Welcome, Guest. Please login or register.
November 18, 2008, 05:56:49 PM

Login with username, password and session length

212220 Posts
24530 Topics
57708 Members

Latest Member: zebadee

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  Desktop Security Products
| |-+  Comodo Internet Security - CIS
| | |-+  Virus/Malware Removal Assistance
| | | |-+  how can i remove this?
« previous next »
Pages: [1] Go Down Print
Author Topic: how can i remove this?  (Read 1517 times)
Ghost57
Newbie
*
Offline Offline

Posts: 7


« on: June 04, 2007, 11:16:05 PM »

heres a scan from jotti on a fake csrss.exe i have and comodo dont find any virus in it and i need help
heres the log
 Service load:     
0%              100%
File:    csrss.exe
Status:    
INFECTED/MALWARE (Note: this file has been scanned before. Therefore, this file's scan results will not be stored in the database)
MD5    77a9fd1cd6aa2ad137e53aaff18b77f3
Packers detected:    
PE_PATCH.UPX, UPX
Scanner results
Scan taken on 05 Jun 2007 03:45:38 (GMT)
A-Squared    
Found nothing
AntiVir    
Found TR/Agent.141606
ArcaVir    
Found nothing
Avast    
Found nothing
AVG Antivirus    
Found nothing
BitDefender    
Found nothing
ClamAV    
Found nothing
Dr.Web    
Found nothing
F-Prot Antivirus    
Found nothing
F-Secure Anti-Virus    
Found Trojan-Downloader.Win32.Agent.bl
Fortinet    
Found W32/Agent.BL!tr.dldr
Kaspersky Anti-Virus    
Found Trojan-Downloader.Win32.Agent.bl
NOD32    
Found nothing
Norman Virus Control    
Found nothing
Panda Antivirus    
Found Trj/Agent.FHZ
Rising Antivirus    
Found nothing
VirusBuster    
Found nothing
VBA32    
Found Trojan-Downloader.Win32.Agent.bl

so i need help with this
Logged
Toggie
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 1256


"Oh, let me have just a little bit of peril"


« Reply #1 on: June 05, 2007, 12:33:36 AM »

Hi Ghost57, me again Smiley

Can I take it you downloaded CAVs and it didn't find the virus? Did you update the virus database before scanning?

Are you running any other AV programs, if so, which?

I found some info on removing Trojan-Downloader.Win32.Agent.bl:

1. Delete the original Trojan file (its location will depend on how the malicious program originally penetrated the victim machine).

2. Delete the file downloaded by the Trojan:

C:\ntldr.pif

From what I can make out, the other viruses found in your scan are just different names for the same virus.

Perform the steps above and run another scan.

Toggie

Logged

One man alone can be pretty dumb sometimes, but for real bona fide stupidity, there ain't nothin' can beat teamwork.
Ghost57
Newbie
*
Offline Offline

Posts: 7


« Reply #2 on: June 05, 2007, 02:30:10 AM »

its fixed for now my other AV detected it and removed it after i scaned the fake csrss.exe thx for the help  Saved My Life

Edit: Also BoClean also detected and removed 3 trojans ill be runing a few scans to make sure its clean  Bounce
« Last Edit: June 05, 2007, 02:32:16 AM by Ghost57 » Logged
Toggie
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 1256


"Oh, let me have just a little bit of peril"


« Reply #3 on: June 05, 2007, 02:47:32 AM »

Good news Smiley
Logged

One man alone can be pretty dumb sometimes, but for real bona fide stupidity, there ain't nothin' can beat teamwork.
Tags:
Pages: [1] Go Up Print 
« previous next »
Jump to:  

SSL Firewall
Page created in 0.165 seconds with 20 queries.
Powered by SMF 1.1.7 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com