b.kraus
Jun 21 2009, 04:26 AM
I recently bought a Motorola ZINE ZN5 from T-Mobile. The phone came with motorola Phone Tools 5.0. When I tried to install it, Ad-Aware Anniversary Edition Live found that Win32.Trojan.Agent was in jstart.exe. The log is below.
MSG [1704] 2009/06/20 21:31:23: C:\users\admin\appdata\local\temp\jgl_rt\jstart.exe (diagnosis: Malware family: Win32.Trojan.Agent) => Block
Is this a false posivitve reading? I'm surprised reputable companies like Motorola and T-Mobile would have a Trojan infection in the software.
6/21/2009: Corrected SE to Anniversary Edition. I'm using Ad-Aware Anniversary Edition not SE
visitor
Jun 21 2009, 12:53 PM
Ad-Aware SE is no longer supported and definitions ended in March. If it is a false positive, it may have already been removed from updated definitions for Ad-Aware 2007/2008/AE.
b.kraus
Jun 21 2009, 02:34 PM
QUOTE(visitor @ Jun 21 2009, 12:53 PM)

Ad-Aware SE is no longer supported and definitions ended in March. If it is a false positive, it may have already been removed from updated definitions for Ad-Aware 2007/2008/AE.
Thanks for replying. I made a mistake on the version of Ad-Aware I'm using .... I'm using the Anniversary Edition.
LS Albin
Jun 22 2009, 08:41 AM
Hi b.kraus !
Is it possible for you attach the detected file in this thread? You need to zip or rar the file to get permisson to attach it. If you perform a scan of your harddrive a logfile is created. This logfile could also be useful to get hold of to solve the issue.
Thanks
Albin
Lavasoft Malware Labs
ratnip
Jul 4 2009, 07:34 PM
I'm also having problems with false win32trojanagent reports, but I think something more severe than a bad definition may be to blame. Often, running a quick scan, I get a report of the file: "C:\WINDOWS\System32\gxvxcjqsrtsoheibgqcubimvtvxdjvbqoocen.dll" being listed as "Win32.Trojan.Agent2". However, THERE IS NO SUCH FILE ON MY COMPUTER. I've changed my Vista "folder and search" options to show hidden and system files, looked at it from a command prompt started with administrator privilege, and NOTHING. A false positive report I can understand. A completely fabricated file is something else again. *** PS: updating to def file 0148.0065 didn't help... --Doug P, USA
LS Anders
Jul 6 2009, 09:04 AM
Hello ratnip
Could you please post a log file from your scan when the file is detected. For more information about how to post a log file please see:
http://www.lavasoftsupport.com/index.php?showtopic=18033Regards
LS Anders
ratnip
Jul 9 2009, 06:47 AM
The indicated article seems to assume that Ad-Aware is running on Windows XP. I'm running Vista. Where would I look for the log file?
Thanks,
Doug Pintar
LS Anders
Jul 9 2009, 08:51 AM
On vista the log files should located in:
C:\ProgramData\Lavasoft\Ad-Aware\Logs
Regards
LS Anders
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please
click here.