Computer Help and Spyware Removal Computer Help and Spyware Removal Computer Help and Spyware Removal Computer Help Forums Windows Startup Programs Database Spyware and Malware Removal Guides Computer Tutorials Uninstall Database File Database Computer Glossary Computer Resources
 

Welcome Guest ( Log In | Click here to Register a free account now! )



Register a free account to unlock additional features at BleepingComputer.com
Welcome to Bleeping Computer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.
Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.


Important Announcement: In recognition of reaching a milestone of 1,000,000 posts on the site, we are hosting the BC 1 Million Post contest. More information about this contest can be found at the following link:

Bleeping Computer 1,000,000 Post Contest

- BleepingComputer Management
 
Reply to this topicStart new topic
> Trojandownloader.agent.acv Trojan Help
kris007
post Feb 28 2006, 10:13 AM
Post #1


New Member
*

Group: Members
Posts: 1
Joined: 28-February 06
Member No.: 57,228



Guys this is my first post. I have Windows Xp professional without any service packs installed. This problem started around 2 weeks back. At that time I had Norton 2005 with the latest updates and PC-CILLIN also with the latest updates. The first sign was when Norton reported some files missing and asked to reinstall. I reinstalled the application. After 2 days my computer went haywire. When I started out the computer both PC-CILLIN and NORTON detected a virus in my temp directory. There were a large number of files being created in the TEMP directory. I had set up both of the antiviruses to delete the files. Files started from something 0000 to E345 . It used to stop after a while. I uninstalled Norton because it was not allowing access and PC-CILLIN detected the virus inside Norton quarantine. The messages stopped coming. I then installed ANTIVIR which did not detect anything. Now the main trouble started coming.
When I started my comp, some programs like firefox and azereus did not used to respond. They did not open up but when I opened task manager it showed that they were running. Also after a while the explorer just used to shut off and I had to restart the application. PC-CILLIN also went haywire as it kept on giving pop-ups. I tried to set that option off in the emergency centre but it denied me access.
So I heard on some forums that NOD32 was very good and so tried that and uninstalled ANTIVIR. It detected the following applications I have submitted the log list as shown below. I also uninstalled PC-CILLIN after really getting annoyed with the pop-ups. So now my computer runs half of the time. The first thing I check on starting my comp is whether firefox runs. If it does'nt I restart the system until I can do that. Nowadays it starts only once in 3 times I start off.
So guys can anyone please explain what is going on? And how to get my system back to normal without having to reformat the entire system. Also please suggest the settings for NOD32 and some really good antivirus.






Time Module Object Name Threat Action User Information
2/28/2006 16:19:22 PM AMON file C:\WINDOWS\win32ssr.exe IRC/SdBot trojan NT AUTHORITY\SYSTEM Event occurred at an attempt to access the file by the application: C:\WINDOWS\system32\services.exe.
2/28/2006 15:42:24 PM AMON file C:\WINDOWS\win32ssr.exe IRC/SdBot trojan NT AUTHORITY\SYSTEM Event occurred at an attempt to access the file by the application: C:\WINDOWS\system32\services.exe.
2/25/2006 2:16:52 AM AMON file C:\WINDOWS\system32\wbem\wmiprvi.dll Win32/TrojanDownloader.Agent.ACV trojan deleted (after the next restart) NT AUTHORITY\SYSTEM Event occurred when attempting to access the file.
2/25/2006 2:15:49 AM AMON file C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\U5GVCRED\tds[1].exe Win32/TrojanDownloader.Agent.ACV trojan deleted NT AUTHORITY\SYSTEM Event occurred when attempting to access the file.
2/25/2006 2:15:19 AM AMON file C:\WINDOWS\system32\perfont.exe Win32/TrojanDownloader.Agent.ACV trojan deleted (after the next restart) NT AUTHORITY\SYSTEM Event occurred when attempting to access the file.
2/25/2006 2:14:07 AM AMON file C:\windows\system32\perfont.exe Win32/TrojanDownloader.Agent.ACV trojan deleted (after the next restart) NT AUTHORITY\SYSTEM Event occurred when attempting to access the file.
2/25/2006 2:13:45 AM Kernel file c:\windows\system32\perfont.exe Win32/TrojanDownloader.Agent.ACV trojan Alert was generated during the system startup file check.
Go to the top of the page
 
+Quote Post
quietman7
post Feb 28 2006, 12:15 PM
Post #2


Bleepin' Janitor
******

Group: Global Moderator
Posts: 13,417
Joined: 9-July 05
From: Virginia, USA
Member No.: 26,513



Its hard to tell from your post but have you been running two anti-virus programs at the same time.

The concern with using more than one anti-virus program is due to conflicts that can arise from them both running together in real-time protection mode. Each program will often interpret the activity of the other as a virus and there is a greater chance of them alerting you to "False Positives". Further anti-virus software componets insert themselves into the operating systems core and using more than one can cause instability, crash your computer, slow performance and waste system resources.

While operating in real-time mode, if one AV program finds a virus and then the other AV program also finds the same virus, then both programs will be competing over exclusive rights on dealing with that virus. Each piece of AV software will attempt to seize the offending file and quarantine it. Further, if one AV finds and quarantines the file before the other one does, then you encounter the problem of both AV's wanting to scan each other's zipped or archived files. This can lead to a repetivite cycle of endless alerts that continually warn you that a virus has been found.

With that said, I suggest you only using one anti-virus and then download and scan with Ewido Anti-Malware v3.5
Ewido Install and Scan Instructions


--------------------
"THE BAD GUYS DON'T NEED A SEARCH WARRANT. ARE YOU PROTECTED?"

Microsoft MVP - Windows Security 2007-2008
Go to the top of the page
 
+Quote Post

Reply to this topicStart new topic
1 User(s) are reading this topic (1 Guests and 0 Anonymous Users)
0 Members:

 



Lo-Fi Version Time is now: 20th November 2008 - 07:34 AM


Advertise   |   About Us   |   Terms of Use   |   Privacy Policy   |   Contact Us   |   Site Map   |   Chat   |   Tutorials   |   Uninstall List
Discussion Forums   |   The Computer Glossary   |   Resources   |   RSS Feeds   |   Startups   |   The File Database   |   Malware Removal Guides

© 2003-2008 All Rights Reserved Bleeping Computer LLC.