Warning: iconv_mime_decode() [function.iconv-mime-decode]: Malformed string in /home/secureg/public_html/lib/standard.lib.php on line 2251
TROJAN INFO
TROJAN INFO

TROJAN INFO

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
TROJAN INFO IgNiTE 08-09-2008
|--> Re: TROJAN INFO Maurice N ~ MV...08-10-2008
Posted by =?Utf-8?B?SWdOaVRF?= on August 9, 2008, 5:54 pm
If you were  Registered and logged in, you could reply and use other advanced thread options


Hey,
I was just running a AV scan thru my ESET's NOD32. I just got a new update
from online with more signatures and stuff. So I wanted to do the scan see if
something pops up. I do this scans about every 2 or 3 days. I did have Vundo
trojan before like a 3 to 4 weeks ago. Thanks to Microsoft MVPS, Fourms like
this & Aumha Fourms that problem was taken care of.
Here is the Error popped just few min. ago.

Threat :- Win32/Agent.OBH Trojan.
Anyone know what that means or what type of trojan are we talking about here.

Thanks for your input.

Posted by Maurice N ~ MVP on August 10, 2008, 12:35 pm
If you were  Registered and logged in, you could reply and use other advanced thread options


Q: Did NOD32 indicate the name of the file(s) involved ?

--=20
Maurice Naggar=20
MS-MVP=20
-----

> Hey,
> I was just running a AV scan thru my ESET's NOD32. I just got a new =
update=20
> from online with more signatures and stuff. So I wanted to do the scan =
see if=20
> something pops up. I do this scans about every 2 or 3 days. I did have =
Vundo=20
> trojan before like a 3 to 4 weeks ago. Thanks to Microsoft MVPS, =
Fourms like=20
> this & Aumha Fourms that problem was taken care of.=20
> Here is the Error popped just few min. ago.
>=20
> Threat :- Win32/Agent.OBH Trojan.
> Anyone know what that means or what type of trojan are we talking =
about here.
>=20
> Thanks for your input.

Posted by Maurice N ~ MVP on August 10, 2008, 12:46 pm
If you were  Registered and logged in, you could reply and use other advanced thread options


P.S. =20
ref =
http://research.sunbelt-software.com/threatdisplay.aspx?name=3DTrojan.Win=
32.Agent.oh&threatid=3D44209
"Trojan.Win32.Agent.oh is a trojan downloader that contacts remote =
servers to download and install additional malware."
"Trojan.Win32.Agent.oh infects Windows files winlogon.exe and =
iexplore.exe. It modifies the registry and may lower system security."
"File Traces
1303.exe=20
arm32.dll=20
c:\documents and settings\all users\documents\settings06.dll=20
C:\Documents and Settings\All Users\Documents\Settings\ur32mega.dll=20
ver2.exe=20
veter15.exe=20
veter16.exe=20
"
Let me suggest you have NOD32 put the tagged files in quarantine, at =
least.

--=20
Maurice Naggar=20
MS-MVP=20
-----

> Hey,
> I was just running a AV scan thru my ESET's NOD32. I just got a new =
update=20
> from online with more signatures and stuff. So I wanted to do the scan =
see if=20
> something pops up. I do this scans about every 2 or 3 days. I did have =
Vundo=20
> trojan before like a 3 to 4 weeks ago. Thanks to Microsoft MVPS, =
Fourms like=20
> this & Aumha Fourms that problem was taken care of.=20
> Here is the Error popped just few min. ago.
>=20
> Threat :- Win32/Agent.OBH Trojan.
> Anyone know what that means or what type of trojan are we talking =
about here.
>=20
> Thanks for your input.

Posted by =?Utf-8?B?RGFu?= on August 19, 2008, 5:46 am
If you were  Registered and logged in, you could reply and use other advanced thread options


Exactly, Maurice, it is important to let NOD32 put the tagged files in
quarantine and then the tagged files need to be fully analyzed for a threat
or to see if the issue was a false positive on NOD32's part. There are too
many false positives in the industry these days.

"Maurice N ~ MVP" wrote:

> P.S.
> ref
http://research.sunbelt-software.com/threatdisplay.aspx?name=Trojan.Win32.Agent.oh&threatid=44209
> "Trojan.Win32.Agent.oh is a trojan downloader that contacts remote servers to
download and install additional malware."
> "Trojan.Win32.Agent.oh infects Windows files winlogon.exe and iexplore.exe. It
modifies the registry and may lower system security."
> "File Traces
> 1303.exe
> arm32.dll
> c:\documents and settings\all users\documents\settings06.dll
> C:\Documents and Settings\All Users\Documents\Settings\ur32mega.dll
> ver2.exe
> veter15.exe
> veter16.exe
> "
> Let me suggest you have NOD32 put the tagged files in quarantine, at least.
>
> --
> Maurice Naggar
> MS-MVP
> -----
>
> > Hey,
> > I was just running a AV scan thru my ESET's NOD32. I just got a new update
> > from online with more signatures and stuff. So I wanted to do the scan see
if
> > something pops up. I do this scans about every 2 or 3 days. I did have Vundo
> > trojan before like a 3 to 4 weeks ago. Thanks to Microsoft MVPS, Fourms like
> > this & Aumha Fourms that problem was taken care of.
> > Here is the Error popped just few min. ago.
> >
> > Threat :- Win32/Agent.OBH Trojan.
> > Anyone know what that means or what type of trojan are we talking about here.
> >
> > Thanks for your input.
>

Similar ThreadsPosted
PkiView.msc - where does it get its info? March 26, 2007, 7:43 am
Clearing BANK info off of a PC.... How to? March 20, 2007, 9:41 pm
How do get the Certificate info from at .cat file April 14, 2007, 4:30 pm
1yz.info - Anonymous Proxy December 24, 2007, 3:18 am
Re: Computer Info Compromised? February 2, 2008, 2:09 am
how do i get info from incoming mail October 9, 2008, 10:42 am
If you hack a server joined to domain, how much info can you get ? August 16, 2005, 11:41 am
SCForum.info - Security CENTRAL Forum May 31, 2007, 2:22 pm
Require Info on EAP extension development for windows mobile February 21, 2007, 7:18 am
info on the National Information Security Group (NAISG) + an invitation February 4, 2008, 9:34 pm

The site map in XML format XML site map

Contact Us | Privacy Policy