uz.exe detected as trojan by Kaspersky
Started by Tallman, Jul 05 2008 05:12 AM
8 replies to this topic
#1
Posted 05 July 2008 - 05:12 AM
A few days ago I downloaded AutoPatcher and ran the updater to download updates for Widows XP, Office XP, Office 2003 and Office 2007. Tonight I scanned my computer with Kaspersky 7.0. Kaspersky identified the following 11 fiels as, "Infected: Trojan program Trojan-Dropper.Win32.VB.bag"
d:\system volume information\_restore{c93052a1-5220-4ae1-b383-a045cab1e828}\rp505\a0079902.exe 72KB
d:\computer backups\updates\downloaded\other\autopatcher\apup.zip 705.8 KB
D:\System Volume Information\_restore{C93052A1-5220-4AE1-B383-A045CAB1E828}\RP506\A0080195.exe 72 KB
d:\computer backups\updates\downloaded\other\autopatcher\office 2003\apup_bin\uz.exe 72 KB
d:\computer backups\updates\downloaded\other\autopatcher\office 2007\apup_bin\uz.exe 72 KB
d:\system volume information\_restore{c93052a1-5220-4ae1-b383-a045cab1e828}\rp505\a0079894.exe 72 KB
D:\System Volume Information\_restore{C93052A1-5220-4AE1-B383-A045CAB1E828}\RP506\A0080475.exe 72 KB
D:\System Volume Information\_restore{C93052A1-5220-4AE1-B383-A045CAB1E828}\RP506\A0080277.exe 72 KB
d:\computer backups\updates\downloaded\other\autopatcher\office xp\apup_bin\uz.exe 72 KB
D:\System Volume Information\_restore{C93052A1-5220-4AE1-B383-A045CAB1E828}\RP506\A0080268.exe 72 KB
d:\computerbackups\updates\downloaded\other\autopatcher\windows xp\apup_bin\uz.exe 72 KB
I am thinking this is a false positive on Kaspersky's part as far as the AutoPatcher files are concerned. But what about the System Volume Information files, are they part of AutoPatcher as well?
Does anyone have any information or thoughts on this?
d:\system volume information\_restore{c93052a1-5220-4ae1-b383-a045cab1e828}\rp505\a0079902.exe 72KB
d:\computer backups\updates\downloaded\other\autopatcher\apup.zip 705.8 KB
D:\System Volume Information\_restore{C93052A1-5220-4AE1-B383-A045CAB1E828}\RP506\A0080195.exe 72 KB
d:\computer backups\updates\downloaded\other\autopatcher\office 2003\apup_bin\uz.exe 72 KB
d:\computer backups\updates\downloaded\other\autopatcher\office 2007\apup_bin\uz.exe 72 KB
d:\system volume information\_restore{c93052a1-5220-4ae1-b383-a045cab1e828}\rp505\a0079894.exe 72 KB
D:\System Volume Information\_restore{C93052A1-5220-4AE1-B383-A045CAB1E828}\RP506\A0080475.exe 72 KB
D:\System Volume Information\_restore{C93052A1-5220-4AE1-B383-A045CAB1E828}\RP506\A0080277.exe 72 KB
d:\computer backups\updates\downloaded\other\autopatcher\office xp\apup_bin\uz.exe 72 KB
D:\System Volume Information\_restore{C93052A1-5220-4AE1-B383-A045CAB1E828}\RP506\A0080268.exe 72 KB
d:\computerbackups\updates\downloaded\other\autopatcher\windows xp\apup_bin\uz.exe 72 KB
I am thinking this is a false positive on Kaspersky's part as far as the AutoPatcher files are concerned. But what about the System Volume Information files, are they part of AutoPatcher as well?
Does anyone have any information or thoughts on this?
#2
Posted 05 July 2008 - 06:36 AM
Tallman, on Jul 5 2008, 06:12 AM, said:
I am thinking this is a false positive on Kaspersky's part as far as the AutoPatcher files are concerned.
AutoPatcher has had false positives before as you can see in THIS TOPIC.
Tallman, on Jul 5 2008, 06:12 AM, said:
But what about the System Volume Information files, are they part of AutoPatcher as well?
#3 Guest_dabber_*
Posted 05 July 2008 - 09:12 PM
Also in my opinion there is something wrong with uz.exe.
I wasn't able to extract uz.exe from apup.zip because of the virus: Trojan-Dropper.Win32.VB.bag
After ignoring this message and bypassing the virus scanner I got some problems.
Each time I only try to acces this file my computer resets.
My AutoPatcher is not working right now. Is it possible to place a new apup.zip
I wasn't able to extract uz.exe from apup.zip because of the virus: Trojan-Dropper.Win32.VB.bag
After ignoring this message and bypassing the virus scanner I got some problems.
Each time I only try to acces this file my computer resets.
My AutoPatcher is not working right now. Is it possible to place a new apup.zip
Tallman, on Jul 5 2008, 07:12 AM, said:
A few days ago I downloaded AutoPatcher and ran the updater to download updates for Widows XP, Office XP, Office 2003 and Office 2007. Tonight I scanned my computer with Kaspersky 7.0. Kaspersky identified the following 11 fiels as, "Infected: Trojan program Trojan-Dropper.Win32.VB.bag"
Does anyone have any information or thoughts on this?
Does anyone have any information or thoughts on this?
#4
Posted 05 July 2008 - 11:43 PM
James, on Jul 4 2008, 10:36 PM, said:
I think this is a false positive too. The apup.zip file (and the uz.exe file it contains) are unchanged on the autopatcher.com server since the file was uploaded on 23 March 2008. I have downloaded a fresh copy today to check and it still gives the same MD5 hash as before (MD5 Hash = 3E2FA4B4C99CCE5CF04B149523E84AF2)
AutoPatcher has had false positives before as you can see in THIS TOPIC.
AutoPatcher has had false positives before as you can see in THIS TOPIC.
#5
Posted 06 July 2008 - 06:19 AM
Tallman, on Jul 5 2008, 11:43 PM, said:
I am currently in communication with the folks at the Kaspersky Labs forum but have not gotten any deffinitive answer on this issue yet.
Thanks for taking this to Kapersky - so far they have released NO details of what Trojan-Dropper.Win32.VB.bag is supposed to be. It is NOT listed in any virus database I have llooked at. All very unsatisfactory
--
#6
Posted 06 July 2008 - 09:36 AM
Also looks like AVG Antivirus is detecting it as a " Trojan horse dropper.Generic.ZLV "
Think this might also be a false/positive response?
Think this might also be a false/positive response?
#7
Posted 06 July 2008 - 08:29 PM
freeloader, on Jul 6 2008, 09:36 AM, said:
Also looks like AVG Antivirus is detecting it as a " Trojan horse dropper.Generic.ZLV "
Think this might also be a false/positive response?
Think this might also be a false/positive response?
Please read THIS TOPIC.
--
#8
Posted 08 July 2008 - 02:38 AM
James, on Jul 5 2008, 10:19 PM, said:
Thanks for taking this to Kapersky - so far they have released NO details of what Trojan-Dropper.Win32.VB.bag is supposed to be. It is NOT listed in any virus database I have llooked at. All very unsatisfactory
--
--
#9
Posted 08 July 2008 - 10:12 AM
Thanks Tallman for the feedback. I did follow your thread over at the Kaspersky forums.
As posted in THIS TOPIC it looks like this subject is now finished.
Final advice to everyone:
If you have F-Secure or Kaspersky just update your AV with the current definitions.
Anything else - keep trying until your AV supplier updates their definitions.
If there is still a false alarm, just exclude apup.zip and uz.exe from being scanned.
--
As posted in THIS TOPIC it looks like this subject is now finished.
Final advice to everyone:
If you have F-Secure or Kaspersky just update your AV with the current definitions.
Anything else - keep trying until your AV supplier updates their definitions.
If there is still a false alarm, just exclude apup.zip and uz.exe from being scanned.
--
1 user(s) are reading this topic
0 members, 1 guests, 0 anonymous users


This topic is locked









