Help - Search - Members - Calendar
Full Version: Win32.Trojan.Agent
Lavasoft Support Forums > Archived Topics > Archives: Resolved/Inactive Topics > Resolved/Inactive False Postive Issues
b.kraus
I recently bought a Motorola ZINE ZN5 from T-Mobile. The phone came with motorola Phone Tools 5.0. When I tried to install it, Ad-Aware Anniversary Edition Live found that Win32.Trojan.Agent was in jstart.exe. The log is below.

MSG [1704] 2009/06/20 21:31:23: C:\users\admin\appdata\local\temp\jgl_rt\jstart.exe (diagnosis: Malware family: Win32.Trojan.Agent) => Block

Is this a false posivitve reading? I'm surprised reputable companies like Motorola and T-Mobile would have a Trojan infection in the software.

6/21/2009: Corrected SE to Anniversary Edition. I'm using Ad-Aware Anniversary Edition not SE
visitor
Ad-Aware SE is no longer supported and definitions ended in March. If it is a false positive, it may have already been removed from updated definitions for Ad-Aware 2007/2008/AE.
b.kraus
QUOTE(visitor @ Jun 21 2009, 12:53 PM) *
Ad-Aware SE is no longer supported and definitions ended in March. If it is a false positive, it may have already been removed from updated definitions for Ad-Aware 2007/2008/AE.


Thanks for replying. I made a mistake on the version of Ad-Aware I'm using .... I'm using the Anniversary Edition.
LS Albin
Hi b.kraus !

Is it possible for you attach the detected file in this thread? You need to zip or rar the file to get permisson to attach it. If you perform a scan of your harddrive a logfile is created. This logfile could also be useful to get hold of to solve the issue.

Thanks biggrin.gif

Albin

Lavasoft Malware Labs
ratnip
I'm also having problems with false win32trojanagent reports, but I think something more severe than a bad definition may be to blame. Often, running a quick scan, I get a report of the file: "C:\WINDOWS\System32\gxvxcjqsrtsoheibgqcubimvtvxdjvbqoocen.dll" being listed as "Win32.Trojan.Agent2". However, THERE IS NO SUCH FILE ON MY COMPUTER. I've changed my Vista "folder and search" options to show hidden and system files, looked at it from a command prompt started with administrator privilege, and NOTHING. A false positive report I can understand. A completely fabricated file is something else again. *** PS: updating to def file 0148.0065 didn't help... --Doug P, USA
LS Anders
Hello ratnip

Could you please post a log file from your scan when the file is detected. For more information about how to post a log file please see:
http://www.lavasoftsupport.com/index.php?showtopic=18033


Regards
LS Anders
ratnip
The indicated article seems to assume that Ad-Aware is running on Windows XP. I'm running Vista. Where would I look for the log file?
Thanks,
Doug Pintar
LS Anders
On vista the log files should located in:

C:\ProgramData\Lavasoft\Ad-Aware\Logs


Regards
LS Anders
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2009 Invision Power Services, Inc.