Support in other languages: 
Reply
Guru
rbell
Posts: 19
Registered: ‎11-25-2007
Location: Rogers, MN
0

Trojan threat detected when installing Rescue & Recovery

I am performing a fresh install of Win7 on a T61p.  I downloaded the 'Thinkpad Rescue and Recovery' installer (tvtvrnr43_1027fi.exe) from Lenovo's download site and ran it to began installing it.  After some unpacking and working through the setup wizard a bit AVG detected the following as a threat:

File:   C:\preboot\utils\rnrdbgtool.exe
Threat: Trojan horse Agent_r.BKV

Since I know this package came direct from Lenovo and since R&R is likely doing things that LOOK like a trojan, I have to believe AVG is throwing a false positive here.  But before I proceed I wanted to ask anyone else if they have encountered this before? Is it possible that the R&R installer is actually infected with a virus??

Thanks,
Rob

Bit Torrent
TuuS
Posts: 1,507
Registered: ‎01-02-2011
Location: US

Re: Trojan threat detected when installing Rescue & Recovery


rbell wrote: Is it possible that the R&R installer is actually infected with a virus??


Thanks,
Rob



The answer to this is No...   not even your AVG suspects that. A trojan is much different then a Virus. An example of a trojan would be a computer program that claims to do one thing, but really does something different. A virus is a generic definition of a type of malware that infects and reproduces and spreads.

 

Any program that can make major changes to a computer could easily be detected as a false positive by anti-virus software, and AVG is one of the worse when it comes to false detections.

 

My advice is to look it up on AVG's database and see what it is they claim to have found. Odds are it's a generic classification or a heuristic definition, meaning their software is basically making a wild guess that it might not be what it claims to be. 

 

If you're overly concerned about this you can update your AVG definitions each day until it's removed from the database. I'd also report it to AVG, they can't rule it out until someone reports it. Odds are it's been reported already, but it's best to check and do your part and improving a freeware product.

 

I doubt lenovo can do anything about it anyway. If the file was infected with a virus, that may be a different story, but most servers will detect a change in the file and anything infected will be removed very quickly. With a trojan definiton, it would be like trying to prove a negative. For example, if you say you're a doctor, but I say you're a plumber, you can easily prove you are a doctor, but you can't so easily prove you're NOT a plumber, and in this case AVG probably isn't even saying what type of program it thinks this really is, so that makes it infintiely harder to prove...      so the ball is in AVG's court, then need to fix it, or provide something specific for lenovo to contest or fix.

 

 

ThinkPad W-510 i7-820QM(1.73-3.06GHz) Quad Core... ThinkPad T500, T9900, 8gb SSD...FrankNpad T-60p/61p (X9000 2.8ghz) 8gb SSD ips FlexView...ThinkPad T-61p (T9300 2.5ghz) 8gb ram...Thinkpad X-61 Tablet 4gb ram...ThinkPad A-31 (1.9ghz P4 1.5gb ram)
Guru
rbell
Posts: 19
Registered: ‎11-25-2007
Location: Rogers, MN
0

Re: Trojan threat detected when installing Rescue & Recovery

That was my thought as well.  I just wanted some additional confirmation on it.  I can't believe nobody else has seen this before. 

 

Thanks,
Rob