View Full Version : Trojan Horse Generic3.JJG
marjud
03-10-2007, 12:01 AM
Installed the new version 2.0.0.9 and soon after received my first ever Smart Update (update.exe - 1.75MB) - which AVG promptly intercepted and quarantined claiming it was infected with Trojan Horse Generic3.JJG.
hdavid
03-10-2007, 12:42 AM
This is weird because version 2.0.0.9 does not have updates yet. The Smart Update (update.exe) that is installed with the firewall does not have any problems and if AVG clamed it to be a Trojan then it is their BUG
marjud
03-10-2007, 09:52 AM
I see, so Update.exe wasn't an update, it's the Smart Update function.
I've told AVG to put it back (which it did) but it still won't let it run.
I can't be the only person running both PC Tools Firewall and AVG 7.5?
Tanimoto
03-10-2007, 10:46 AM
Hello:
I have just had the same unpleasant experience with the same configuration . Used AVG free for many years until my new Dell arrived a few months ago, when the McAfee Suite with it eventually slowed things down, I went back to AVG for the AV ( having tried many others). I purchased Spyware Doctor sometime time ago, and have twice gone back to v4, because of critical problems with v5.
This was a shock as I get few Trojans or Worms and when they appear it is I must say by and large AVG which picks them up - though SD has done so on several occasions. I also at the same time found a couple of others - which may or may not be related - Trojan Horse Generic3.UZ in that case related to a program I purchased called Handy Recovery. THe exe in that case had been deleted and replaced with an updated version after a glitch a few days ago.
AVG in the same scan also found Worm/VB.AUG attached to a varietuy of FirefoxSetup.exe and Firefox.exe files - none of which are my current Firefox.exe .
So is this a fault of Firewall Plus? I do not know, but I do know I had to uninstall it and reinstall it from the Web site a day or so ago after I had downloaded the v2.0 version as recommended by Achen - following long term problems I had had with disappearing sytray icon. My concern as a committed PC tools fan, is that once an update.exe file - especially in a security firewall program starts showing up as Malware- the company can quickly lose credibility.
I sincerely hope Acen and others can sort this out AND THEN POST AN ANNOUNCEMENT THAT THEY HAVE DONE SO!!
Regards
Tanimoto
Catlady4ever
03-10-2007, 02:14 PM
It just happened to me too, just now. :eek: I hope this will be resolved soon.
clweb
03-10-2007, 03:22 PM
Yes, you must tell it AVG: it is a false positive. Send them the file.
I've done so a while ago with Avast detecting an old file as virus.
Tanimoto
03-11-2007, 05:25 PM
As already noted by me and others earlier, my AVG AV has identified the PCT Firewall Plus Update.exe, as infected with Trojan Horse Generic3.JJG. Following this I uninstalled the FW completely cleaned out the folders and registry, switched off System restore, rebooted and re downloaded the leatest version of the Firewall fro the PC Tools Web site. ( Itemporarily used the Windows Firewall whilst doing this.
The problem now is that on trying the update from the PCT FW screen ( forget for now that there are no updates), an error box appears saying the file is missing and cannot be found. ( see attached screenshot)
The action happens whether or not the file is healed or deleted by AVG I have tried both. In any case is this a FP or not. Remember this happens instantly the file is downloaded from the PCTools web site.
I would appreciate any comments and assistance from Technical people as well as input from any one at all.
Thanks Tanimoto
likuidkewl
03-11-2007, 06:30 PM
Letting AVG clean or delete the file is the wrong approach you should utilize the ignore function as this is most certainly a FP, I cannot explain how as I don't have AVG installed on any of my pcs nor do I plan on installing it anytime soon. Either ignore or create an exception in the scanner for it. See you help documentation.
Below is a screen capture form VirusTotal's online scanner:
http://xs413.xs.to/xs413/07100/iviewcapture_date_11_03_2007_time_14_20_41.jpg.xs. jpg (http://xs.to/xs.php?h=xs413&d=07100&f=iviewcapture_date_11_03_2007_time_14_20_41.jpg)
hdavid
03-11-2007, 09:22 PM
We will contact AVG. update.exe that is installed on the same directory of the firewall (usually c:\Program Files\PC Tools Firewall Plus) performs the Smart Update functionality of the firewall. It is activated automatically but you can disable checking for updates automatically in the settings
louise250
03-12-2007, 05:58 AM
I had to cancel the installation of PC Tools Firewall because NOD32 was sure it had found a trojan - I can't remember the exact name but it was a variant ...heur...
It's not only AVG that is finding this - it is NOD32 as well. Another poster made a similar post on a separate thread yesterday.
Louise250
AChen
03-12-2007, 06:19 AM
Hi Everyone,
Thanks for the info.
We will be contacting AVG and ESET to have these issues resolved.
ertyanna
03-12-2007, 03:00 PM
http://farm1.static.flickr.com/156/418906453_b525a5769d_m.jpg (http://farm1.static.flickr.com/156/418906453_c2b7114f7a_o.jpg)
Stupid Nod:mad:
Robin Springall
03-12-2007, 06:41 PM
ESET are probably not being stupid, but they might be trying to get their own back on PCTools because some weeks ago a SD update decided that NOD32 was a Trojan. The trouble with this kind of playground silliness is that it's we, the customers, who suffer until the big boys sort out their differences.
likuidkewl
03-12-2007, 07:06 PM
ESET are probably not being stupid, but they might be trying to get their own back on PCTools because some weeks ago a SD update decided that NOD32 was a Trojan. The trouble with this kind of playground silliness is that it's we, the customers, who suffer until the big boys sort out their differences.
I doubt that is the case, 'tis mearly a false positive
:)
katie
03-13-2007, 06:12 AM
ESET are probably not being stupid, but they might be trying to get their own back on PCTools because some weeks ago a SD update decided that NOD32 was a Trojan. The trouble with this kind of playground silliness is that it's we, the customers, who suffer until the big boys sort out their differences.
Totally agree with likuidkewl :)
Managed to locate the post about this from pc tools. Hopefully this will clear things up abit.
"I just want to clear up 2 points.
1. The detection of NOD32 was in no way deliberate. I can understand how it may have looked after NOD32 detected Spyware Doctor 2 days earlier but this was just coincidental bad timing.
PC Tools has nothing to gain by retaliating against other products.
In fact, false positives of this magnitude cause our support team a lot of extra work in replying to affected customers as well as the negative image associated with a product that produces false positives which is why we resolve these issues asap.
As soon as we were aware of the false positive, we escalated the issue and made an emergency rebuild of the database for immediate release (remember, we are in Australia and the problem was first reported at around midnight our time)
2. The reason why everything under eset was detected (including readme.txt etc) is because \program files\eset was the false positive: therefore everything under the eset folder was detected.
Please be assured that it was in no way a retaliation. We would be hurting ourselves more than anyone else if this was."
kt
shawnee3
03-13-2007, 03:32 PM
I had the same problem with NOD32 as others. I deleted the pctools file and downloaded again. I turned off NOD32 and ran the PC tools file. Had a problem with the installation with an error saying a file was missing (update.exe). I ignored the error and continued to install. After rebooting the PC the firewall started up but the Vista firewall started also. I tried to access the smartupdate(to see if the file was really missing) and got a message the file was missing. Not being sure what to do next I uninstalled PC tools firewall.
I am running Vista business from a clean install.
Any suggestions
adeythrash
03-15-2007, 12:36 AM
to get past nod32's false positive, i disabled file monitoring while i installed the firewall, then after rebooting, i made an exclusion rule for the updater. all seems fine so far :)
tinbin
03-15-2007, 06:47 PM
to get past nod32's false positive, i disabled file monitoring while i installed the firewall, then after rebooting, i made an exclusion rule for the updater. all seems fine so far :)
i did same, firewall and nod32 working just great
cheers for the info m8
shawnee3
03-15-2007, 06:52 PM
to get past nod32's false positive, i disabled file monitoring while i installed the firewall, then after rebooting, i made an exclusion rule for the updater. all seems fine so far :)
Did you do this in Windows Defender or Windows vista firewall?. Could you be more specific. Thanks
hdavid
03-15-2007, 07:49 PM
We are in the process of contacting them and solving the problem.