Author Topic: Win32:Agent-VM[Trj] how to get rid of it?  (Read 3735 times)

0 Members and 1 Guest are viewing this topic.

Gofra

  • Guest
Win32:Agent-VM[Trj] how to get rid of it?
« on: July 27, 2006, 03:51:31 PM »
Hi folks, my first time here...

Just recently my friend asked me to help him with his PC which was behaving weird. As suspected, I found viruses, Trojans and malware. I used Avast, Ad-Aware, SpyBot SD and got rid of most. However, Win32:Agent-VM seems impossible to get rid off. Avast AV always finds it in the same place:

c:\windows:\temp
Name of the file is data.exe

I turned off system restore, ran a safe mode scan, boot scan, updated definitions, tried with other software but no go, its still here. Can you guys help me please?

I'm using a 4.7 home edition version with 0630-2 VPS file


Thank you very much!


Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67194
Re: Win32:Agent-VM[Trj] how to get rid of it?
« Reply #1 on: July 27, 2006, 05:54:06 PM »
Did you try scheduling the Boot Time Scan?

Click on the Menu button.
Choose Schedule Boot Time Scan.
Doing so displays a dialog allowing you to schedule virus scanning.
Check Archives, if you want scan all the archives.
Specify whether all the disks or just a specific folder should be scanned.
Select Advanced options for scheduling details.
Select how to automatically process infected files.
Choose how to automatically process infected system files.
Click the Schedule button to confirm the settings.
The best things in life are free.

Spiritsongs

  • Guest
Re: Win32:Agent-VM[Trj] how to get rid of it?
« Reply #2 on: July 27, 2006, 07:23:51 PM »
 :)  Hi Gofra:

      Your friend should add an antiTROJAN program ; if the
      Operating System is Win 2000 or Win XP, use the good
      & FREE "Ewido" from www.ewido.net/en . Any other OS
      should add A-Squared FREE at :
      www.emsisoft.com/en/software/free/ .

Gofra

  • Guest
Re: Win32:Agent-VM[Trj] how to get rid of it?
« Reply #3 on: July 28, 2006, 07:59:33 AM »
I turned off system restore, ran a safe mode scan, boot scan...

I did schedule a boot time scan - no changes tho.

Thanx for that software link, I'll try it later on!

Thank you both for helping!

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33897
  • malware fighter
Re: Win32:Agent-VM[Trj] how to get rid of it?
« Reply #4 on: July 28, 2006, 08:28:50 AM »
Hi Gofra,

Consider also these technical information on this trojan:
http://www3.ca.com/securityadvisor/virusinfo/virus.aspx?id=40053

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Gofra

  • Guest
Re: Win32:Agent-VM[Trj] how to get rid of it?
« Reply #5 on: July 28, 2006, 06:28:19 PM »
I think I did it - no signs of infections so far. Solution = EWIDO

Thanks again, I really appreaciate it - thanks for your help aswell Polonus!