Lenovo One Key Recovery Trojan

All versions of Windows OS

Moderator: SilverZero

Lenovo One Key Recovery Trojan

Postby dmj97247 » Thu Jul 09, 2009 7:35 am

Zone Alarm (Anti-Virus setting "Ultra Deep Scan," Anti-Spyware setting "Deep Scan") found
Win32.Downloader.Small.afwj located in C:\Program Files\Lenovo\OneKey App\OneKey Recovery\MakeWinPEISO\Tools\PETools\x86\BootSect.exe

Screengrab can be seen here Image
dmj97247
New User
 
Posts: 4
Joined: Wed Jul 08, 2009 5:39 pm
Color and Model: white S10
OS(s) installed: WinXP

Advertisement

Re: Lenovo One Key Recovery Trojan

Postby warreng24 » Thu Jul 09, 2009 11:34 am

False alarm. BootSec.exe is part of the PE Tools package that generates a pre-boot environment to restore the disk image.

Reported on the HP's as well (which also utilizes the PE Tools package).
http://forums.zonealarm.org/zonelabs/bo ... e.id=33161

If it really concerns you, just low-level format the machine, repartition, and clean install Windows without installing the One Key Recovery package.
warreng24
Novice
 
Posts: 22
Joined: Wed Jul 01, 2009 5:55 am
Color and Model: S10 Black 4231-AGU and T42 2378-FVU
OS(s) installed: Windows XP Professional

Re: Lenovo One Key Recovery Trojan

Postby dmj97247 » Fri Jul 10, 2009 5:31 am

The original post was a statement of fact.



The respondent's hypothesis offers no basis of proof.
dmj97247
New User
 
Posts: 4
Joined: Wed Jul 08, 2009 5:39 pm
Color and Model: white S10
OS(s) installed: WinXP

Re: Lenovo One Key Recovery Trojan

Postby DCO » Sun Jul 12, 2009 12:40 am

dmj97247 wrote:The original post was a statement of fact.


Not necessarily.
It's not uncommon for anti-virus programs to give false positives.
DCO
Novice
 
Posts: 23
Joined: Wed Oct 22, 2008 4:04 pm

Re: Lenovo One Key Recovery Trojan

Postby dmj97247 » Sun Jul 12, 2009 10:40 am

DCO wrote:
dmj97247 wrote:The original post was a statement of fact.


Not necessarily.
It's not uncommon for anti-virus programs to give false positives.


DISAGREE, use a top notch program and it will become a rarity.


You, as the previous respondent, makes an assumption ("false positive") without providing any basis to back up your claim.

Have you any knowledge regarding the trojan and file, or do you just make statements to potentially mislead others?
dmj97247
New User
 
Posts: 4
Joined: Wed Jul 08, 2009 5:39 pm
Color and Model: white S10
OS(s) installed: WinXP

Re: Lenovo One Key Recovery Trojan

Postby fadiaz » Sun Jul 12, 2009 11:57 am

dmj97247 wrote:
DCO wrote:
dmj97247 wrote:The original post was a statement of fact.


Not necessarily.
It's not uncommon for anti-virus programs to give false positives.


DISAGREE, use a top notch program and it will become a rarity.


You, as the previous respondent, makes an assumption ("false positive") without providing any basis to back up your claim.

Have you any knowledge regarding the trojan and file, or do you just make statements to potentially mislead others?


hi,

I work in the IT environment and have seen lots of "false positives" even with high end commercial antivirus . There is no perfect software, much less in one as complex as an antivirus. I am not saying to be wreckless now, but many people here know about computers and the lenovo software enough to say it is most probably a false positive.

If you feel a little nervous you can verify the results with other antivirus software scanners to make sure. I would recomend online solutions, so that you do not need to uninstall your actual antivirus. I would recomend TrendMicro House (http://housecall.trendmicro.com/) or Kaspersky online (http://www.kaspersky.com/virusscanner).

You can also Google (or Yahoo or Bing; your preference) for Bootsect.exe; the file in question.

If you still feel paranoid or worried, you could do a fresh install of windows and as you were suggested before, not reinstall the one key recovery software.

One word of advice; do not treat bad the people that sincerely are trying to help you.

Take care and good luck,



Francisco
Black IdeaPad S10
2 GB RAM (crucial) / 160 GB HDD / Bluetooth (ebay)
9 Cell Battery (ebay)
fadiaz
Beginner
 
Posts: 6
Joined: Fri May 15, 2009 8:23 am
Location: San Juan, PR (USA)
Color and Model: Ideapad S10 Black
OS(s) installed: Windows XP Pro

Re: Lenovo One Key Recovery Trojan

Postby dmj97247 » Sun Jul 12, 2009 3:40 pm

....... or Kaspersky online (http://www.kaspersky.com/virusscanner).

Just so you know, Checkpoint, the pimp of Zone Alarm paid to incorporate Kaspersky into their Security Suite.

You can also Google (or Yahoo or Bing; your preference) for Bootsect.exe; the file in question.

Do you really think that was not the first thing that I did?
Did you do the same prior telling me what to do.
Quite frankly, their is little IF ANY definitive proof that this is a positive or false positiv
e.

If you still feel paranoid or worried, you could do a fresh install of windows and as you were suggested before, not reinstall the one key recovery software.

Re-read the original post. It was a statement. You and the other are reading way to much into something that is just not there.
As one can clearly see (pic), the file was quarantined.

The original post was an informative one, period.


One word of advice; do not treat bad the people that sincerely are trying to help you.

I am sorry you feel that way.


The original post was an informative one, period.

Take care and good luck,

Same to you.
dmj97247
New User
 
Posts: 4
Joined: Wed Jul 08, 2009 5:39 pm
Color and Model: white S10
OS(s) installed: WinXP


Return to Windows

Who is online

Users browsing this forum: No registered users and 1 guest