Notices

X50 / X51 Forums Talk about anything related to the X50 / X51 series.

Reply
 
LinkBack Thread Tools
Old 08-01-09, 12:25 PM   #1 (permalink)
Aximsite Rookie
 
Join Date: Nov 2004
Location: Neptune Beach, FL
Posts: 37
Device: On my 3rd LG VX8100
Carrier: Verizon
Thanked 0 Times in 0 Posts
Continually Reoccuring Trojan:Win32/Agent Warning Appears only During ActivSync

I have not been using my Axim X51v that often, lately, but I have started using it again. In the interim, I put Windows Live OneCare on my home Laptop. (A great all-around utility program, I can't say enough positive things about it.) However, every time I now Sync my Axim to the laptop, I get the same OneCare warning message, "Windows Live OneCare has found potentially unwanted software . We recommend you remove such software that you do not recognize."

Software ------------------ Catagory
Trojan:Win32/Agent ----- Trojan

I click "Clear" on Live OneCare and Windows Live OneCare removes it for the time being. However, the same message returns persistently. Clearly, whatever this is, is on my Axim and is trying to unload itself onto my computer every time I sync.

Any idea what this is and more important, how the heck would find locate it and get rid of it once and for all? (it is persitent, it just reappeared for a second time while I was typing this message.) I am far from a pro, so I would appreciate it if anybody who knows what to do would walk me through this with the specific steps necessary to remove it. My sincere thanks for your assistance.

Last edited by Stu-be; 08-01-09 at 12:45 PM.
Stu-be is offline   Reply With Quote
Sponsor Ads
Old 08-01-09, 12:47 PM   #2 (permalink)
Aximsite Veteran
 
johnhu_2005's Avatar
 
Join Date: May 2008
Location: Pennsylvania, US
Posts: 2,377
Device: Samsung Glyde =(
Carrier: Verizon Wireless
Thanked 78 Times in 75 Posts

Awards Showcase
Aximsite Active Bronze Member Aximsite Bronze Contributors Aximsite Contest Winner Top Notch MyPDA 
Total Awards: 4

Where is the location of the malware?
__________________
Currently running LennySh L11 ROM on my x51v.
Currently running LennySh A09 ROM on my x50v.
~~~~~~~~~~~~~~
To support me,
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
!

To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
johnhu_2005 is offline   Reply With Quote
Old 08-01-09, 01:11 PM   #3 (permalink)
Aximsite Rookie
 
Join Date: Nov 2004
Location: Neptune Beach, FL
Posts: 37
Device: On my 3rd LG VX8100
Carrier: Verizon
Thanked 0 Times in 0 Posts
What steps would I take to determine that?
Stu-be is offline   Reply With Quote
Old 08-01-09, 01:29 PM   #4 (permalink)
Aximsite Veteran
 
johnhu_2005's Avatar
 
Join Date: May 2008
Location: Pennsylvania, US
Posts: 2,377
Device: Samsung Glyde =(
Carrier: Verizon Wireless
Thanked 78 Times in 75 Posts

Awards Showcase
Aximsite Active Bronze Member Aximsite Bronze Contributors Aximsite Contest Winner Top Notch MyPDA 
Total Awards: 4

Stumped me, never used Onecare before. I only trust Avira and NOD32...

Here is a picture on an Onecare detection. You should the location by "File Location".

Trojan:Win32/Agent could possibly be a false positive. Since Onecare pops up every time something synced, could there be malware on the Axim? But then again, there aren't many Pocket PC malware in the wild...

So location is what we need to determine if it is a false positive or not.
__________________
Currently running LennySh L11 ROM on my x51v.
Currently running LennySh A09 ROM on my x50v.
~~~~~~~~~~~~~~
To support me,
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
!

To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
johnhu_2005 is offline   Reply With Quote
Old 08-01-09, 03:34 PM   #5 (permalink)
Aximsite Hall of Fame
 
Jogga's Avatar
 
Join Date: Feb 2006
Location: United Kingdom of Great Britain & Northern Ireland
Posts: 6,247
Device: htc Touch 3G
Carrier: Orange
Thanked 2 Times in 1 Post

Awards Showcase
Aximsite Bronze Contributors Aximsite Active Silver Member Top Notch MyPDA Aximsite Silver Contributors Aximsite Contest Winner Bronze Poster 
Total Awards: 6

Microsoft OncCare lists this agent as a backdoor trojan.

Make sure that you are up to date with MS patches and spyware removal applications.

To check if OneCare has quarantined click Change Settings (Quick Links) on your OneCare control panel (if you get a warning, click OK) and then the Viruses and Spyware tab. Click on the Quarantine option and that will give you details of where the spyware is located.
Jogga is offline   Reply With Quote
Old 08-02-09, 02:09 PM   #6 (permalink)
Aximsite Rookie
 
Join Date: Nov 2004
Location: Neptune Beach, FL
Posts: 37
Device: On my 3rd LG VX8100
Carrier: Verizon
Thanked 0 Times in 0 Posts
No Quarantined Item

When I follow this proceedure through to the quarantine button, there are no items quarantined. (Remember, this is REMOVED every time I run the proceedure.) Should I try to manually add this to the quarentine list?
I appear to be up to date on all MS patches.
Stu-be is offline   Reply With Quote
Old 08-02-09, 03:33 PM   #7 (permalink)
Aximsite Veteran
 
johnhu_2005's Avatar
 
Join Date: May 2008
Location: Pennsylvania, US
Posts: 2,377
Device: Samsung Glyde =(
Carrier: Verizon Wireless
Thanked 78 Times in 75 Posts

Awards Showcase
Aximsite Active Bronze Member Aximsite Bronze Contributors Aximsite Contest Winner Top Notch MyPDA 
Total Awards: 4

Does it automatically remove it? If so, try to get a manual prompt. Then find the location of the file(s)
__________________
Currently running LennySh L11 ROM on my x51v.
Currently running LennySh A09 ROM on my x50v.
~~~~~~~~~~~~~~
To support me,
To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
!

To view links or images in signatures your post count must be 10 or greater. You currently have 0 posts.
johnhu_2005 is offline   Reply With Quote
Old 08-03-09, 01:18 PM   #8 (permalink)
Aximsite Hall of Fame
 
Jogga's Avatar
 
Join Date: Feb 2006
Location: United Kingdom of Great Britain & Northern Ireland
Posts: 6,247
Device: htc Touch 3G
Carrier: Orange
Thanked 2 Times in 1 Post

Awards Showcase
Aximsite Bronze Contributors Aximsite Active Silver Member Top Notch MyPDA Aximsite Silver Contributors Aximsite Contest Winner Bronze Poster 
Total Awards: 6

Originally Posted by Stu-be View Post
When I follow this proceedure through to the quarantine button, there are no items quarantined. (Remember, this is REMOVED every time I run the proceedure.) Should I try to manually add this to the quarentine list?
I appear to be up to date on all MS patches.
Yes, my vote would be to quarantine this file (if it OneCare gives you the option). If you can't quarantine the file, you'll need to remove the file by running OneCare in Safe mode.

Relavant OneCare Forum Thread

Instructions for running OneCare in safe mode.

You could also try removing the infection with Spybot S&D :approve:
Jogga is offline   Reply With Quote
The Following User Says Thank You to Jogga For This Useful Post:
Box (10-06-09)
Old 08-04-09, 01:32 PM   #9 (permalink)
Aximsite Rookie
 
Join Date: Nov 2004
Location: Neptune Beach, FL
Posts: 37
Device: On my 3rd LG VX8100
Carrier: Verizon
Thanked 0 Times in 0 Posts
You nailed it!

Thanks Jogga,
Your recommendation was exactly correct. I appreciate the link to the "Relavant OneCare Forum Thread." This was precisely the issue. I got with Window's OneCare as recommended at this site, and they were most helpful in assisting in the Trojan's removal. Once again both laptop and Axim are functioning without the problem.
Stu-be is offline   Reply With Quote
Old 08-04-09, 04:06 PM   #10 (permalink)
Aximsite Hall of Fame
 
Jogga's Avatar
 
Join Date: Feb 2006
Location: United Kingdom of Great Britain & Northern Ireland
Posts: 6,247
Device: htc Touch 3G
Carrier: Orange
Thanked 2 Times in 1 Post

Awards Showcase
Aximsite Bronze Contributors Aximsite Active Silver Member Top Notch MyPDA Aximsite Silver Contributors Aximsite Contest Winner Bronze Poster 
Total Awards: 6

Groovy! :approve: I'm glad that I could be of assistance.
Jogga is offline   Reply With Quote
Reply

Tags
activsync, appears, continually, reoccuring, trojanwin32 or agent, warning

Sponsor Ads

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -5. The time now is 04:46 PM.
Powered by vBulletin® Version 3.8.2
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.3.0
Copyright © 2003-09 LeckMedia, LLC