct 2009 14:37:42 +0000</pubDate>
			<guid>http://forum.driverpacks.net/viewtopic.php?pid=34574#p34574</guid>
		</item>
		<item>
			<title><![CDATA[Re: [SLVD] False Pos. - Win32:Trojan-gen in LAN driverpack?]]></title>
			<link>http://forum.driverpacks.net/viewtopic.php?pid=34572#p34572</link>
			<description><![CDATA[<p>OverFlow, I&#039;m guessing this is a false positive then and not some unexpected addition to the LAN driverpack? Just wanted to make sure before I turned off the web-shield for Avast <img src="http://forum.driverpacks.net/img/smilies/smile.png" width="15" height="15" alt="smile" /><br />Cheers<br />Marko</p>]]></description>
			<author><![CDATA[null@example.com (marko2002)]]></author>
			<pubDate>Fri, 23 Oct 2009 14:26:19 +0000</pubDate>
			<guid>http://forum.driverpacks.net/viewtopic.php?pid=34572#p34572</guid>
		</item>
		<item>
			<title><![CDATA[Re: [SLVD] False Pos. - Win32:Trojan-gen in LAN driverpack?]]></title>
			<link>http://forum.driverpacks.net/viewtopic.php?pid=34523#p34523</link>
			<description><![CDATA[<p>Avast 21/10/2009 18:03:08<br />Version 091021-0<br />It&#039;s Avast Home Edition Beta</p><p>Hope that helps <img src="http://forum.driverpacks.net/img/smilies/smile.png" width="15" height="15" alt="smile" /><br />Cheers<br />Marko</p>]]></description>
			<author><![CDATA[null@example.com (marko2002)]]></author>
			<pubDate>Thu, 22 Oct 2009 06:32:57 +0000</pubDate>
			<guid>http://forum.driverpacks.net/viewtopic.php?pid=34523#p34523</guid>
		</item>
		<item>
			<title><![CDATA[Re: [SLVD] False Pos. - Win32:Trojan-gen in LAN driverpack?]]></title>
			<link>http://forum.driverpacks.net/viewtopic.php?pid=34521#p34521</link>
			<description><![CDATA[<p>It is known now <img src="http://forum.driverpacks.net/img/smilies/wink.png" width="15" height="15" alt="wink" />...</p><p>Thanks for reporting!</p><p>Welcome to DriverPacks and have a great day.</p><p>PS which definition version gave the false positive... (date/ver)</p>]]></description>
			<author><![CDATA[null@example.com (OverFlow)]]></author>
			<pubDate>Wed, 21 Oct 2009 21:30:59 +0000</pubDate>
			<guid>http://forum.driverpacks.net/viewtopic.php?pid=34521#p34521</guid>
		</item>
		<item>
			<title><![CDATA[[SLVD] False Pos. - Win32:Trojan-gen in LAN driverpack?]]></title>
			<link>http://forum.driverpacks.net/viewtopic.php?pid=34519#p34519</link>
			<description><![CDATA[<p>Hi, I&#039;m downloading the LAN driverpack though I&#039;m being told by Avast that the download contains Win32:Trojan-gen and thus aborts the download.&nbsp; &nbsp;Is this a known false-positive or is there something else amiss here?<br />Thanks in advance<br />Marko</p>]]></description>
			<author><![CDATA[null@example.com (marko2002)]]></author>
			<pubDate>Wed, 21 Oct 2009 18:53:24 +0000</pubDate>
			<guid>http://forum.driverpacks.net/viewtopic.php?pid=34519#p34519</guid>
		</item>
	</channel>
</rss>
