Trojan in SP2 Update??

Corel Paint Shop Pro

Moderator: Kathy_9

Post Reply
jojomart
Posts: 51
Joined: Sun Oct 17, 2010 5:09 pm
operating_system: Windows 7 Home Premium
System_Drive: C
32bit or 64bit: 64 Bit
motherboard: FOXCONN ALOE 1.01
processor: 2.60 gigahertz AMD Phenom II X4 910
ram: 8GB
Video Card: ATI Radeon HD 4350
sound_card: Realtek High Definition Audio
Hard_Drive_Capacity: 1TB

Trojan in SP2 Update??

Post by jojomart »

I downloaded and installed the Paint Shop Pro X5 SP2 update and when Super Anti-Spyware did it's scan last night, it found this:

Trojan.Agent/Gen-FakeAlert[Local]
C:\USERS\OWNER\APPDATA\LOCAL\MICROSOFT\WINDOWS\TEMPORARY INTERNET FILES\LOW\CONTENT.IE5\UJ7TK17X\PSPX5_SP2[1].EXE

The program got rid of it, but what the heck??
Joelle
Posts: 1815
Joined: Wed Apr 02, 2008 10:12 am
operating_system: Windows 10
System_Drive: C
32bit or 64bit: 64 Bit
motherboard: Asus Prime B350M-A
processor: AMD Ryzen 5 1500 Quad-Core
ram: 16 GB RAM
Video Card: NVidia GeForce GTX 1050
Hard_Drive_Capacity: 1TB
Monitor/Display Make & Model: Samsung
Corel programs: PaintShop Pro X9
Location: UK

Re: Trojan in SP2 Update??

Post by Joelle »

I scanned the saved download with Avast and it said "No Threat Found".
:-)
Joëlle
Joëlle
(PSPX9 )
jojomart
Posts: 51
Joined: Sun Oct 17, 2010 5:09 pm
operating_system: Windows 7 Home Premium
System_Drive: C
32bit or 64bit: 64 Bit
motherboard: FOXCONN ALOE 1.01
processor: 2.60 gigahertz AMD Phenom II X4 910
ram: 8GB
Video Card: ATI Radeon HD 4350
sound_card: Realtek High Definition Audio
Hard_Drive_Capacity: 1TB

Re: Trojan in SP2 Update??

Post by jojomart »

It wouldn't show in the download because it is something that happens as it's being installed, otherwise it wouldn't be in the temporary data file.
df
Posts: 1224
Joined: Mon Feb 08, 2010 11:21 pm
operating_system: Windows 11
System_Drive: C
32bit or 64bit: 64 Bit
motherboard: GIGABYTE Z690 AERO G DDR4
processor: 13th Gen Intel Core i7-13700K
ram: 64gb
Video Card: RTX 3060 Ti 8gb GDRR6
Hard_Drive_Capacity: 1 Tb
Location: Washington State
Contact:

Re: Trojan in SP2 Update??

Post by df »

Why is there a [1]? That usually indicates that this is a second file of the same name within the same folder (Windows adds a [1] or (1) to differentiate which came second). Is there a file without that somewhere else? If so, why didn't Super-Antispyware hit on that? Is it the exact same size?
Regards, Dan

"Smoke me a kipper, I'll be back for breakfast."
jojomart
Posts: 51
Joined: Sun Oct 17, 2010 5:09 pm
operating_system: Windows 7 Home Premium
System_Drive: C
32bit or 64bit: 64 Bit
motherboard: FOXCONN ALOE 1.01
processor: 2.60 gigahertz AMD Phenom II X4 910
ram: 8GB
Video Card: ATI Radeon HD 4350
sound_card: Realtek High Definition Audio
Hard_Drive_Capacity: 1TB

Re: Trojan in SP2 Update??

Post by jojomart »

When the pop up started downloading the file from Corel, it got about 30% done and then it froze up. I clicked on the link to download it manually and it brought up IE instead of Firefox, so I cancelled the download and copied the link into Firefox to re-download it. After that, I just double clicked the .exe file on my hard drive to install it. That may be why there was the [1] there, but I can't imagine that that would be the reason for it to be named a Trojan.
df
Posts: 1224
Joined: Mon Feb 08, 2010 11:21 pm
operating_system: Windows 11
System_Drive: C
32bit or 64bit: 64 Bit
motherboard: GIGABYTE Z690 AERO G DDR4
processor: 13th Gen Intel Core i7-13700K
ram: 64gb
Video Card: RTX 3060 Ti 8gb GDRR6
Hard_Drive_Capacity: 1 Tb
Location: Washington State
Contact:

Re: Trojan in SP2 Update??

Post by df »

If SAS didn't find any of the other downloads as trojans then I'd just chalk it up to a false positive result from SAS. It happens. If it happens more than rarely then you may look into it further.

edit: The reason ie was brought up the first time was because that's what is set as your default browser in Windows. You can have FireFox (or whatever) set as default if you don't wish to invoke ie in the future, but it's just a minor annoyance for most.
Regards, Dan

"Smoke me a kipper, I'll be back for breakfast."
jojomart
Posts: 51
Joined: Sun Oct 17, 2010 5:09 pm
operating_system: Windows 7 Home Premium
System_Drive: C
32bit or 64bit: 64 Bit
motherboard: FOXCONN ALOE 1.01
processor: 2.60 gigahertz AMD Phenom II X4 910
ram: 8GB
Video Card: ATI Radeon HD 4350
sound_card: Realtek High Definition Audio
Hard_Drive_Capacity: 1TB

Re: Trojan in SP2 Update??

Post by jojomart »

No, IE isn't my default browswer, Firefox is and always has been.
Radim
Posts: 712
Joined: Mon Nov 01, 2010 5:54 pm
operating_system: Windows 10
System_Drive: C
32bit or 64bit: 64 Bit
ram: 4GB
Monitor/Display Make & Model: 27 inch

Re: Trojan in SP2 Update??

Post by Radim »

I often use service like VirusTotal.com for file(s) not digitaly signed.

There is also SUPERAntiSpyware (https://www.virustotal.com/file/bd00e95 ... 360228153/)

but my experience over years is that, that not only this *security* tool is too offensive sometimes and I get in 10-15 % of scanned files false possitive. You can also report to developers of sofware... Or you can wait while (1-2 week/s) for updated database...
JStanley
Posts: 313
Joined: Wed Jul 27, 2011 12:41 am
operating_system: Windows XP Home
System_Drive: C

Re: Trojan in SP2 Update??

Post by JStanley »

df wrote:Why is there a [1]? That usually indicates that this is a second file of the same name within the same folder (Windows adds a [1] or (1) to differentiate which came second). Is there a file without that somewhere else? If so, why didn't Super-Antispyware hit on that? Is it the exact same size?
Regarding browser caches, especially Internet Explorer's Temporary Internet Files, this is technically incorrect...

That being said, this is most likely a false positive.
sdcigarbear
Posts: 1
Joined: Sat Nov 17, 2012 2:37 am
operating_system: Windows 7 Ultimate
System_Drive: C
32bit or 64bit: 64 Bit
Location: Washington USA

Re: Trojan in SP2 Update??

Post by sdcigarbear »

No virus detected with Panda Cloud Antivirus as of Wednesday night when I downloaded SP2.
Post Reply