FIXED False positives on VISE based installers from DAZ3D

Recently, AVAST has started giving false positives for Win32:Trojan-gen {VC} on older Installer V.I.S.E. based content installers from DAZ3D http://www.daz3d.com a producer of content for 3d programs, in particular Poser. This occurs on installers that have been sitting on my computer for years or ones that have just been downloaded. The only connection is that they are all older installer V.I.S.E. based installers.

A partial list of files it claims are infected:


27/03/2008 23:33:08	SYSTEM	1704	Sign of "Win32:Trojan-gen {VC}" has been found in "F:\scene\DAZ\PURCHASES\Characters_Maps\ps_mo108b-dayPoses.exe" file.  
27/03/2008 23:33:36	SYSTEM	1704	Sign of "Win32:Trojan-gen {VC}" has been found in "F:\scene\DAZ\PURCHASES\Characters_Maps\ps_bn039_M3Headmorph.exe" file.  
27/03/2008 23:34:08	Andrew	3836	Sign of "Win32:Trojan-gen {VC}" has been found in "F:\scene\DAZ\PURCHASES\Characters_Maps\ps_mo108b-dayPoses.exe" file.  
27/03/2008 23:35:03	Andrew	3268	Sign of "Win32:Trojan-gen {VC}" has been found in "F:\scene\DAZ\PURCHASES\Characters_Maps\ps_bn039_M3Headmorph.exe" file.  
27/03/2008 23:35:12	Andrew	3268	Sign of "Win32:Trojan-gen {VC}" has been found in "F:\scene\DAZ\PURCHASES\Characters_Maps\ps_mo108b-dayPoses.exe" file.  
27/03/2008 23:35:46	SYSTEM	1704	Sign of "Win32:Trojan-gen {VC}" has been found in "F:\scene\DAZ\PURCHASES\Clothing\ps_ac568b-M3casualcloth.exe" file.  
27/03/2008 23:36:10	SYSTEM	1704	Sign of "Win32:Trojan-gen {VC}" has been found in "F:\scene\DAZ\PURCHASES\Clothing\ps_ac556_M3HoodedCloak.exe" file.  
27/03/2008 23:36:12	SYSTEM	1704	Sign of "Win32:Trojan-gen {VC}" has been found in "F:\scene\DAZ\PURCHASES\Clothing\ps_ac526-M3Boots.exe" file.  
27/03/2008 23:36:13	SYSTEM	1704	Sign of "Win32:Trojan-gen {VC}" has been found in "F:\scene\DAZ\PURCHASES\Clothing\ps_ac352b_Treadz.exe" file.

ClamAV finds no infection.

I cannot redistribute these files legally.
These are the contact details for DAZ3D, they might provide you with sample files if you need them.
TOLL FREE: 1(800)267-5170
Phone: 1(801)495-1777
12637 South 265 West #300, Draper, UT 84020

The support email support@daz3d.com is probably not a good idea, as they have switched to one of these automated support systems which are remarkably good at losing stuff.

EDIT: using the VirusTotal website is also not an option, as files have to be uploaded to analyse

EDIT: This has been fixed now in the new VPS’s, thanks :smiley:

I’m afraid we can’t do anything about it without a sample file.

Unfortunately it is against the DAZ3D EULA to redistribute their content, so you will have to contact DAZ3D for copies of those files.

I have located another file from DAZ3d that shows the same resulsts as the above. Avast detects it as infected by a trojan, and when I try to download a new copy, Avast blocks the download because it claims it is infected. As this is a free download from DAZ3D and just contains texture templates it should be OK to snd you a copy of it.

I checked it at Virustotal, only Avast and one other consider it suspicious. Here are the results.


File ps_pe041b_SaraT.exe received on 03.29.2008 17:09:52 (CET)
Current status:    finished 
Result: 2/32 (6.25%) 
 Compact 
Print results  Antivirus	Version	Last Update	Result
AhnLab-V3	2008.3.29.0	2008.03.29	-
AntiVir	7.6.0.78	2008.03.28	-
Authentium	4.93.8	2008.03.29	-
Avast	4.7.1098.0	2008.03.29	Win32:Trojan-gen {VC}
AVG	7.5.0.516	2008.03.28	-
BitDefender	7.2	2008.03.29	-
CAT-QuickHeal	9.50	2008.03.28	-
ClamAV	0.92.1	2008.03.29	-
DrWeb	4.44.0.09170	2008.03.29	-
eSafe	7.0.15.0	2008.03.18	-
eTrust-Vet	31.3.5653	2008.03.29	-
Ewido	4.0	2008.03.29	-
F-Prot	4.4.2.54	2008.03.28	-
F-Secure	6.70.13260.0	2008.03.29	-
FileAdvisor	1	2008.03.29	-
Fortinet	3.14.0.0	2008.03.29	-
Ikarus	T3.1.1.20	2008.03.29	-
Kaspersky	7.0.0.125	2008.03.29	-
McAfee	5262	2008.03.28	-
Microsoft	1.3301	2008.03.28	-
NOD32v2	2983	2008.03.29	-
Norman	5.80.02	2008.03.28	-
Panda	9.0.0.4	2008.03.29	-
Prevx1	V2	2008.03.29	-
Rising	20.37.51.00	2008.03.29	-
Sophos	4.28.0	2008.03.29	-
Sunbelt	3.0.978.0	2008.03.18	-
Symantec	10	2008.03.29	-
TheHacker	6.2.92.258	2008.03.29	-
VBA32	3.12.6.3	2008.03.25	-
VirusBuster	4.3.26:9	2008.03.29	-
Webwasher-Gateway	6.6.2	2008.03.29	Win32.Malware.gen (suspicious)
Additional information
File size: 2635581 bytes
MD5: 9f53d93d5a62066b37539012e948066e
SHA1: 2eb2d4d7ee3a0577d4fea12d8b7164eddb6b61db
PEiD: Armadillo v1.71

But checking file at VirusTotal is implicit violation of your DAZ3D EULA to redistribute their content :slight_smile: due to VT should automatically resend problem file to virlabs if the number of positive detections will greater than some boundary value, isn’t it?

Yes I considered that, but as the file is free and contains only templates to assist creating textures, which are useless without the figure they are intended for, I don’t think DAZ3D will mind.

EDIT: I have also emailed the file in a password protected zip to AVAST.

EDIT 2: running AVAST version 4.7.1098 , VPS: 090329-0

Webwasher-Gateway 6.6.2 2008.03.29 Win32.Malware.gen (suspicious)

If you want to Avast remove the false positives you need to send the files, it is illegal to distribute any paid program, your are not sending the whole program or installers only some files. Alwil will not benefit or will not use the program for them, only for removes the false positives.

If you bothered read my original message properly, you would realise that it is the older CONTENT INSTALLERS themselves from DAZ3D that AVAST incorrectly flags as infected. They all seem to date from 2002 to 2004, by the way. The one I submitted to AVAST is FREE and contains nothing that is useful without the figure it is intended to be used with. As to why DAZ3d insist on distributing their stuff as executable installers, they seem to think graphic artists are incapable of opening a zip file.

Igor needs a sample… or, at least, a link to download them (post edited links to false positives and not live ones).

I have already sent a sample on the 29th:

I sent a zipped copy of the file ps_pe041b_SaraT.exe , which as you see avove gets flagged as infected with Win32:Trojan-gen {VC} to virus@avast.com

The title of the email is:
ps_pe041b_SaraT.exe reported as trojan by Avast

If the email has gotton lost, here is a link to where you can download it from DAZ3D. You need to sign up at the forums first. This download also gets flagged as infected, which reinforces my belief that this is a false positive, as the file dates from 2003 or thereabouts:

httXp://forum.daz3d.com/viewtopic.php?t=1204&highlight=sara

The link in the first post saying “Sara Template (PC)” is the one you want.

As I mentioned above, it is these older executable installers from 2002 to 2004 that get marked as infected, not their contents. Old downloads or fresh downloads, it doesn’t matter. Avast will attempt to block the download with a warning that it is infected.

EDIT: Should I post this in the viruses and worms forum? Or is it OK here?

EDIT: broke liniks as suggested below

Seems clean…

Thats not a direct link to the file That is a link to the post where the file is announced. Here is a direct link, but I have no idea if it works without being logged in to the forums.

hxxp ://forum.daz3d.com/forum_freebies/ps_pe041b_SaraT.exe (edited link)

EDIT thanks for checking
EDIT2: Broke link

Tech it is not the page that the link is on but a link to the executable file the “Sara Template (PC)” file also comes up clean.

Andrew please break the link (the modify button) so it isn’t active.

e.g. hxxp :// forum.daz3d.com/forum_freebies/ps_pe041b_SaraT.exe

Interesting, I paused the web shield to download the file and avast didn’t alert to it. I even did an ashQuick.exe scan and no detection.

Andrew, ensure you have the latest VPS 080331-0 and scan this file and your others that were detected. The VPS might have been corrected, certainly seems so for this one, I don’t know if that will be true for the others. Perhaps it will be OK if they were detected as having the same malware name.

Thanks for checking it out, everyone :slight_smile:

Sorry, I edited the link.

I’m on my Linux machine at the moment, been using it since Sunday. Hopefully the updates since Saturday have cleared up the problem. I will have to boot up WinXP.

Your welcome, let us know how you get on, though I’m sure you would ;D

Generally, they’re quite fast on correcting false positives.

Yes, the problem here was finding an affected file that I could send to AVAST. Once I found that, they sorted it quickly, thanks : D

I’ve scanned all the affected files and they all come up clear now, thank you

Thanks for the feedback.