Trojan in SP2 Update??
Moderator: Kathy_9
-
jojomart
- Posts: 51
- Joined: Sun Oct 17, 2010 5:09 pm
- System_Drive: C
- 32bit or 64bit: 64 Bit
- motherboard: FOXCONN ALOE 1.01
- processor: 2.60 gigahertz AMD Phenom II X4 910
- ram: 8GB
- Video Card: ATI Radeon HD 4350
- sound_card: Realtek High Definition Audio
- Hard_Drive_Capacity: 1TB
Trojan in SP2 Update??
I downloaded and installed the Paint Shop Pro X5 SP2 update and when Super Anti-Spyware did it's scan last night, it found this:
Trojan.Agent/Gen-FakeAlert[Local]
C:\USERS\OWNER\APPDATA\LOCAL\MICROSOFT\WINDOWS\TEMPORARY INTERNET FILES\LOW\CONTENT.IE5\UJ7TK17X\PSPX5_SP2[1].EXE
The program got rid of it, but what the heck??
Trojan.Agent/Gen-FakeAlert[Local]
C:\USERS\OWNER\APPDATA\LOCAL\MICROSOFT\WINDOWS\TEMPORARY INTERNET FILES\LOW\CONTENT.IE5\UJ7TK17X\PSPX5_SP2[1].EXE
The program got rid of it, but what the heck??
Joanne's Digital Designs
http://www.joannes-digital-designs.com
http://www.joannes-digital-designs.com
-
Joelle
- Posts: 1815
- Joined: Wed Apr 02, 2008 10:12 am
- System_Drive: C
- 32bit or 64bit: 64 Bit
- motherboard: Asus Prime B350M-A
- processor: AMD Ryzen 5 1500 Quad-Core
- ram: 16 GB RAM
- Video Card: NVidia GeForce GTX 1050
- Hard_Drive_Capacity: 1TB
- Monitor/Display Make & Model: Samsung
- Corel programs: PaintShop Pro X9
- Location: UK
Re: Trojan in SP2 Update??
I scanned the saved download with Avast and it said "No Threat Found".

Joëlle
Joëlle
Joëlle
(PSPX9 )
(PSPX9 )
-
jojomart
- Posts: 51
- Joined: Sun Oct 17, 2010 5:09 pm
- System_Drive: C
- 32bit or 64bit: 64 Bit
- motherboard: FOXCONN ALOE 1.01
- processor: 2.60 gigahertz AMD Phenom II X4 910
- ram: 8GB
- Video Card: ATI Radeon HD 4350
- sound_card: Realtek High Definition Audio
- Hard_Drive_Capacity: 1TB
Re: Trojan in SP2 Update??
It wouldn't show in the download because it is something that happens as it's being installed, otherwise it wouldn't be in the temporary data file.
Joanne's Digital Designs
http://www.joannes-digital-designs.com
http://www.joannes-digital-designs.com
-
df
- Posts: 1224
- Joined: Mon Feb 08, 2010 11:21 pm
- System_Drive: C
- 32bit or 64bit: 64 Bit
- motherboard: GIGABYTE Z690 AERO G DDR4
- processor: 13th Gen Intel Core i7-13700K
- ram: 64gb
- Video Card: RTX 3060 Ti 8gb GDRR6
- Hard_Drive_Capacity: 1 Tb
- Location: Washington State
- Contact:
Re: Trojan in SP2 Update??
Why is there a [1]? That usually indicates that this is a second file of the same name within the same folder (Windows adds a [1] or (1) to differentiate which came second). Is there a file without that somewhere else? If so, why didn't Super-Antispyware hit on that? Is it the exact same size?
Regards, Dan
"Smoke me a kipper, I'll be back for breakfast."
"Smoke me a kipper, I'll be back for breakfast."
-
jojomart
- Posts: 51
- Joined: Sun Oct 17, 2010 5:09 pm
- System_Drive: C
- 32bit or 64bit: 64 Bit
- motherboard: FOXCONN ALOE 1.01
- processor: 2.60 gigahertz AMD Phenom II X4 910
- ram: 8GB
- Video Card: ATI Radeon HD 4350
- sound_card: Realtek High Definition Audio
- Hard_Drive_Capacity: 1TB
Re: Trojan in SP2 Update??
When the pop up started downloading the file from Corel, it got about 30% done and then it froze up. I clicked on the link to download it manually and it brought up IE instead of Firefox, so I cancelled the download and copied the link into Firefox to re-download it. After that, I just double clicked the .exe file on my hard drive to install it. That may be why there was the [1] there, but I can't imagine that that would be the reason for it to be named a Trojan.
Joanne's Digital Designs
http://www.joannes-digital-designs.com
http://www.joannes-digital-designs.com
-
df
- Posts: 1224
- Joined: Mon Feb 08, 2010 11:21 pm
- System_Drive: C
- 32bit or 64bit: 64 Bit
- motherboard: GIGABYTE Z690 AERO G DDR4
- processor: 13th Gen Intel Core i7-13700K
- ram: 64gb
- Video Card: RTX 3060 Ti 8gb GDRR6
- Hard_Drive_Capacity: 1 Tb
- Location: Washington State
- Contact:
Re: Trojan in SP2 Update??
If SAS didn't find any of the other downloads as trojans then I'd just chalk it up to a false positive result from SAS. It happens. If it happens more than rarely then you may look into it further.
edit: The reason ie was brought up the first time was because that's what is set as your default browser in Windows. You can have FireFox (or whatever) set as default if you don't wish to invoke ie in the future, but it's just a minor annoyance for most.
edit: The reason ie was brought up the first time was because that's what is set as your default browser in Windows. You can have FireFox (or whatever) set as default if you don't wish to invoke ie in the future, but it's just a minor annoyance for most.
Regards, Dan
"Smoke me a kipper, I'll be back for breakfast."
"Smoke me a kipper, I'll be back for breakfast."
-
jojomart
- Posts: 51
- Joined: Sun Oct 17, 2010 5:09 pm
- System_Drive: C
- 32bit or 64bit: 64 Bit
- motherboard: FOXCONN ALOE 1.01
- processor: 2.60 gigahertz AMD Phenom II X4 910
- ram: 8GB
- Video Card: ATI Radeon HD 4350
- sound_card: Realtek High Definition Audio
- Hard_Drive_Capacity: 1TB
Re: Trojan in SP2 Update??
No, IE isn't my default browswer, Firefox is and always has been.
Joanne's Digital Designs
http://www.joannes-digital-designs.com
http://www.joannes-digital-designs.com
-
Radim
- Posts: 712
- Joined: Mon Nov 01, 2010 5:54 pm
- System_Drive: C
- 32bit or 64bit: 64 Bit
- ram: 4GB
- Monitor/Display Make & Model: 27 inch
Re: Trojan in SP2 Update??
I often use service like VirusTotal.com for file(s) not digitaly signed.
There is also SUPERAntiSpyware (https://www.virustotal.com/file/bd00e95 ... 360228153/)
but my experience over years is that, that not only this *security* tool is too offensive sometimes and I get in 10-15 % of scanned files false possitive. You can also report to developers of sofware... Or you can wait while (1-2 week/s) for updated database...
There is also SUPERAntiSpyware (https://www.virustotal.com/file/bd00e95 ... 360228153/)
but my experience over years is that, that not only this *security* tool is too offensive sometimes and I get in 10-15 % of scanned files false possitive. You can also report to developers of sofware... Or you can wait while (1-2 week/s) for updated database...
Re: Trojan in SP2 Update??
Regarding browser caches, especially Internet Explorer's Temporary Internet Files, this is technically incorrect...df wrote:Why is there a [1]? That usually indicates that this is a second file of the same name within the same folder (Windows adds a [1] or (1) to differentiate which came second). Is there a file without that somewhere else? If so, why didn't Super-Antispyware hit on that? Is it the exact same size?
That being said, this is most likely a false positive.
-
sdcigarbear
- Posts: 1
- Joined: Sat Nov 17, 2012 2:37 am
- System_Drive: C
- 32bit or 64bit: 64 Bit
- Location: Washington USA
Re: Trojan in SP2 Update??
No virus detected with Panda Cloud Antivirus as of Wednesday night when I downloaded SP2.
