Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

"trojan.agent" In Hosts File


  • Please log in to reply
1 reply to this topic

#1 Tekn0cat

Tekn0cat

  • Members
  • 23 posts
  • OFFLINE
  •  
  • Local time:04:03 PM

Posted 15 July 2008 - 05:19 PM

Today I ran a Kaspersky scan on one of our laptops and it came up with two "bugs" which I think aren't really viruses since we have VNC installed on this machine. Excerpt from Kaspersky log:

Scan area - Folder:
C:\

Scan statistics:
Files scanned: 74639
Threat name: 2
Infected objects: 2
Suspicious objects: 0
Duration of the scan: 01:37:54


File name / Threat name / Threats count
C:\Program Files\RealVNC\VNC4\winvnc4.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4110 1
C:\Program Files\RealVNC\VNC4\wm_hooks.dll Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 1

The selected area was scanned.

Just to be on the safe side, I downloaded MBAM, updated it with the latest database, then ran a scan. Here's the log:
Malwarebytes' Anti-Malware 1.20
Database version: 957
Windows 5.1.2600 Service Pack 3

4:51:58 PM 7/15/2008
mbam-log-7-15-2008 (16-51-50).txt

Scan type: Quick Scan
Objects scanned: 136514
Time elapsed: 25 minute(s), 19 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\WINDOWS\hosts (Trojan.Agent) -> Quarantined and deleted successfully.

I then deleted the Trojan.Agent file, rebooted and ran MBAM again. Same thing was found again.

Is this something I should be worried about, or am I just being paranoid? :thumbsup:

BC AdBot (Login to Remove)

 


#2 DaChew

DaChew

    Visiting Alien


  • Members
  • 10,317 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:millenium falcon and rockytop
  • Local time:05:03 PM

Posted 16 July 2008 - 01:48 AM

http://www.malwarebytes.org/forums/index.p...art=#entry21366

See if this applies in your case?
Chewy

No. Try not. Do... or do not. There is no try.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users