Jump to content


Photo

win32tr\.\erAgent


  • This topic is locked This topic is locked
3 replies to this topic

#1 SSAlcorn

SSAlcorn

    Newbie

  • Members
  • Pip
  • 1 posts

Posted 01 June 2009 - 02:50 AM

Ad-Aware notified me that it stopped a process "Win32.TrojanDownloader.Agent". I opened up Ad-Aware to run a scan. When I tried to update it, it said that a connection to the internet was not available (I was online & I confirmed that a connection was available). I have run Ad-Aware scan several times; each time it detects malware "Win32Tr\.\erAgent". I delete this malware and restart the computer. However, I keep getting notifications that Ad-Aware is stopping the process, and I have run the scan several times, attempted to remove the malware, but it does not get removed. Furthermore, I cannot update Ad-Aware. What do I do now?

#2 visitor

visitor

    Advanced Member

  • Valued Member
  • PipPipPip
  • 2855 posts

Posted 01 June 2009 - 06:14 AM

Moved to the forum "HELP! My computer is infected! What should I do?" Follow the instructions in this pinned thread: IMPORTANT: Before You Post Read This!

For the connection problem, read the pinned threads in this forum.
Before posting, please read the pinned topics atop the forums or check the Lavasoft searchable FAQs.

Lavasoft Support for Plus/Pro paid licenses.

Help fight malware! Upload Suspicious Files to Lavasoft.

Malware removal assistance? Please read this first.
After following the instructions, open a new thread in the HijackThis Forum where you can copy/paste your HJT log.
Note: do not bump HJT threads by replying - volunteer security advisors help the 0 reply threads on a first-come, first-served basis.

#3 Rorschach112

Rorschach112

    Advanced Member

  • Volunteer Security Advisor
  • PipPipPip
  • 2180 posts

Posted 03 June 2009 - 06:27 PM

hi
  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in

    netsvcs
    msconfig
    safebootminimal
    safebootnetwork
    activex
    drivers32
    %systemroot%\System32\antiwpa.dll
    %systemroot%\SYSTEM32\wpa.dll
    %systemroot%\setup\scripts\biestart.exe
    %systemroot%\system32\drivers\royal.sys
    %SYSTEMDRIVE%\*.
    %SYSTEMDRIVE%\*.*
    %PROGRAMFILES%\*.

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTListIt.Txt and Extras.Txt. These are saved in the same location as OTListIt2.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them all in.

By the power of truth, I, while living, have conquered the universe.

~Scratch~

My help is always free, but if you want to donate to help me continue my fight against malware then click here

#4 Rorschach112

Rorschach112

    Advanced Member

  • Volunteer Security Advisor
  • PipPipPip
  • 2180 posts

Posted 06 June 2009 - 09:40 PM

Due to lack of feedback, this topic has been closed.

If you need this topic reopened, please contact a staff member. This applies only to the original topic starter.

Everyone else please begin a New Topic.

Thank You !
By the power of truth, I, while living, have conquered the universe.

~Scratch~

My help is always free, but if you want to donate to help me continue my fight against malware then click here




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users