Author Topic: Trojan? or False Positive?  (Read 11922 times)

0 Members and 1 Guest are viewing this topic.

Logan

  • Guest
Trojan? or False Positive?
« on: September 27, 2006, 11:27:20 PM »
Hey all. Well I did a virus scan with avast nothing as usual ^_^ Then I did a CounterSpy scan same thing. Adaware had only two little cookies there, then ZoneAlarm did an Automatic scan and it found two Trojans... Yeah.. anyways I download Spybot Search and Destroy and did a scan nothing came up just two little cookies. Here is the names of the "Trojans" I did a google search on both of them by their name and nothing came up

Win32.ProcessKill File: C:\System Volume Information\_restore{8CF4D3C9-A44D-4F6E-8C86-DBA5BFC36BC5}\RP23\A0000965.dll
File: C:\Documents and Settings\Logan\Local Settings\Temp\nseE.tmp
Directory: C:\Documents and Settings\Logan\Local Settings\Temp\nseE.tmp


and Win32.Dialer.Fotosex (This was interesting seeing how I don't look up porn or anything like that)
RegistryKey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CONNECT

Is this a Trojan? or is it just Zone Alarm acting weird? Also I heard that Trojans gather Info and are kind of in a grayish area betwean virus and Spyware. Should I go through the hassle of Reconfiguring my computer if I do find a Trojan? or is that just being paranoid? Thanks in advance

P.S I posted here as well as the Zone Alarm forums but it seems people here know a little more about worms and such

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89104
  • No support PMs thanks
Re: Trojan? or False Positive?
« Reply #1 on: September 27, 2006, 11:54:29 PM »
You could also check the offending/suspect file at: VirusTotal - Multi engine on-line virus scanner
Or Jotti - Multi engine on-line virus scanner if any other scanners here detect them it is less likely to be a false positive. You can't do this with the file in the chest, you will need to move it out.

You can't do much about the one in C:\System Volume Information\_restore as this is windows protected storage, a part of system restore. The only way to clean infected _restore points is to disable system restore and reboot. This will clear ALL _restore points. Once you have disabled system restore, reboot, scan your PC again and if clear enable system restore.

Win XP-ME - How to disable System Restore
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Logan

  • Guest
Re: Trojan? or False Positive?
« Reply #2 on: September 27, 2006, 11:58:19 PM »
I did remove the files and it did not re-detect them.  But is my computer now screwed?  Will I need to Reconfig?

Spiritsongs

  • Guest
Re: Trojan? or False Positive?
« Reply #3 on: September 28, 2006, 01:19:23 AM »
 :)  Hi Logan :

      SPECIFICALLY, what Zone Alarm product was used ?
      AND was it an online scan ?

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89104
  • No support PMs thanks
Re: Trojan? or False Positive?
« Reply #4 on: September 28, 2006, 01:22:46 AM »
There is no way to tell if you have got rid of them, deletion is never a good first option.

However, since the majority were to be found in the Temp folders I would think not, you can do a google search for nseE.tmp and see if it brings up anything. There is only one hit that mentions Patchmaker.

Having two resident anti-virus scanners and I'm assuming that the ZA anti-virus is resident (active) ?
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Logan

  • Guest
Re: Trojan? or False Positive?
« Reply #5 on: September 28, 2006, 01:34:28 AM »
No I did not use an Online scanner I used Avast  :)  Also I'm using Zone Alarm Pro.

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: Trojan? or False Positive?
« Reply #6 on: September 28, 2006, 03:34:55 AM »
Win XP-ME - How to disable System Restore
Follow David's advice.
Do a boot time scanning with avast (or a thorough scanning).
Enable System Restore only after that  ;)

Oh, using ewido and/or a-squared scanning is a good thing too  ;)
The best things in life are free.

Logan

  • Guest
Re: Trojan? or False Positive?
« Reply #7 on: September 28, 2006, 05:41:59 AM »
well I reconfigured my computer, Downloaded all my security software and updated it.  Then I installed my drivers. I then scanned with Zone Alarm and the same two "Trojans" came up. This leads me to the belief that this is a False Positive. Dose this sound correct?

Logan

  • Guest
Re: Trojan? or False Positive?
« Reply #8 on: September 28, 2006, 06:49:56 AM »
Well I did a scan with Ewido and no "Trojan" came up just a few little cookies.  So is this a False Positive? and if so how do I got about reporting it? Thanks for all your help guys

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89104
  • No support PMs thanks
Re: Trojan? or False Positive?
« Reply #9 on: September 28, 2006, 03:01:03 PM »
As I said:
Quote from: DavidR
Having two resident anti-virus scanners and I'm assuming that the ZA anti-virus is resident (active) ?

Perhaps it is decision time as to which resident AV you have installed. Ewido and a-squared can be run as on-demand (non resident scanners and they aren't AVs).
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Logan

  • Guest
Re: Trojan? or False Positive?
« Reply #10 on: September 28, 2006, 07:24:59 PM »
I use Avast Anit-Virus this is the only Anti-Virus I use. It's home edition by the way

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89104
  • No support PMs thanks
Re: Trojan? or False Positive?
« Reply #11 on: September 28, 2006, 08:38:43 PM »
So where did this come from then ?
Quote from: Logan
then ZoneAlarm did an Automatic scan and it found two Trojans...

And this
Quote from: Logan
well I reconfigured my computer, Downloaded all my security software and updated it.  Then I installed my drivers. I then scanned with Zone Alarm and the same two "Trojans" came up. This leads me to the belief that this is a False Positive. Dose this sound correct?
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Logan

  • Guest
Re: Trojan? or False Positive?
« Reply #12 on: September 28, 2006, 08:45:53 PM »
So where did this come from then ?
Quote from: Logan
then ZoneAlarm did an Automatic scan and it found two Trojans...

And this
Quote from: Logan
well I reconfigured my computer, Downloaded all my security software and updated it.  Then I installed my drivers. I then scanned with Zone Alarm and the same two "Trojans" came up. This leads me to the belief that this is a False Positive. Dose this sound correct?

Because Zone Alarm Pro uses Anti-Spyware scan. Trojans are recognized by bother Virus and Spyware scans on average. Avast is a Virus scanner Zone alarm is a Spyware scanner

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89104
  • No support PMs thanks
Re: Trojan? or False Positive?
« Reply #13 on: September 28, 2006, 09:00:30 PM »
I was concerned that it might have been the ZA security Suite which includes anti-virus.

My firewall Outpost Pro also has a resident anti-spyware plugin but I disabled it as I have other on-demand anti-spyware AdAware, Spybot, SpywareBlaster and Ewido and I can run those if I fel I need a second opinion rather than have a resident anti-spyware runing. This could slow boot as it wil have an interaction with avast as for each file that ZA wants to scan avast will also scan, this duplication slowed my boot considerably.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Logan

  • Guest
Re: Trojan? or False Positive?
« Reply #14 on: September 28, 2006, 09:13:44 PM »
That's interesting... I have noticed that my boot time is slow and viewing webpages.... Could Avast and Zone Alarm Pro working together slow down webviewing as well?
I was concerned that it might have been the ZA security Suite which includes anti-virus.


I was concerned that it might have been the ZA security Suite which includes anti-virus.


I am not sure what you mean here.  I am not too familiar with all the aspects of ZA