Help - Search - Members - Calendar
Full Version: WPI Virus?
MSFN Forums > Member Contributed Projects > Windows Post-Install Wizard (WPI)

   


Google Internet Forums Unattended CD/DVD Guide
CaffeineJunkie
My AVG just updated and did a scan of my entire computer.. As it does every sunday. However this time, it came across my WPI folder and found a virus.

Now at first I did not believe that Audio.exe was a Trojan Horse (Generic.BOO). So I downloaded the RAR file again, directly from this site. Again and again, audio.exe is detected as a Trojan Horse.

So now I say.. excuse me?
andreasfc
I think there is something wrong with your pc, I don't have any problem withthe wpi installer.
I have Norton AV Corp, and I am using a good Firewall applicatie, none of them is reacting as if audio.exe is a trojan.
engjcowi
hmmm very interesting and i will have a look. is it possible that your computer had a virus and the audio.exe was infected by the virus but not originally carried it?
p388l3s
I just scanned my version with the latest ESet definitions and i doesn't report anything, what AV scanner are you using? from what you describe in your post i'd say your AV settings have changed to something more agressive and it's now detecting the Audio.exe as a potential virus, check your AV heuristics settings and such.

Pebbles
CaffeineJunkie
I use AVG Antivirus.. it has updates every few days. Extremely reliable!

@engjcowi - No viri are on my computer, I run scans every week. I downloaded a fresh version directly off this site to make sure I wasn't crazy. And the moment I scanned that rar file, AVG found audio.exe to be a virus.

Trojan Horse (Generic.BOO)

@p388l3s - My AVG Virus definitions just updated.. and that is when it found audio.exe to be a virus. I will check the most recent release log.
glent
Well none of my AV software found anything, Siginet had a similar problem with his Tools and I think XPero did at on time too. There is no need to worry newwink.gif it will be a false alarm, Kel is very busy on other projects at the moment so Pm him if your concerned
Kelsenellenelvian
I am stilll here everyday. No known or confimed viruses in WPI. However, we have had false positives before.
iamrock
QUOTE (kelsenellenelvian @ Oct 17 2005, 03:11 AM) *
I am stilll here everyday. No known or confimed viruses in WPI. However, we have had false positives before.


This most likely is a false positive, but I also use AVG AntiVirus and I thought a screenshot might help you figure this out.
nujackk
You know I had the same happen with antivir around the same time as this thread started, I assumed it was a false positive, ( can't remember if I submitted to them or not) but with the lastest version and current update, and heuristics turned to max, still no hit.

So if you are still getting this then you do need to update. Antivir does get a lot of false positives with heuristics turned above low
naturekid
Hi,
I have the same problem with my AVG. I will get in contact with the AVG support this evening and ask them.

Will report as soon as I have an answer.

Cheers,
naturekid
Nanaki
AVG is cool. It also reported Firefox, Winamp, BSplayer, PowerDVD and many other classics to be a virus. ^^
Kelsenellenelvian
$#@%$%$#@ers I need a **** serial number just to contact AVG support!!!
iamrock
QUOTE (kelsenellenelvian @ Oct 25 2005, 08:53 AM) *
$#@%$%$#@ers I need a **** serial number just to contact AVG support!!!


Here's a link to the free version of AVG AntiVirus. The install will automatically generate a serial number for you. Once the install package displays the serial number, you can cancel the install. That will allow you to contact supprt.

http://free.grisoft.com/doc/Get+AVG+FREE/lng/us/tpl/v5
naturekid
Just sent a mail to AVG Support.

I will post the answer as soon as I get one.

naturekid
Kelsenellenelvian
Thank you.
naturekid
Dear Sir/Madam,

Thank you for your email.

We checked the file and there is really no virus in it. Please accept our apologies, we will correct it in some next virus base update.

Thank you!

Best regards,
AVG Technical Support
libboid
I have had the same issues with AVG, have updated the definitions this morning and everything is now OK with audio.exe
Kelsenellenelvian
Great I am glad they fixed it....
Kamikaze!
I get virus on this archive too. With bit defender 9.

But i think is a mixtake.
farisnt
I Have BitDefender and it report hat this is a (small.Trojan)
blinkdt
It wasn't too long ago that AVG reported all of my compiled AutoIt scripts as viruses. Bummer, but I can deal with that. Nice to see AVG tech support was responsive even for users of the free version.
bart of borg
I am also getting a virus infrction report from Avast A\V.....says the audio.exe files contains sample of the "Win32:Ircbot-KT [Trj]"
elessarch
bitdefender gives same message "Trojen.Small.EN" about audio.exe on my machine. I searched this trojan in virus knowledge bases in some sites(bitdefender,avg etc.) and could not find anything about this trojan.
what is the reason of wrong-identification of some virus programs? is there anybody who know the codes of audio.exe?
Kelsenellenelvian
It is a compiled auto-it file.
Kelsenellenelvian
Sorry it is a compiled batch file the contents are only this and an icon:

@ECHO OFF
start %windir%\system32\mshta.exe "%CD%/Audio/audioplayer.hta"
exit
oneless
QUOTE (kelsenellenelvian @ Jan 13 2006, 01:47 AM) *
Sorry it is a compiled batch file the contents are only this and an icon:

@ECHO OFF
start %windir%\system32\mshta.exe "%CD%/Audio/audioplayer.hta"
exit

i give up . after the latest update , my bitdefender
block all WPI directory , even i told it before to ignore audio.exe file .
so , i must delete it manually and cut music in installation part .
very bad , but that it .

i hope 4.4rc1 do not include THIS compilation , 3 lines can be compiled easy
with other tools.
bionicman
Just finished scan with Trojan Hunter & got these results. WPI is not currently installed but I have the zip file on my secondary drive. These are the only resuts found & all in WPI.

Progs\WPI_v4.3.8.rar/CloseAudio.exe/COeJ.exe because it is contained in an archive
Unable to clean trojan file D:\The Rest\Odds & Sods\Unattended Install Progs\WPI_v4.3.8.rar/cmdow.exe because it is contained in an archive
Unable to clean trojan file D:\The Rest\Odds & Sods\Unattended Install Progs\WPI_v4.3.8.rar/Universal Silent Switch Finder.exe because it is contained in an archive
Unable to clean trojan file D:\The Rest\Odds & Sods\Unattended Install Progs\WPI_v4.3.8.rar/Universal Silent Switch Finder.exe/UGMKuz7.exe because it is contained in an archive
Unable to clean trojan file D:\The Rest\Odds & Sods\Unattended Install Progs\WPI_v4.3.8.rar/WPI Config Lister.exe because it is contained in an archive
Unable to clean trojan file D:\The Rest\Odds & Sods\Unattended Install Progs\WPI_v4.3.8.rar/WPI Config Lister.exe/5Uplc2.exe because it is contained in an archive
Trojan cleaning finished.

Listed offenders:
Adware.MaxFiles.100
PWSteal.Agent.104
Riskware.HideWindows.104
kai445
virusscan.jotti.org results for audio.exe

Service load: 0% 100%
File: audio.exe
Status: INFECTED/MALWARE
MD5 8a274b65be70e021a5c6db1e50d25f62
Packers detected: UPX
Scanner results:
AntiVir Found nothing
ArcaVir Found nothing
Avast Found nothing
AVG Antivirus Found nothing
BitDefender Found Trojan.Small.EN
ClamAV Found nothing
Dr.Web Found nothing
F-Prot Antivirus Found nothing
Fortinet Found nothing
Kaspersky Anti-Virus Found nothing
NOD32 Found nothing
Norman Virus Control Found nothing
UNA Found nothing
VirusBuster Found Trojan.Delf.AKU
VBA32 Found nothing
Dumpy Dooby
ESET and NAV/SAV are regarded as two of the best antivirus programs on the market (as far as accuracy is concerned). AVG is just kinda ... bleh.
Kelsenellenelvian
I use Nod32 and no virus reports here. Of course I would be really screwed too. LOL
Avneet
nod32 rulez.. i use it too and no virus problems






Google Internet Forums Unattended CD/DVD Guide

This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.