Jump to content

Recurring Trojan.Agent (Regedit32)


Recommended Posts

After quarantining and deleting the following items (MAM Premium, database v2014.08.27.02 under Win7 x64):

* Backdoor.Agent (C:\Users\[user]\AppData\Roaming\rundll32.exe)
* Trojan.Agent (C:\Users\[user]\AppData\Roaming\svchost.exe)
* Trojan.AGent.VXGen (C:\Users\[user]\AppData\Local\Temp\C91D.tmp.exe)

After reboot (and quarantine/delete), MAM keeps detecting:

Trojan.Agent (Registry Value) HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|Regedit32

Does anyone know how to eliminate this residual trojan item ?   TIA.

 

Dave.

Link to post
Share on other sites

Hello and welcome:

 

We can't work on malware diagnostics and removal in this sub-section of the forum.

So, for expert assistance, I suggest that you please follow the advice in this pinned topic: Available Assistance For Possibly Infected Computers.
A malware analyst will guide you through the cleanup process.

 

>>Until then, your post suggests that this might be a very serious type of infection that could compromise your personal and financial information.  As such, until you receive expert help, please do not conduct any sort of financial transaction from the affected computer.

You will likely need to change all your passwords from a known, clean computer; contact your financial institutions; and take other, critical counter-measures.

>>The forum staff, experts and malware helpers will have additional important advice for you.

Thanks,

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.