Avast just popped up stating "PDFCreator" toolbar is a trojan. Is this a FP?

Avast just popped up stating “PDFCreator” toolbar is a trojan. Is this a False-Positive? PDFCreator is a free, open source PDF creation tool.
[b]
“A Trojan House Was Found!”

Filename: C:\Program Files\pdfcreator toolbar\v3.0.0.0\pdfcreator_toolbar.dll
Malware name: Win32-Agent-WYC [trj]
Malware type: Trojan House
VPS version: 080512-0, 05/12/2008
[/b]

Any ideas?

Detection Win32:Agent-WYC [trj] trigged false positive alert on this file. It will be fixed in few hours in VPS 080513-0

I have just deleted this file from all our computers.

I suppose I have to reinstall PDF Creator.

Thanks for the info :slight_smile:

Unless you have some file recovery software to recover deleted files than yes reinstalling PDF Creator would seem your only option, unless you can extract the particular file from another location.

Deletion isn’t really a good first option (you have none left), ‘first do no harm’ don’t delete, send virus to the chest and investigate.

It’s back, causing false positives again:

C:\Program Files (x86)\PDFCreator Toolbar\v3.3.0.1\PDFCreator_Toolbar.dll

VPS version: 080929-0, 09/29/2008

I don’t know why, but since this is a different version, 3.0.0.1 of the pdf creator toolbar you will have to repeat the process again.

You could also check the offending/suspect file at: VirusTotal - Multi engine on-line virus scanner and report the findings here. You can’t do this with the file securely in the chest, you need to extract it to a temporary (not original) location first, see below.

Create a folder called Suspect in the C:\ drive, e.g. C:\Suspect. Now exclude that folder in the Standard Shield, Customize, Advanced, Add, type (or copy and paste) C:\Suspect* That will stop the standard shield scanning any file you put in that folder. You should now be able to export any file in the chest to this folder and upload it to VirusTotal without avast alerting.

If it is indeed a false positive, see http://forum.avast.com/index.php?topic=34950.msg293451#msg293451, how to report it to avast! and what to do to exclude them until the problem is corrected.

Hi, I’m having the same problem too. I contacted Philip at www.pdfforge.org and he suggested I scan it at http://www.virustotal.com/ , which I did. I also scanned at http://virusscan.jotti.org/ . Avast! and GData got the same results at both sites: Win32:Trojan:gen {other}.

Presumable no other scanners detected anything (or you would have said), GData also uses avast’s engine as one of its two AV engines.

If so, then follow the instructions in the link in my post, ‘how to report it’ and exclude, etc.

Thanks. I e-mailed the file to Avast! last night. No, no other scanners came up with results. Thanks again.

You’re welcome.

Hopefully it will be promptly corrected as it was the last time.