←  General Support

AutoPatcher Forum

»

Autopatcher Original -- Virus detection issue

Kbird's Photo Kbird 23 Nov 2007

Hi , I am still running Autopatcher Aug core ,while i wait for the new development and thought i'd let you know that as of yesterday AVG Free 7.5 Antivirus has started detecting both Hotfix Cleaner.exe and Dir2File.exe as trogan horse dropper. vb3 .aq , it is probably a false postive but AVG deletes both files if it is set to heal after scanning.

Another issue someone might be able to help me with ,since installing the August core on my computers Windows explorer will no long reuse open windows , it opens a new window for every click on anohter directory,so if i am 5-6 levels down in a directory i have to have 7-8 windows open . I can no longer get the "folder pane" to show either on the LH side automatically as before. i have searched the net for ideas and tryed a few settings etc in "file options" dialog in XP but so far the fix has eluded me.

Thanks for you help.
Quote

Cyrus's Photo Cyrus 23 Nov 2007

In windows explorer there is an option to that effect under Tools -> Folder Options. I'm on a linux box right now so I can't check the exact option past that, but just look in there.
Quote

Kbird's Photo Kbird 24 Nov 2007

View PostCyrus, on Nov 23 2007, 03:01 PM, said:

In windows explorer there is an option to that effect under Tools -> Folder Options. I'm on a linux box right now so I can't check the exact option past that, but just look in there.


Actually that is one of the options i have tried already and it doesnt seem to matter whether it is enabled or not but thanks for the idea....
Quote

dkdk_it's Photo dkdk_it 24 Nov 2007

View PostKbird, on Nov 23 2007, 11:28 PM, said:

Hi , I am still running Autopatcher Aug core ,while i wait for the new development and thought i'd let you know that as of yesterday AVG Free 7.5 Antivirus has started detecting both Hotfix Cleaner.exe and Dir2File.exe as trogan horse dropper. vb3 .aq , it is probably a false postive but AVG deletes both files if it is set to heal after scanning.

Don't worry... send an email to AVG support for a false positive.

Quote

Another issue someone might be able to help me with ,since installing the August core on my computers Windows explorer will no long reuse open windows , it opens a new window for every click on anohter directory,so if i am 5-6 levels down in a directory i have to have 7-8 windows open . I can no longer get the "folder pane" to show either on the LH side automatically as before. i have searched the net for ideas and tryed a few settings etc in "file options" dialog in XP but so far the fix has eluded me.

Have you installed one or more tweak?!?
Quote

Aerowinder's Photo Aerowinder 24 Nov 2007

Open Windows Explorer. Click the Folders button at the top of the window above the address bar. Is that what you want?

Then do this: Tools > Folder Options > General tab > Browse folders section > click "Open each folder in the same window" (this will fix Explorer window spam).
Then navigate to: Tools > Folder Options > View tab > Apply to all Folders (this is to apply the folders pane).
Quote

Phred's Photo Phred 25 Nov 2007

View PostKbird, on Nov 23 2007, 10:28 PM, said:

Hi , I am still running Autopatcher Aug core ,while i wait for the new development and thought i'd let you know that as of yesterday AVG Free 7.5 Antivirus has started detecting both Hotfix Cleaner.exe and Dir2File.exe as trogan horse dropper. vb3 .aq , it is probably a false postive but AVG deletes both files if it is set to heal after scanning.

Same issue. The MD5 (thanks M2Ys4U) on my Aug Core is correct and it installs just fine. I submitted both files to virscan.org and it's not just AVG that reports problems with the two files. Both files appear to have similar characteristics that trigger virus warnings - the question is, false warnings or not.. All of this may have been covered in the old forums, but as they say, that's history..

Hotfix Cleaner.exe

AVG - Dropper.VB.3.AQ
ClamAV - PUA.Packed.TeLock
F-Prot - Possible W32/Heuristic-162!Eldorado (not disinfe
Ikarus - suspicious(level 125)
Prevx - TROJAN.DOWNLOADER.GEN
Quick Heal - Suspicious - DNAScan
The Hacker - W32/Behav-Heuristic-066

dir2file.exe

AVG - Dropper.VB.3.AQ
ClamAV - PUA.PAcked.TeLock
F-Prot - Possible W32/Heuristic-162Eldorado (not disinfectable)
Ikarus - suspicious(level 95)
Prevx - TROJAN.DOWNLOADER.GEN
The HAcker - W32/Behav-Heuristic -066



Phred
Quote

Renato's Photo Renato 25 Nov 2007

Those are false positives.
Quote

Phred's Photo Phred 26 Nov 2007

View PostRenato, on Nov 25 2007, 11:48 PM, said:

Those are false positives.

Thanks Renato.

Cheers,
Phred
Quote

Kbird's Photo Kbird 27 Nov 2007

View PostAerowinder, on Nov 24 2007, 12:40 PM, said:

Open Windows Explorer. Click the Folders button at the top of the window above the address bar. Is that what you want?

Then do this: Tools > Folder Options > General tab > Browse folders section > click "Open each folder in the same window" (this will fix Explorer window spam).
Then navigate to: Tools > Folder Options > View tab > Apply to all Folders (this is to apply the folders pane).


Thanks for the ideas , i have tried them but so far it hasnt changed this problem , I used AP Aug Core on 4 different computers and they all have this same issue now . I do use most of the registry tweaks that AP used to come with but on looking again i cant seem to find one that affects this behavior.I am using classic folders with web content turned off but am unsure whether this is part of the problem.

Thanks for the update on the False Positive , i was 100% sure thats what is was , just wanted to warn others so that they didnt panic.

thanks for the ideas guys

KB
Quote

ehatherley's Photo ehatherley 04 Mar 2008

Spyware Terminator is reporting Dir2File.exe as Dropper.VB.3.AQ as well. Reported as false positive via built-in reporting tool.
Edited by ehatherley, 04 March 2008 - 12:01 PM.
Quote