Jump to content

Trojan.agent


Guest dor123

Recommended Posts

Guest dor123

Recently Anti-Malware reported several important windows files in my computer as a trojan.agent and erased then and my windows became unstabled.

From what i read from the internet This threat is really non exist in the world and only detected by rouge security programs. Malwarebytes be asked to remove this threat from its definitions!

Link to post
Share on other sites

  • Root Admin

Well unfortunately we need an actual /developer log file to verify and remove it from the list. Name alone is not enough.

If someone else posts it or runs into it we can have them post a /developer log and we can then check and verify and remove it if it is in fact a FP.

Thank you though for your input on this, much appreciated.

Link to post
Share on other sites

Guest dor123

Here is a log i got after the scan. All the inftected files are important to windows.

Malwarebytes' Anti-Malware 1.36

Database version: 2176

Windows 5.1.2600 Service Pack 3

25/05/2009 17:27:59

mbam-log-2009-05-25 (17-27-59).txt

Scan type: Quick Scan

Objects scanned: 84652

Time elapsed: 3 minute(s), 37 second(s)

Memory Processes Infected: 0

Memory Modules Infected: 0

Registry Keys Infected: 0

Registry Values Infected: 0

Registry Data Items Infected: 0

Folders Infected: 0

Files Infected: 8

Memory Processes Infected:

(No malicious items detected)

Memory Modules Infected:

(No malicious items detected)

Registry Keys Infected:

(No malicious items detected)

Registry Values Infected:

(No malicious items detected)

Registry Data Items Infected:

(No malicious items detected)

Folders Infected:

(No malicious items detected)

Files Infected:

C:\WINDOWS\system\ieudinit.exe (Trojan.Agent) -> Quarantined and deleted successfully.

C:\Documents and Settings\Doron\Application Data\Microsoft\mstinit.exe (Trojan.Agent) -> Quarantined and deleted successfully.

C:\WINDOWS\system32\drivers\rsvp.exe (Trojan.Agent) -> Quarantined and deleted successfully.

C:\WINDOWS\system32\drivers\cisvc.exe (Trojan.Agent) -> Quarantined and deleted successfully.

C:\Documents and Settings\Doron\Local Settings\Application Data\Microsoft\sessmgr.exe (Trojan.Agent) -> Quarantined and deleted successfully.

C:\WINDOWS\system\cisvc.exe (Trojan.Agent) -> Quarantined and deleted successfully.

C:\Documents and Settings\Doron\Application Data\Microsoft\comrepl.exe (Trojan.Agent) -> Quarantined and deleted successfully.

C:\Documents and Settings\Doron\Local Settings\Application Data\spoolsv.exe (Heuristics.Reserved.Word.Exploit) -> Quarantined and deleted successfully.

Link to post
Share on other sites

I had Trojan.Agent come up on some scans too, and I deleted it and there was no problem with the computer after I deleted them.

I wonder if something off happened with your system?

Are the problems still occurring?

Here is a log i got after the scan. All the inftected files are important to windows.

Malwarebytes' Anti-Malware 1.36

Database version: 2176

Windows 5.1.2600 Service Pack 3

25/05/2009 17:27:59

mbam-log-2009-05-25 (17-27-59).txt

Scan type: Quick Scan

Objects scanned: 84652

Time elapsed: 3 minute(s), 37 second(s)

Memory Processes Infected: 0

Memory Modules Infected: 0

Registry Keys Infected: 0

Registry Values Infected: 0

Registry Data Items Infected: 0

Folders Infected: 0

Files Infected: 8

Memory Processes Infected:

(No malicious items detected)

Memory Modules Infected:

(No malicious items detected)

Registry Keys Infected:

(No malicious items detected)

Registry Values Infected:

(No malicious items detected)

Registry Data Items Infected:

(No malicious items detected)

Folders Infected:

(No malicious items detected)

Files Infected:

C:\WINDOWS\system\ieudinit.exe (Trojan.Agent) -> Quarantined and deleted successfully.

C:\Documents and Settings\Doron\Application Data\Microsoft\mstinit.exe (Trojan.Agent) -> Quarantined and deleted successfully.

C:\WINDOWS\system32\drivers\rsvp.exe (Trojan.Agent) -> Quarantined and deleted successfully.

C:\WINDOWS\system32\drivers\cisvc.exe (Trojan.Agent) -> Quarantined and deleted successfully.

C:\Documents and Settings\Doron\Local Settings\Application Data\Microsoft\sessmgr.exe (Trojan.Agent) -> Quarantined and deleted successfully.

C:\WINDOWS\system\cisvc.exe (Trojan.Agent) -> Quarantined and deleted successfully.

C:\Documents and Settings\Doron\Application Data\Microsoft\comrepl.exe (Trojan.Agent) -> Quarantined and deleted successfully.

C:\Documents and Settings\Doron\Local Settings\Application Data\spoolsv.exe (Heuristics.Reserved.Word.Exploit) -> Quarantined and deleted successfully.

Link to post
Share on other sites

Hi,

As far as I can see thats no "fake threat".....why would spoolsv.exe be in your application data folder?

cisvc.exe should be in system32 folder too....

rsvp.exe is not a windows that I know of...

ieudinit.exe should be in system32 folder again (if at all)

and the rest of those .exes raise suspicion in app data folder.

All is well as far as I can see.

Link to post
Share on other sites

  • Root Admin

Those are Trojans if they're in that path location. Executable files do not belong there.

Post will be closed, they're not false positives and we will not remove them from detection. If you want them to not be detected on your system then you can place them on the ignore list.

Thank you.

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.