This HP Community is for Customer to Customer Product Support. First Time Here? Check Out Videos on How to Search, Register, Post and More.

Re: Suspected False Positive Virus Detection (3188 Views)
Reply
Top Student
Adscense
Posts: 5
Registered: ‎10-02-2009
Message 1 of 11 (3,226 Views)
Accepted Solution

Suspected False Positive Virus Detection

[ Edited ]

I recently install Avira Antivirus and run some scans in my Compaq Presario and a virus known as APPL/ACLSet is always detected in the following location:

 

 

 

C:\Program Files\Hewlett-Packard\HP TCS\SetACL.exe

    [DETECTION] Contains recognition pattern of the APPL/ACLSet application

 

 

 

 

Since it's in HP program file I suspect it's a file that is used by HP for certain purposes like updating or others. So I just ignore it. 

On 3 Oct 2009 I run a scan again and this time there are more new detections in addition to the old one as below:

 

 

 

 

C:\Program Files\Hewlett-Packard\HP TCS\SetACL.exe

    [DETECTION] Contains recognition pattern of the APPL/ACLSet application

C:\Program Files\Hewlett-Packard\KBD\KbdStub.exe

    [DETECTION] Is the TR/Dropper.Gen Trojan

Begin scan in 'D:\' <FACTORY_IMAGE>

D:\hp\Drv\APP01300\src\KbdStub.exe

    [DETECTION] Is the TR/Dropper.Gen Trojan


End of the scan: Saturday, 3 October, 2009  10:26

Used time:  1:00:06 Hour(s)

 

 

 

 

Upon checking with Avira website, it's found that TR|Dropper.Gen is a new virus just detected on 1 Oct 2009 and it seems to be the  top and latest threat.

Again since it's associated to HP program I just ignore it for now.

 

Can anyone give me a 100% confirmation if these detection were just false positive or are they really malicious virus/malware? Should I just ignore them or get rid of them? If I do get rid of them and they turn out to be legitimate program of HP, will it affect my PC in anyway?

 

Thank you very much in advance.  :smileyhappy:

 

 

Message Edited by Adscense on 10-02-2009 08:58 PM
Message Edited by Adscense on 10-02-2009 08:59 PM
Please use plain text.
Top Student
hpfannr1
Posts: 7
Registered: ‎10-03-2009
Message 2 of 11 (3,267 Views)

Re: Suspected False Positive Virus Detection

i have the same problem, and delted the file: C:\Program Files\Hewlett-Packard\KBD\KbdStub.exe

 

i would also like to know, if this was a mistake, and if it is a virus.

 

 

Please use plain text.
Top Student
Adscense
Posts: 5
Registered: ‎10-02-2009
Message 3 of 11 (3,188 Views)

Re: Suspected False Positive Virus Detection

Hello hpfannr1, I have checked with HP Total care email support and they have confirmed that they are indeed viruses. Advice was to delete them.

 

Please use plain text.
Top Student
hpfannr1
Posts: 7
Registered: ‎10-03-2009
Message 4 of 11 (3,184 Views)

Re: Suspected False Positive Virus Detection

thx a lot!
Please use plain text.
Top Student
hpfannr1
Posts: 7
Registered: ‎10-03-2009
Message 5 of 11 (3,162 Views)

the only problem is, i cant delete it, and my new one is on:

 

 D:\hp\Drv\APP08750\src\kbd.exe'

 

so thats the factory_image. i even cant reinstall the system now.

Please use plain text.
Top Student
Adscense
Posts: 5
Registered: ‎10-02-2009
Message 6 of 11 (3,130 Views)

Re: problem

I suggest you contact HP Support for help cos I'm not familiar with these computer stuff myself. Hope they can help you out. 
 
Email add:  pavilion_support_en@mail.support.hp.com
 
 

Please use plain text.
Top Student
hpfannr1
Posts: 7
Registered: ‎10-03-2009
Message 7 of 11 (3,120 Views)

Re: problem

I will do so, thanks again Adscense...
Please use plain text.
Top Student
Adscense
Posts: 5
Registered: ‎10-02-2009
Message 8 of 11 (2,987 Views)

Re: problem

Hi, 

 

C:\Program Files\Hewlett-Packard\HP TCS\SetACL.exe

    [DETECTION] Contains recognition pattern of the APPL/ACLSet application

C:\Program Files\Hewlett-Packard\KBD\KbdStub.exe

    [DETECTION] Is the TR/Dropper.Gen Trojan

Begin scan in 'D:\' <FACTORY_IMAGE>

D:\hp\Drv\APP01300\src\KbdStub.exe

    [DETECTION] Is the TR/Dropper.Gen Trojan

 

I refer to the above, m beginning to suspect that they were false positive and it was a mistake to delete them.

I deleted both SetACL.exe , TR/Dropper.Gen, one of the TR/Dropper.Gen in the factory image couldn't be scanned so I deleted it.

 

But after that I couldn't open the HP Advisor, so I restore the PC to the original factory conditions. Immediately after that I checked and found the same SetACL.exe in the same location.

 

I think they are not virus after all. :smileysad:

 

 

Please use plain text.
Top Student
hpfannr1
Posts: 7
Registered: ‎10-03-2009
Message 9 of 11 (2,986 Views)

Re: problem

No, they weren't, as HP support told me...
Please use plain text.
Top Student
Adscense
Posts: 5
Registered: ‎10-02-2009
Message 10 of 11 (2,970 Views)

Re: problem

They told me they were viruses and advised me to delete them!!!  Now they are saying otherwise. :smileymad:
Please use plain text.