Jump to content



Recommended Posts

Downloaded utorrent BETA last week and had to get rid of it a day later as a trojan was flagged by CA-AV. Having an ACER i have had a problem with the odd false positive so has anyone else had a trojan problem with BETA. As far as i can remember it was off here as i downloaded it via the upgrade option in utorrent

Link to comment
Share on other sites

i also received the trojan alert after i updated to the 1.8 version

but i'm 99.9% certain that it's a "false positive" :

2/07/2008 2:27:34 Running process C:\USERS\MR.PONGO\APPDATA\LOCAL\TEMP\UTTA439.TMP.EXE: detected modification of riskware 'Trojan.generic'.

manually scanning the quarantined file gives these results:

2/07/2008 3:14:19 File: C:\USERS\MR.PONGO\APPDATA\LOCAL\TEMP\UTTA439.TMP.EXE packed file UPX

2/07/2008 3:14:19 File: C:\USERS\MR.PONGO\APPDATA\LOCAL\TEMP\UTTA439.TMP.EXE//UPX ok scanned

2/07/2008 3:14:22 File: C:\USERS\MR.PONGO\APPDATA\LOCAL\TEMP\UTTA439.TMP.EXE ok scanned

ps: i'm using Kaspersky anti-virus

Link to comment
Share on other sites

I downloaded it from the upgrade option in utorrent itself the first time and here the second time. The flagged Trojan has descriptions also from Kaspersky etc so it is definately not a false positive although it does flag a false positive in ACERS of C/PROGRAMMEFILES/SYSTEM32/FLAGACER.EXE and that related to the adobie 8 installation file and was only named and described by CA. The one flagged in uTorrent BETA though has descriptions as i've said, from Kaspersky etc so i would say it's genuinne

Spyware Detail


Date Published:

Monday, July 2, 2007

Threat Assessment

Overall Risk:



System Integrity: Characteristics

Category : Trojan

Also known as: Win32.ExplorerHijack [CounterSpy], Trojan-Downloader.NSIS.Agent.ac [Kaspersky], Trj/Downloader.OZE [Panda], DLoader.CLIF [NORMAN]

That's the full description of the Trojan in uTorrent BETA.

Link to comment
Share on other sites


This topic is now archived and is closed to further replies.

  • Create New...