Author Topic: Updates from HP  (Read 2819 times)

0 Members and 1 Guest are viewing this topic.

imrmoose

  • Guest
Updates from HP
« on: January 03, 2010, 07:53:00 PM »
New her. Thanks in advance for any help anyone can give me. First experience with a virus, took it in and this is what they found an did.
Program Files\BackWeb\BackWeb Client\6.2.3.66\Program\runner.exe   probably a variant of Win32/Agent trojan   cleaned by deleting - quarantined
and
Program Files\Updates from HP\137903\Program\BackWeb-137903.exe   probably a variant of Win32/Agent trojan   cleaned by deleting - quarantined
After a few boots the HP thing is back. Avast does not find them. Any idea what to do.
Thanks, Moose

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89145
  • No support PMs thanks
Re: Updates from HP
« Reply #1 on: January 03, 2010, 08:15:03 PM »
What originally detected these ?

As I'm not sure it was avast given your comment, "cleaned by deleting - quarantined," as avast doesn't clean by deletion, send to Chest, is its quarantine. Many of these Agent detections are generic, this makes them more prone to mis-detection.

The avast virus database for win32.agent is a huge 22891 signatures in all and some of those are I believe generic detections able to detect multiple variants of the same family.
« Last Edit: January 03, 2010, 08:17:17 PM by DavidR »
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

imrmoose

  • Guest
Re: Updates from HP
« Reply #2 on: January 03, 2010, 08:18:46 PM »
Not sure what they used to detect them but it was an 8 hour scan. I have run avast a few times and before and after and they no show up.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89145
  • No support PMs thanks
Re: Updates from HP
« Reply #3 on: January 03, 2010, 08:26:50 PM »
Given the locations of the detections relating to HP and BackWeb Client I don't know if this is anything to do with their support function (I won't use HP ever again), so there is every possibility that this was a generic detection based on what it might do, rather than a specific virus signature.

If this original detection was avast (which has to be confirmed) and it subsequently is no longer detected, then it could be it was a false positive detection, which has now been corrected. For this reason I hope you now get the idea that deletion is never a good option, you have none left, so send to chest and investigate.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security