Trojan Horse Downloader.Agent.ETP

Trojan Horse Downloader.Agent.ETP

Secure Home | Search | About
 Microsoft Antivirus Discussions    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Trojan Horse Downloader.Agent.ETP bartlb@gmail.com 08-09-2006
Posted by bartlb@gmail.com on August 9, 2006, 11:16 am
If you were  Registered and logged in, you could reply and use other advanced thread options
I rec'd a popup from AVG indicating that my computer was infected. It
is now in the vault but I am receiving messages when I try to run
anything or just sitting there that there are files missing such as
point32.exe and winnet.dll. Should I take it out of the vault and try
something else? This is on a laptop using my wirless network. I also
tried a different laptop that has not been used for over a month to see
if I could find out anything about this on the internet. I rec'd a
couple of wierd errors so I ran an scan with AVG on this computer which
showed the same error but I was able to remove it with no apparent
problems. I also have a couple of desktop computers which I have not
booted up. Can the trojan be in the wireless network router? Do I have
to start over (reformat) with the laptop that's giving me errors? Any
help would be greatly appreciated.......Brian


Posted by Elendil on August 9, 2006, 12:40 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
To begin with, myself (and others I believe) will need a little more
information on the problem:

1. What Operating System are you using?
2. Did the problems start occuring right after you removed the virus?
3. What is the name of this virus?
4. Are you using any other anti-malware software other than AVG?

I'm not sure if you have to do something as harsh as reformatting, yet.
As theory states, no anti-virus or anti-malware is perfect. While AVG is
excellent (I'm a huge fan of it), there is a rather large possibility
that it missed some things. There are a few options in this situation:

1. Make sure AVG is updated and scan in Safe Mode.
2. In your post you do not make any mentioning of scanning with
something other than an anti-virus program; however, your problem could
be spyware or a non-viral malware that AVG does not detect. Try using
Ewido Anti-Spyware

First download ewido anti-spyware from HERE and save that file to your
desktop.

1. Once you have downloaded ewido anti-spyware, locate the icon on
the desktop and double-click it to launch the set up program.
2. Once the setup is complete you will need to run ewido and update
the definition files.
3. On the main screen select the "Update" icon then click "Start
Update". The update will start and a progress bar will show the updates
being installed.
4. Once the update has completed select the "Scanner" icon at the top
of the screen, then select the "Settings" tab.
5. Once in the Settings screen click on "Recommended actions" and
then select "Quarantine".
6. Under "Reports"
* Select "Automatically generate report after every scan"
* Un-Select "Only if threats were found"

Close ewido anti-spyware and reboot your computer into Safe Mode.

1. Lauch ewido-anti-spyware by double-clicking the icon on your desktop.
IMPORTANT: Do not open any other windows or programs while ewido
is scanning, it may interfere with the scanning proccess.
2. Select the "Scanner" icon at the top and then the "Scan" tab then
click on "Complete System Scan"
3. Ewido will now begin the scanning process, be patient this may
take a little time.
4. Ewido will list any infections found on the left hand side. When
the scan has finished, it should automatically set the recommended
action to Quarantine--if not click on Recommended Action and set it
there. Click the Apply all actions button. Ewido will display "All
actions have been applied" on the right hand side.
5. Click on "Save Report", then "Save Report As". This will create a
text file. Make sure you know where to find this file again (like on the
Desktop).
6. Close ewido.
7. Locate the Ewido Scan Report, paste its contents into a reply, and
post the reply here as well as the state of your computer.

If these methods fail, don't despair! Reformatting is still a while away
as there are other methods.

bartlb@gmail.com wrote:
> I rec'd a popup from AVG indicating that my computer was infected. It
> is now in the vault but I am receiving messages when I try to run
> anything or just sitting there that there are files missing such as
> point32.exe and winnet.dll. Should I take it out of the vault and try
> something else? This is on a laptop using my wirless network. I also
> tried a different laptop that has not been used for over a month to see
> if I could find out anything about this on the internet. I rec'd a
> couple of wierd errors so I ran an scan with AVG on this computer which
> showed the same error but I was able to remove it with no apparent
> problems. I also have a couple of desktop computers which I have not
> booted up. Can the trojan be in the wireless network router? Do I have
> to start over (reformat) with the laptop that's giving me errors? Any
> help would be greatly appreciated.......Brian
>

--
ÐÏࡱá

Posted by bartlb@gmail.com on August 9, 2006, 1:23 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Thanks for the reply.
Operating system is Windows XP
The problem occurred as soon as I sent it to the vault in AVG
The virus is called Trojan Horse Downloader Agent.ETP
I also have Ad-aware but I had not run it for awhile
I am trying save myself from reformatting so that was why I was
wondering if I took it out of the AVG vault and scanned again whether I
could fix it or has it already corrupted a bunch of files...

Elendil wrote:
> To begin with, myself (and others I believe) will need a little more
> information on the problem:
>
> 1. What Operating System are you using?
> 2. Did the problems start occuring right after you removed the virus?
> 3. What is the name of this virus?
> 4. Are you using any other anti-malware software other than AVG?
>
> I'm not sure if you have to do something as harsh as reformatting, yet.
> As theory states, no anti-virus or anti-malware is perfect. While AVG is
> excellent (I'm a huge fan of it), there is a rather large possibility
> that it missed some things. There are a few options in this situation:
>
> 1. Make sure AVG is updated and scan in Safe Mode.
> 2. In your post you do not make any mentioning of scanning with
> something other than an anti-virus program; however, your problem could
> be spyware or a non-viral malware that AVG does not detect. Try using
> Ewido Anti-Spyware
>
> First download ewido anti-spyware from HERE and save that file to your
> desktop.
>
> 1. Once you have downloaded ewido anti-spyware, locate the icon on
> the desktop and double-click it to launch the set up program.
> 2. Once the setup is complete you will need to run ewido and update
> the definition files.
> 3. On the main screen select the "Update" icon then click "Start
> Update". The update will start and a progress bar will show the updates
> being installed.
> 4. Once the update has completed select the "Scanner" icon at the top
> of the screen, then select the "Settings" tab.
> 5. Once in the Settings screen click on "Recommended actions" and
> then select "Quarantine".
> 6. Under "Reports"
> * Select "Automatically generate report after every scan"
> * Un-Select "Only if threats were found"
>
> Close ewido anti-spyware and reboot your computer into Safe Mode.
>
> 1. Lauch ewido-anti-spyware by double-clicking the icon on your deskto=
p=2E
> IMPORTANT: Do not open any other windows or programs while ewido
> is scanning, it may interfere with the scanning proccess.
> 2. Select the "Scanner" icon at the top and then the "Scan" tab then
> click on "Complete System Scan"
> 3. Ewido will now begin the scanning process, be patient this may
> take a little time.
> 4. Ewido will list any infections found on the left hand side. When
> the scan has finished, it should automatically set the recommended
> action to Quarantine--if not click on Recommended Action and set it
> there. Click the Apply all actions button. Ewido will display "All
> actions have been applied" on the right hand side.
> 5. Click on "Save Report", then "Save Report As". This will create a
> text file. Make sure you know where to find this file again (like on the
> Desktop).
> 6. Close ewido.
> 7. Locate the Ewido Scan Report, paste its contents into a reply, and
> post the reply here as well as the state of your computer.
>
> If these methods fail, don't despair! Reformatting is still a while away
> as there are other methods.
>
> bartlb@gmail.com wrote:
> > I rec'd a popup from AVG indicating that my computer was infected. It
> > is now in the vault but I am receiving messages when I try to run
> > anything or just sitting there that there are files missing such as
> > point32.exe and winnet.dll. Should I take it out of the vault and try
> > something else? This is on a laptop using my wirless network. I also
> > tried a different laptop that has not been used for over a month to see
> > if I could find out anything about this on the internet. I rec'd a
> > couple of wierd errors so I ran an scan with AVG on this computer which
> > showed the same error but I was able to remove it with no apparent
> > problems. I also have a couple of desktop computers which I have not
> > booted up. Can the trojan be in the wireless network router? Do I have
> > to start over (reformat) with the laptop that's giving me errors? Any
> > help would be greatly appreciated.......Brian
> >=20
>=20
> --=20
> =D0=CF=E0=A1=B1=E1


Posted by David H. Lipman on August 9, 2006, 4:42 pm
If you were  Registered and logged in, you could reply and use other advanced thread options

| I rec'd a popup from AVG indicating that my computer was infected. It
| is now in the vault but I am receiving messages when I try to run
| anything or just sitting there that there are files missing such as
| point32.exe and winnet.dll. Should I take it out of the vault and try
| something else? This is on a laptop using my wirless network. I also
| tried a different laptop that has not been used for over a month to see
| if I could find out anything about this on the internet. I rec'd a
| couple of wierd errors so I ran an scan with AVG on this computer which
| showed the same error but I was able to remove it with no apparent
| problems. I also have a couple of desktop computers which I have not
| booted up. Can the trojan be in the wireless network router? Do I have
| to start over (reformat) with the laptop that's giving me errors? Any
| help would be greatly appreciated.......Brian


Download MULTI_AV.EXE from the URL --
http://www.ik-cs.com/programs/virtools/Multi_AV.exe

To use this utility, perform the following...
Execute; Multi_AV.exe { Note: You must use the default folder C:\AV-CLS }
Choose; Unzip
Choose; Close

Execute; C:\AV-CLS\StartMenu.BAT
{ or Double-click on 'Start Menu' in C:\AV-CLS }

NOTE: You may have to disable your software FireWall or allow WGET.EXE to go
through your
FireWall to allow it to download the needed AV vendor related files.

C:\AV-CLS\StartMenu.BAT -- { or Double-click on 'Start Menu' in C:\AV-CLS}
This will bring up the initial menu of choices and should be executed in Normal
Mode.
This way all the components can be downloaded from each AV vendor's web site.
The choices are; Sophos, Trend, McAfee, Kaspersky, Exit this menu and Reboot the
PC.

You can choose to go to each menu item and just download the needed files or you
can
download the files and perform a scan in Normal Mode. Once you have downloaded
the files
needed for each scanner you want to use, you should reboot the PC into Safe Mode
[F8 key
during boot] and re-run the menu again and choose which scanner you want to run
in Safe
Mode. It is suggested to run the scanners in both Safe Mode and Normal Mode.

When the menu is displayed hitting 'H' or 'h' will bring up a more comprehensive
PDF help
file. http://www.ik-cs.com/multi-av.htm

Additional Instructions:
http://pcdid.com/Multi_AV.htm


* * * Please report back your results * * *


--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm



Similar ThreadsPosted
Where does Trojan-downloader.win32.Agent.bkd start up? June 17, 2007, 9:33 pm
JS Downloader Agent (Virus) and Trojan Horses January 27, 2008, 2:24 pm
Trojan horse downloader.small.42m (C:\bla.exe) June 30, 2005, 7:42 am
Trojan horse Downloader.Istbar.6.BU November 15, 2005, 4:47 pm
Trojan Dropper Agent 8 B Help August 9, 2005, 9:21 pm
Re: Trojan Dropper Agent 8 B Help August 9, 2005, 10:44 pm
Re: Trojan Dropper Agent 8 B Help August 10, 2005, 12:39 pm
trojan.win32.agent.xud August 11, 2008, 4:18 pm
trojan.agent.f / ewido/grisoft-anti-malware ? December 19, 2006, 5:13 pm
Win32.Trojan.Spy.Agent.kb detected by ZoneAlarm Internet Security May 23, 2008, 3:13 pm

The site map in XML format XML site map

Contact Us | Privacy Policy