Topic: [SLVD] False positive - Quick Heal Antivirus Showing Win32.trojan

Hi Friends

I got here a new bug here possibly for me only.

I hve created driverpacks enebaled, SP3 slipstreamed, Application Loaded windows xp professional Disk.

I use to install my pc with that disk. Now the real story starts,

When i try to install my 'QUICK HEAL TOTAL SECURITY ANTIVIRUS' IT SHOWS ME my system infected with A "Win32.TrogenDownloader...." and i am not able to install my antivirus in it.

I will tell the whole story how i have created my xp disk.

While creating my xp source first copied the xpsp2 disk to some folder then i put the $OEM$ source into it then slip streamed SP3 to it by dos command line then i used 'Windows Media Player 11 slip streamer' to integrate windows media player 11. Then i integrated driverpacks into it.and at last i used nLite to create an ISO.

I dont know which process is effecting to my source. But, if any one has faced this kind of problem and has a solution of it pls pls reply to this post.

Thanks & Regards

An eye for an eye will make the whole world blind. - Mahatma Gandhi (Mohandas Karamchand Gandhi)

Re: [SLVD] False positive - Quick Heal Antivirus Showing Win32.trojan

Do you get the same problem without DriverPacks integrated? 
It's possible the host system is infected.
DriverPacks downloaded from this site are clean.

Read BEFORE you post.  HWID tool   DriverPacks Tutorial   DONATE!
http://driverpacks.net/userbar/admin-1.png
Not all heroes wear capes, some wear Kevlar!

Re: [SLVD] False positive - Quick Heal Antivirus Showing Win32.trojan

What file is infected?

Where did you obtain your XP source disc? is it a MS hologramed unit?

was the machine connected to the network during the install?

DP BartPE Tutorial   DP_BASE Tutorial   HWID's Tool     Read BEFORE you post    UserBars!
http://driverpacks.net/userbar/admin-1.png
The DriverPacks, the DP_Base program, and Support Forum are FREE!.

Re: [SLVD] False positive - Quick Heal Antivirus Showing Win32.trojan

Ok let me try every thng

with driverpacks
with windows media player 11

and for the rest i can assure that there is no virus thing inside. Because i created some XP disks without driver packs using nLite integration drivers. at that time it was working perfectly. But, as we know we have a huge base of drivers in our driver packs i decided to go for it and i also think that there cant be any threat in our driverpacks but may be in the source/integrater of windows media player 11.

Ok will meet again here only

thanks for reply

An eye for an eye will make the whole world blind. - Mahatma Gandhi (Mohandas Karamchand Gandhi)

Re: [SLVD] False positive - Quick Heal Antivirus Showing Win32.trojan

I have checked it by only integrating with our driverpacks and it shows virus. And tried without driverpacks and it didnt showed Win32.TrongenDownloader....

I am going to download our driver packs again from our site and check it again. But on a different system.

Lets hope the Trogen Message dosent appear again.

An eye for an eye will make the whole world blind. - Mahatma Gandhi (Mohandas Karamchand Gandhi)

Re: [SLVD] False positive - Quick Heal Antivirus Showing Win32.trojan

Which file(s) does your AV show as infected?  I'll double-check on my system.

Read BEFORE you post.  HWID tool   DriverPacks Tutorial   DONATE!
http://driverpacks.net/userbar/admin-1.png
Not all heroes wear capes, some wear Kevlar!

Re: [SLVD] False positive - Quick Heal Antivirus Showing Win32.trojan

It dosent show the file name but while i start installing quick heal anti virus plus 2009 v10.0 and during preinstall virus scan it shows message about 'Your system is infected with Win32.TrogenDownloader..... we suggest to scan your system with quick heal rescue disk or the installation may be infected.'

I will suggest you one thing that install a new system with your DP enabled disk and try to install quick heal license on that.

Thanks for reply

An eye for an eye will make the whole world blind. - Mahatma Gandhi (Mohandas Karamchand Gandhi)

Re: [SLVD] False positive - Quick Heal Antivirus Showing Win32.trojan

OK now i have tried all the things whichever is possible.

My quick heal stops at file C:\Windows\System32\zipfldr.dll during preinstall virus scan and gives me the message "Found some threates in your system. Proceeding with installation will not be safe as the installation copy will be infected. We recommand you to scan and clean your system with quick heal emergency disk."
'Win32.TrojanDownloader.Small.gen!V.8'

I am now 90% sure that there is some mistake with our driverpacks. I request you to check our driverpacks.

Last edited by Tarak Bhavsar (2009-10-06 17:04:14)

An eye for an eye will make the whole world blind. - Mahatma Gandhi (Mohandas Karamchand Gandhi)

Re: [SLVD] False positive - Quick Heal Antivirus Showing Win32.trojan

Well, I am 99% sure that there is nothing wrong with DriverPacks. wink
I scanned all the extracted DriverPacks I have here on my system (release, nightly, & Third Party DriverPacks ), and over 50,000 files clean with zero infected files.
I used Eset NOD32 and Symantec Endpoint Protection (both with latest updates).
It's a false positive, and updating your AV to a current version should make that error go away.
Besides, that .dll is a XP system file.  DriverPacks doesn't modify that system file anyway.
I've never heard of your AV brand before.  But free AV are known for announcing false positives.  I'd recommend getting Eset.  It's cheap, and the best.

Read BEFORE you post.  HWID tool   DriverPacks Tutorial   DONATE!
http://driverpacks.net/userbar/admin-1.png
Not all heroes wear capes, some wear Kevlar!

Re: [SLVD] False positive - Quick Heal Antivirus Showing Win32.trojan

My AV brand is not free and it is as costly as Norton and better then NOD or Norton as i have tried NOD, Symantec and Quick Heal on atleast 1500 systems.

You can check my brand on

www.quickheal.co.in

and moreover my brand also comes under Microsoft WGA Program. So, i think there is no mistake in my search. This AV brand is working since 1993.

http://www.quickheal.co.in/mstone.asp

http://www.quickheal.co.in/awards.asp

Last edited by Tarak Bhavsar (2009-10-06 19:56:01)

An eye for an eye will make the whole world blind. - Mahatma Gandhi (Mohandas Karamchand Gandhi)

Re: [SLVD] False positive - Quick Heal Antivirus Showing Win32.trojan

Found this on the web.

As mr_smartepants said, it is not part of the DriverPacks. Has to be a false positive or is infected on the source CD.

------------------------------------------------------------------------------------------------------------------------------------------

Description

zipfldr.dll is a Compressed Folders Module from Microsoft Corporation belonging to Microsoft® Windows® Operating System

Recommendation

zipfldr.dll should not be disabled, required for essential applications to work properly.

Re: [SLVD] False positive - Quick Heal Antivirus Showing Win32.trojan

I don't really care how good you think it is... or even how good they think it is...

If it is reporting false positives... then it is junk smile
How much of your time has been wasted, just on this issue?
What about our wasted time?
If someone wastes a few hours of IT time it will definately cost them more than what they thought that they had saved on the AV program. (even worse if they paid a premium price) tongue  False positives cost time, lots of time, and time is money. 

Can you confirm the virus using another scanner of your choice?

Have you submitted the file to Quick Heal for evaluation?
did you check the hash on the file before and after your process to see if it actually is being changed?
were you able to reproduce the exact same result each time (IE more than once)
Are you runing any service packs as part of your setup that might update this file?



I assume you are doing on access scanning...
your source shows no virus,
DriverPacks shows no virus,
DriverPacks has to be the last step in your process before ISO creation..
So where does it come from?
(It is a magic teleporting virus that can add itself to WORM media smile)

(( You never answered my question:

Was the network card plugged in during the install?
(link light on, and conncted to a network... and possibly the internet
- I am going to bet the answer to that question is YES. Since it went unanswered)

that would explain different results each time... you are just getting a different virus from the net each time you install lol. if you give a machine internet access during an install you will have a virus before you get to the desktop. wink even local network access is risky tongue

[are you installing from disc?]
If so just pull the network cable until you have your AV / Firewall in place big_smile.
Does the issue still exist?

))


We don't use Zip... and don't fool with ANY windows dll files.
txtsetup dosnet and setup... that is it, just those three.
we include our own un7zip app...


None of the team has heard of this AV...
collectively we service tens of thousands of machines. (daily)
DriverPacks is downlaoded at the rate of at least a million times a week.
this is the only report out of our tens of millons of users of this issue.
No one at all out of all those people also sees this issue... think about it...

the reviews you point to are all on their site... and not one of them is noteworthy...
Who cares if the  Mahratta Chamber of Commerce gave them an award???
(It is a small town with a specialty every one of the businesses is chocked full with MVPs CCIE's and other who saids)

I don't see a single reputable source, like Consumer Reports or PC magazine, in the list...

Google top AV programs / reviews
Check ANY independent list of top AV programs and topheal is not on their list.

So if they can't make a single top ten list, ever not once in 15 years... I think we can all agree it's junk.
And if you really paid as much as you would for Norton then you got taken to the cleaners.
I am sure they have no resources that even come close to compare to SARC.
Although I must admit i have been very disapointed with where Norton has gone since Peter left. I have stopped recomending all of their products for years now.

Either
1 resolve the issue with your process
2 resolve false positive with your prefered AV,  or get one that works...

Issue marked solved...

DP BartPE Tutorial   DP_BASE Tutorial   HWID's Tool     Read BEFORE you post    UserBars!
http://driverpacks.net/userbar/admin-1.png
The DriverPacks, the DP_Base program, and Support Forum are FREE!.

Re: [SLVD] False positive - Quick Heal Antivirus Showing Win32.trojan

Ok Leave It I Will Solve It My Way

I Have Another Way To Use Driver Packs In My Os

An eye for an eye will make the whole world blind. - Mahatma Gandhi (Mohandas Karamchand Gandhi)

Re: [SLVD] False positive - Quick Heal Antivirus Showing Win32.trojan

Mr.tarak Bhavsar

Here I Am Jigar Prajapati From India.

Brother OverFlow Brother Is Right I Got Also This Problem With My Untended Xp CD. I Am Also Big Fan Of This DP Community. And I Trust On It.
There Is Just Quick Heal False Report.
This Problem Accured Also With Me I Try Kaspersky KIS 2007 to 2010 No Virus Found And Bro One Big Joke It This When I Install Quick Heal On My Untended Xp Its Show Me Virus In This All Files zipfldr.dll , yv12vfw.dll , xvidvfw.dll , xvidcore.dll ,xpssvcs.dll , xpsshhdr.dll , And Also Big Joke Its Says This xpsp3res.dll ,xpsp2res.dll , xpsp1res.dll , xpob2res.dll , xolehlp.dll , xmlprovi.dll , xmlprov.dll And xcopy  File Are VIrus InFeCtEd lol Its All SP3 OS System Files smile). And If U Dont Trust On Me Then Follow This Instruction Just Excuted Install Of Ur Quick Heal And When Its Says File Name That Is Infected Then Just Close And Go to System32 Folder Find That File And Cut Past It On Anywhere In Ur Pc For Backup Perpose And Then Start Setup Again Then Its Says One Of Other Files Are Infected U Do Again Cut Past And Do It This Process One Bye On Its Give U More Then 30 File Name That Are Infected lol .............. And If U wanna Know Quick Heal Right Or Wrong Then Just Copy All File That Quick Heal SAys That Is Infected And Go To Other Quick Heal Installed System That HAve LAtest Update And Scan All Files  There Is Nothing . smile) I Try It Everything Myself smile) Its Just False Report Installation Time Its Show Virus And Installed And Up To DAte Antivirus Says Its Clean smile) hahaha good joke By Quick HEal . Go And Take Kaspersky 2010 Or McFee ITs Wonderfull Antivirus. And Dont Blam On Driverpacks.net.......... Thanx
And Thanx To Brother Overflow For Detailed Responce.
Also Sorry For My Bad English.

Re: [SLVD] False positive - Quick Heal Antivirus Showing Win32.trojan

Actually Jigar
I installed Quick Heal perfectly on my customized xp installation. How ???

Ans :
when you start the installation of license quick heal on customized xp installation you just jave to keep pressing and hold ctrl+alt till the 'next' button page comes.

Last edited by Tarak Bhavsar (2009-12-09 19:14:45)

An eye for an eye will make the whole world blind. - Mahatma Gandhi (Mohandas Karamchand Gandhi)

Re: [SLVD] False positive - Quick Heal Antivirus Showing Win32.trojan

Nice... Now that is what I want to do, Sit there and continually press CTRL+ALT Waiting for the "next" button to appear, 30 times.

This issue certainly defeats any chance at an unattended installation Disc.
If you can't add it to your installation successfully then it is not any good, If it is not any good then why use it?

Think about this: How many hours have you sat there fooling with it. I am not just referring to this broken unattended disc / false positive issue. I'm sure that there are other issues too! Add the time you wasted posting here, troubleshooting, and CTRL+ALTing through your installs. Take the total hours and multiply by your Hourly Rate. Q) What did it cost you? A) More than it is worth. Get a decent AV program and cut your losses.

DP BartPE Tutorial   DP_BASE Tutorial   HWID's Tool     Read BEFORE you post    UserBars!
http://driverpacks.net/userbar/admin-1.png
The DriverPacks, the DP_Base program, and Support Forum are FREE!.