<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Re: Win32 backdoor D in Security</title>
<link>http://www.dslreports.com/forum/r20187040</link>
<description></description>
<language>en</language>
<pubDate>Sat, 26 Jul 2008 13:32:50 EDT</pubDate>
<lastBuildDate>Sat, 26 Jul 2008 13:32:50 EDT</lastBuildDate>

<item>
<title>Update</title>
<link>http://www.dslreports.com/forum/remark,20276381</link>
<description><![CDATA[<A HREF="/useremail/u/668609"><b>EGeezer</b></A> : The Zone Alarm false positive issue appears to be resolved by updates to ZoneAlarm's engine (not just the updater function)  and CCleaner - see <br> &raquo;<A HREF="http://forum.piriform.com/index.php?s=&showtopic=14886&view=findpost&p=99079" >forum.piriform.com/index.php?s=&&middot;&middot;&middot;&p=99079</A><br><br> <br><small>--<br>Mayors of New York come from nowhere and go nowhere.<br>Wallace Sayre (apparently, so do governors... )</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20276381</guid>
<pubDate>Thu, 03 Apr 2008 13:08:58 EDT</pubDate>
</item>

<item>
<title>Re: Win32 backdoor D</title>
<link>http://www.dslreports.com/forum/remark,20218553</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : ZA Forum confirms false positive, but it was this site that gave me a warm fuzzy feeling and the inclination to not worry about it.<br><br>DSL Forum rocks! Especially for a newbie-to-midi like me.<br><br>Thanks and &raquo;<A HREF="http://www.zonealarm.com/store/content/forms/spyware_report.jsp" >www.zonealarm.com/store/content/&middot;&middot;&middot;port.jsp</A>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20218553</guid>
<pubDate>Mon, 24 Mar 2008 17:58:25 EDT</pubDate>
</item>

<item>
<title>Re: Win32 backdoor D</title>
<link>http://www.dslreports.com/forum/remark,20194772</link>
<description><![CDATA[<A HREF="/useremail/u/679515"><b>CalamityJane</b></A> : Even Microsoft says it's clean...here is your report<br> <blockquote><small>quote:</small><hr>Hello. The Microsoft Malware Protection Center (MMPC) has finished analyzing submission ID 16331310 and the results are listed below. If the files were determined to be malware or potentially unwanted software, the results will identify the threat for each file submitted.<br> <br>This is the last e-mail the MMPC will send to this e-mail address concerning this submission ID.<br> <br>Analyst comments:<br>=================<br> <br>=================<br> <br>Analysis summary:<br>=================<br>Total Files: 1<br>Clean: 1<br>Malware: 0<br>Malware Related: 0<br>Malware Container: 0<br>Potentially Unwanted Software: 0<br>Potentially Unwanted Software Container: 0<br>Postponed: 0<br>Not Yet Analyzed: 0<br> <br>=================<br> <br>Per-file summary:<br>=================<br>20080319_175736820_0_ccsetup205.exe                 | Clean<br> <br>=================<br> <br>Note: in the course of analyzing the files that you submitted, the MMPC decompresses the files in your submission, such as extracting files from archives or other containers. Subsequently you may see more files listed than you originally submitted.<br> <br>Category Descriptions:<br> <br>Clean<br>Files that do not appear to be malware or potentially unwanted software.<br> <br>Thank you for contacting the Microsoft Malware Protection Center.<br><hr></blockquote><br>So the installer at least is fine if you want to reinstall it.<br><br>It is hard to say what is causing the MSRT to remove it because you can't "catch" what file is being flagged. It may need to be addressed by the Developer of the CCleaner to get in touch with Microsoft to report his program is being targeted by that tool.<br><br>As we know it has already been reported to Zone Alarm so it is in their hands now to fix it.<br><small>--<br>It takes a disaster to make a woman out of a female<br>Microsoft MVP/Windows Security 2003-2008<br>Proud Member of <A HREF="http://asap.maddoktor2.com/">ASAP </a> (Alliance of Security Analysis Professionals)</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20194772</guid>
<pubDate>Thu, 20 Mar 2008 09:13:50 EDT</pubDate>
</item>

<item>
<title>Re: Win32 backdoor D</title>
<link>http://www.dslreports.com/forum/remark,20193948</link>
<description><![CDATA[<A HREF="/useremail/u/668609"><b>EGeezer</b></A> : You might post at CCleaner's forum. they're looking for reports on this at <br><br> &raquo;<A HREF="http://forum.piriform.com/index.php?showtopic=14886" >forum.piriform.com/index.php?showtopic=14886</A> <br><br>Also you can submit the flagged file to Jotti at <br><br> &raquo;<A HREF="http://virusscan.jotti.org/" >virusscan.jotti.org/</A>  <br><br>I agree, it's probably a FP but never hurts to check. <br><small>--<br>Mayors of New York come from nowhere and go nowhere.<br>Wallace Sayre (apparently, so do governors... )</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20193948</guid>
<pubDate>Thu, 20 Mar 2008 01:21:49 EDT</pubDate>
</item>

<item>
<title>Re: Win32 backdoor D</title>
<link>http://www.dslreports.com/forum/remark,20193027</link>
<description><![CDATA[<A HREF="/useremail/u/679515"><b>CalamityJane</b></A> : Ok this isn't results (hasn't been analyzed yet) but they do acknowledge they got it FYI :)<br>Very nice feature that new submission thingy for them :)<br> <blockquote><small>quote:</small><hr>Hello. Thank you for submitting suspicious files to the Microsoft Malware Protection Center (MMPC).<br> <br>The MMPC will analyze the files that you submitted to determine if the files are malware or potentially unwanted software. If the files are identified as new malware, the MMPC will add detection signatures for the new malware and publish the signatures after they have been tested and certified.<br> <br>Your submission has been assigned ID 16331310.<br> <br>The MMPC has completed an initial scan of the files you submitted and the results are below. If the files are known malware or potentially unwanted software, the results will identify the threat for each file submitted.<br> <br>The MMPC will send a second and final e-mail to this e-mail address once it makes a final determination concerning this specific submission.<br> <br>Initial analysis summary:<br>=================<br>Total Files: 1<br>Clean: 0<br>Malware: 0<br>Malware Related: 0<br>Malware Container: 0<br>Potentially Unwanted Software: 0<br>Potentially Unwanted Software Container: 0<br>Postponed: 0<br>Not Yet Analyzed: 1<br> <br>=================<br> <br>Per-file summary:<br>=================<br>20080319_175736820_0_ccsetup205.exe                 | Not Yet Analyzed<br> <br>=================<br> <br>Note: in the course of analyzing the files that you submitted, the MMPC decompresses the files in your submission, such as extracting files from archives or other containers. Subsequently you may see more files listed than you originally submitted.<br> <br>Category Descriptions:<br> <br>Clean<br>Files that do not appear to be malware or potentially unwanted software.<br> <br>Malware<br>Files that appear to be known malware.  Malware includes viruses, Trojans, worms, file infectors, etc.<br> <br>Malware Related<br>Files that are not malicious by themselves and should not pose a threat by themselves.<br> <br>Malware Container<br>Container files are archives, binders, etc. that contain files in the "malware" category. Note that they may also contain files in the "Clean" category.<br> <br>Potentially Unwanted Software<br>Files that have been identified as potentially unwanted software.  Potentially unwanted software includes dialers, adware, spyware, etc.<br> <br>Potentially Unwanted Software Container<br>Container files are archives, binders, etc. that contain files in the "spyware" category.  Note that they may also contain files in the "Clean" category.<br> <br>Postponed and Auto-postponed<br>The file does not appear to be malware or potentially unwanted software, but more analysis is necessary to confirm the file is not malicious.<br> <br>Not Yet Analyzed<br>The file will require further analysis to determine whether the file is malicious or not.<br> <br>Thank you for contacting the Microsoft Malware Protection Center.<br><hr></blockquote><br> <br><small>--<br>It takes a disaster to make a woman out of a female<br>Microsoft MVP/Windows Security 2003-2008<br>Proud Member of <A HREF="http://asap.maddoktor2.com/">ASAP </a> (Alliance of Security Analysis Professionals)</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20193027</guid>
<pubDate>Wed, 19 Mar 2008 21:43:04 EDT</pubDate>
</item>

<item>
<title>Re: Win32 backdoor D</title>
<link>http://www.dslreports.com/forum/remark,20192764</link>
<description><![CDATA[<A HREF="/useremail/u/679515"><b>CalamityJane</b></A> : Ok file submitted to Microsoft for analysis at the <br>Microsoft Malware Protection Center (submit page)<br>&raquo;<A HREF="http://www.microsoft.com/security/portal/" >www.microsoft.com/security/portal/</A><br><br>I cannot say if they will respond but at least they will get my report,including the scan results posted earlier and a copy of the file :)<br><br>That's the best I can do.<br><small>--<br>It takes a disaster to make a woman out of a female<br>Microsoft MVP/Windows Security 2003-2008<br>Proud Member of <A HREF="http://asap.maddoktor2.com/">ASAP </a> (Alliance of Security Analysis Professionals)</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20192764</guid>
<pubDate>Wed, 19 Mar 2008 20:58:34 EDT</pubDate>
</item>

<item>
<title>Re: Win32 backdoor D</title>
<link>http://www.dslreports.com/forum/remark,20192521</link>
<description><![CDATA[<A HREF="/useremail/u/679515"><b>CalamityJane</b></A> : <div class="bquote"><small>said by Mikey :</small><br><br>Suggestions?<br> </div>1.  Will have to wait for Zone Alarm to correct it. It's their move now.<br><br>2.  Don't use the Microsoft Malicious Software Removal Tool (for now).<br><br>I'll see if I can find a way to get the CCleaner installer to them to examine.  I just downloaded a fresh copy and only Prevx Heuristics has a possible problem with it (Heuristics can do that - have FPs).  All other scanners call it clean<br>   <blockquote><small>quote:</small><hr> File ccsetup205.exe received on 03.20.2008 01:01:51 (CET)<br>Current status:finished <br>Result: 1/32 (3.13%)<br>&#9;<br>Antivirus &#9;Version &#9;Last Update &#9;Result<br>AhnLab-V3&#9;2008.3.19.1&#9;2008.03.19&#9;-<br>AntiVir&#9;7.6.0.75&#9;2008.03.19&#9;-<br>Authentium&#9;4.93.8&#9;2008.03.19&#9;-<br>Avast&#9;4.7.1098.0&#9;2008.03.19&#9;-<br>AVG&#9;7.5.0.516&#9;2008.03.19&#9;-<br>BitDefender&#9;7.2&#9;2008.03.20&#9;-<br>CAT-QuickHeal&#9;9.50&#9;2008.03.14&#9;-<br>ClamAV&#9;0.92.1&#9;2008.03.20&#9;-<br>DrWeb&#9;4.44.0.09170&#9;2008.03.19&#9;-<br>eSafe&#9;7.0.15.0&#9;2008.03.18&#9;-<br>eTrust-Vet&#9;31.3.5628&#9;2008.03.19&#9;-<br>Ewido&#9;4.0&#9;2008.03.19&#9;-<br>F-Prot&#9;4.4.2.54&#9;2008.03.19&#9;-<br>F-Secure&#9;6.70.13260.0&#9;2008.03.19&#9;-<br>FileAdvisor&#9;1&#9;2008.03.20&#9;-<br>Fortinet&#9;3.14.0.0&#9;2008.03.19&#9;-<br>Ikarus&#9;T3.1.1.20&#9;2008.03.19&#9;-<br>Kaspersky&#9;7.0.0.125&#9;2008.03.20&#9;-<br>McAfee&#9;5255&#9;2008.03.20&#9;-<br>Microsoft&#9;1.3301&#9;2008.03.19&#9;-<br>NOD32v2&#9;2961&#9;2008.03.20&#9;-<br>Norman&#9;5.80.02&#9;2008.03.19&#9;-<br>Panda&#9;9.0.0.4&#9;2008.03.18&#9;-<br>Prevx1&#9;V2&#9;2008.03.20&#9;Heuristic: Suspicious Hijacker<br>Rising&#9;20.36.22.00&#9;2008.03.19&#9;-<br>Sophos&#9;4.27.0&#9;2008.03.20&#9;-<br>Sunbelt&#9;3.0.978.0&#9;2008.03.18&#9;-<br>Symantec&#9;10&#9;2008.03.20&#9;-<br>TheHacker&#9;6.2.92.250&#9;2008.03.19&#9;-<br>VBA32&#9;3.12.6.3&#9;2008.03.17&#9;-<br>VirusBuster&#9;4.3.26:9&#9;2008.03.19&#9;-<br>Webwasher-Gateway&#9;6.6.2&#9;2008.03.19&#9;-<br>Additional information<br>File size: 2733520 bytes<br>MD5: 06ab7fd00ca2f03baf4616c40bb2c761<br>SHA1: 96f0796a003371529d023d4381f7d6e8e6d55f1e<br>PEiD: -<br>packers: WiseSFXDropper, WiseSFXDropper, WiseSFXDropper<br>Prevx info: &raquo;<A HREF="http://info.prevx.com/aboutprogramtext.asp?PX5=13550397D0C62AA4B5562946E6D56D007DCE38E9" >info.prevx.com/aboutprogramtext.&middot;&middot;&middot;7DCE38E9</A><br><hr></blockquote><br><br>If you download the installer again check it first at VirusTotal:<br>&raquo;<A HREF="http://www.virustotal.com/" >www.virustotal.com/</A><br><br>Check the MD5 to my file above listed<br>(MD5: 06ab7fd00ca2f03baf4616c40bb2c761)<br>If it is the same, you have the clean one (with the FP problem ZA and MSRT).<br><br>All you can do is ignore those false reports.<br><small>--<br>It takes a disaster to make a woman out of a female<br>Microsoft MVP/Windows Security 2003-2008<br>Proud Member of <A HREF="http://asap.maddoktor2.com/">ASAP </a> (Alliance of Security Analysis Professionals)</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20192521</guid>
<pubDate>Wed, 19 Mar 2008 20:14:37 EDT</pubDate>
</item>

<item>
<title>Re: Win32 backdoor D</title>
<link>http://www.dslreports.com/forum/remark,20192283</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : Hmmm. Got an Office Update today along with Microsoft Malicious Malware Tool. You guessed it. CCleaner disappeared again.<br><br>Checked back with ZA site and no definitive answer there.<br><br>Suggestions?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20192283</guid>
<pubDate>Wed, 19 Mar 2008 19:29:01 EDT</pubDate>
</item>

<item>
<title>Re: Win32 backdoor D</title>
<link>http://www.dslreports.com/forum/remark,20187645</link>
<description><![CDATA[<A HREF="/useremail/u/679515"><b>CalamityJane</b></A> : Ah, good Mikey - glad to hear.  Thanks for reporting it too so they can fix it :)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20187645</guid>
<pubDate>Tue, 18 Mar 2008 21:16:43 EDT</pubDate>
</item>

<item>
<title>Re: Win32 backdoor D</title>
<link>http://www.dslreports.com/forum/remark,20187167</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : ZA quarantined it on regular weekly scan and maybe I overreacted and asked ZA to delete it. Simply reinstalled and life is good.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20187167</guid>
<pubDate>Tue, 18 Mar 2008 19:51:46 EDT</pubDate>
</item>

<item>
<title>Re: Win32 backdoor D</title>
<link>http://www.dslreports.com/forum/remark,20187135</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : If I downloaded CCleaner from the creator's site then I wouldnt have let ZA scanner delete it.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20187135</guid>
<pubDate>Tue, 18 Mar 2008 19:45:11 EDT</pubDate>
</item>

<item>
<title>Re: Win32 backdoor D</title>
<link>http://www.dslreports.com/forum/remark,20187040</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : Thanks Calamity! I would think it a false positive. I got it from Piraforms site. Made report to Check Point.<br><br>Did I ever mention, you're the best?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20187040</guid>
<pubDate>Tue, 18 Mar 2008 19:25:54 EDT</pubDate>
</item>

<item>
<title>Re: Win32 backdoor D</title>
<link>http://www.dslreports.com/forum/remark,20187022</link>
<description><![CDATA[<A HREF="/useremail/u/679515"><b>CalamityJane</b></A> : Provided you downloaded it from an authorized source, it may likely be a false detection.  It's being reported over in the Zone Alarm Forums in this topic:<br>ZAPro found trojan in CCleaner<br>&raquo;<A HREF="http://forums.zonelab.com/zonelabs/board/message?board.id=Antivirus&message.id=27597" >forums.zonelab.com/zonelabs/boar&middot;&middot;&middot;id=27597</A><br><br>and as stated in that thread by one of their gurus, here is where to report it and get it checked out:<br> <blockquote><small>quote:</small><hr>probably a false positive from the ZA own scanner.<br>Report it to ZA including as much details as possible, including a download link to the ccleaner you use.<br> <br>Here:<br>&raquo;<A HREF="http://www.zonealarm.com/store/content/forms/spyware_report.jsp" >www.zonealarm.com/store/content/&middot;&middot;&middot;port.jsp</A><br> <hr></blockquote><br><small>--<br>It takes a disaster to make a woman out of a female<br>Microsoft MVP/Windows Security 2003-2008<br>Proud Member of <A HREF="http://asap.maddoktor2.com/">ASAP </a> (Alliance of Security Analysis Professionals)</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20187022</guid>
<pubDate>Tue, 18 Mar 2008 19:22:42 EDT</pubDate>
</item>

<item>
<title>Win32 backdoor D</title>
<link>http://www.dslreports.com/forum/remark,20186935</link>
<description><![CDATA[<A HREF="/useremail/u/0"><b>anon</b></A> : I downloaded CCleaner. I run Zone Alarm Pro. The spyware scanner sees CCleaner as Win32backdoorD.<br>When I had ZA remove the alledged trojan, CCleaner disapears.<br><br>Suggestions please?]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,20186935</guid>
<pubDate>Tue, 18 Mar 2008 19:08:41 EDT</pubDate>
</item>

</channel>
</rss>
