Virus Name: Trojware.Win32.PSW.QQPass~8[at]27153879 for DECCHECKSetup.exe

This file is from Microsoft and tells you if you have a DVD decoder installed. I never got an alert from it before today. CAV is reporting it as infected by Trojware.Win32.PSW.QQPass~8[at]27153879. It behaves very strangely. I opened the folder containing the file and CAV detected it which it never did before. I told it to quarantine and nothing happened. The file stayed where it was and did not appear in the quarantine list. A subsequent right click scan detects nothing. When I delete the file and try to redownload it from Microsoft, it is detected again. I tell it to ignore once a couple of times and it downloads and then is not detected as infected with a right click scan. This seems very strange. The download link is:

http://www.microsoft.com/downloads/details.aspx?FamilyId=DE1491AC-0AB6-4990-943D-627E6ADE9FCB&displaylang=en

FP perhaps? Add it to your Safe files.

I did but I was reporting as an issue that they may want to address. The behavior of CAV with this file is very strange.

Another file that has never triggered an alert but does now for the same signature----wmfdist95.exe which installs the Windows Media 9.5 codecs. This is definitely a safe file. Another issue with both of these files and CAV is that if you tell CAV to quarantine the file, it renders the file useless with a reported file size of 0 if you try to upload it to one of the online scanners but it does not show up in the quarantine list and therefore can not be recovered. Something is very wrong here.

Hi Dch48,

We have downloaded the sample from the link you offered,but found no detected with CIS 3.10.102363.531 DB 1653.If you can find the FP file,you can submit with this link:http://internetsecurity.comodo.com/submit.php.Then we can go to have a look at it.

Regards,
hailong.■■■■

It is no longer being detected with DB 1655. I don’t know what was going on but it was very strange.