-
×InformationNeed Windows 11 help?Check documents on compatibility, FAQs, upgrade information and available fixes.
Windows 11 Support Center. -
-
×InformationNeed Windows 11 help?Check documents on compatibility, FAQs, upgrade information and available fixes.
Windows 11 Support Center. -
- HP Community
- Archived Topics
- Printers Archive
- File downloaded from HP was infected with a Trojan

Create an account on the HP Community to personalize your profile and ask a question

04-30-2016 07:54 PM
My scanning software seems to loose connection with the printer every couple of months and requires me to completely re-install the drivers. That's just the background to the issue today however.
To try to resolve my software problem, I ran HP Print and Scan Doctor but all it could recommend was a complete deletion and re-install of the drivers from HP. I agreeded and it (not me) opened a page at HP for downloading my specific printer's print and scan drivers. I downloaded the complete installation file, but the file never appeared in the downloads folder. I checked my BitDefender Antivirus logs just in case and found a warning that it had detected a Trojan in the file downloaded from HP.
Its possible something else infected the file - but I highly doubt it. Nothing else is showing an infection, the file was blocked before ever being executed, and nothing else in my logs indicates other infections. I run a very tight configuration, don't click on unknown links, run regular scans, etc, etc... since I work in the information security field I try to keep things very clean on my home computers too. It's possible BitDefender registered a false positive but I doubt that too. I'm posting this with the hope someone can help validate what I found or offer an explanation. (see attached screenshot, showing file details).
Thanks
Fabian
GSEC, GSNA, CISSP.
05-01-2016 05:53 PM - edited 05-01-2016 05:54 PM
The full location & filename was in the screenshot, on the right side, but for clarity here it is again:
C:\HP_LaserJet_Professional_CM1410_Series\InstallerContent\Help\CSIHelp.exe
and the infection reported by BitDefender is:
Gen:Trojan.Heur.JP.Yq3@amF0enji
Cheers
