Register - Login
Views: 99860055
Main - Memberlist - Active users - Calendar - Wiki - IRC Chat - Online users
Ranks - Rules/FAQ - Stats - Latest Posts - Color Chart - Smilies
05-04-22 12:49:29 PM
Jul - Computers and Technology - Need some info on a trojan... New poll - New thread - New reply
Next newer thread | Next older thread
Hiryuu

Level: 207


Posts: 1964/14435
EXP: 127636661
For next: 2147493

Since: 07-06-07


Since last post: 11.8 years
Last activity: 11.7 years

Posted on 01-03-08 01:47:07 PM Link | Quote
Caught by AVG, "agent.iy".

I haven't found anything past the fact that it's a high-risk, high-damage Trojan. Nothing on removal details, etc. Already sounds like it's grabbed realscheduler.exe and shell32.dll on the infected comp (my dad's...that's what you get for using IE without updates...).

____________________
Surlent
220
Life over. Continue(s) left: 00
Level: 34


Posts: 43/222
EXP: 242814
For next: 10837

Since: 08-02-07

From: Berlin

Since last post: 8.8 years
Last activity: 8.4 years

Posted on 01-03-08 02:03:39 PM Link | Quote
There is not much information about it, but at least better than nothing:
http://www.sophos.com/security/analyses/trojproxyax.html


I strongly advise to format the hard drive, along from your (clean) computer download SP2 and burn it onto a CD. You might be able to remove the antivirus on the infected comp by using an up-to-date antivirus, along with Hijack This, but there is a very high chance that particular trojans (hello agobot and phatbot) screwed the entire operating system, changed programs and so on to use other backdoors .... I doubt a virus scanner or any program can kill such a complex trojan.
Backup anything important, if possible put it into a neutral environment, such as an old computer disconnected from the internet, scan/try to desinfect that stuff.

Since you reinstall SP2 offline, there is much less risk in getting something while normally downloading the SP2 and all following updates via Windows Upate (which requires Internet Explorer ).
Hiryuu

Level: 207


Posts: 1965/14435
EXP: 127636661
For next: 2147493

Since: 07-06-07


Since last post: 11.8 years
Last activity: 11.7 years

Posted on 01-03-08 03:19:54 PM Link | Quote
That's about what I was thinking...it apparently took down my father's ex-company that he worked for about six months ago for two weeks. Sounds like a pain in the ass.

____________________
Next newer thread | Next older thread
Jul - Computers and Technology - Need some info on a trojan... New poll - New thread - New reply


Rusted Logic

Acmlmboard - commit 47be4dc [2021-08-23]
©2000-2022 Acmlm, Xkeeper, Kaito Sinclaire, et al.

27 database queries.
Query execution time: 0.084680 seconds
Script execution time: 0.008638 seconds
Total render time: 0.093318 seconds