Computing.Net > Forums > Security and Virus > Agobot not deleted by AVG free

Computing.Net: Over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to sign up now, it's free!

Agobot not deleted by AVG free

Reply to Message Icon

Original Message
Name: G_B
Date: January 7, 2004 at 04:49:20 Pacific
Subject: Agobot not deleted by AVG free
OS: Windows 2000
CPU/Ram: 2800/512
Comment:

Have got AVG Free edition and its resident shield keeps telling me it detects the Agobot virus, but when I run AVG complete test it finds nothing. Please reply soon as I have heard this is a very bad virus.

I am also finding that after I have been using the internet for a short while it stops letting me open links in new windows? any sggestions?

Finally what are peoples views on the web browser firebird? I am thinking of installing it.

Thankyou in advance


Report Offensive Message For Removal


Response Number 1
Name: capt
Date: January 7, 2004 at 07:24:54 Pacific
Reply: (edit)

Try the scan at http://housecall.trendmicro.com/ There is a free trojan scan at http://www.pcflank.com/


Report Offensive Follow Up For Removal

Response Number 2
Name: iceblue
Date: January 7, 2004 at 11:15:05 Pacific
Reply: (edit)

Agree;
and then follow that with a Spybot or Ad-aware scan;
and post up a Hijack log.

Spybot
AdAware
HijackThis
http://www.spywareinfo.com/~merijn/files/hijackthis.zip


Report Offensive Follow Up For Removal

Response Number 3
Name: G_B
Date: January 8, 2004 at 02:12:46 Pacific
Reply: (edit)

Cheers, will probably try it in a bit, though haven't had any virus warnings since I turned on this morning. Phantom virus? :-)


Report Offensive Follow Up For Removal

Response Number 4
Name: G_B
Date: January 8, 2004 at 03:19:42 Pacific
Reply: (edit)

Right where do I start :-)

Ran the adware, spybot and housecall programs. Couldn't access PCflank.

Moments before I was about to do all that My computer started hanging, services.exe was using 100% CPU power. Have searched internet and only real suggestion seemed to be installing a service pack for windows, but I already have the latest.

When I restarted my computer I saw a command prompt style window telling me something about drivers not found for hidden.exe and services.exe. I also have a strange executable running SysInt32.exe

Spybot and adware found loads of stuff mostly Gator products. Housecall found the MUMU.B Trojan but was unable to clean it.

Finally here is my Hijack this log file:

Logfile of HijackThis v1.97.7
Scan saved at 11:18:18 PM, on 1/8/2004
Platform: Windows 2000 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG6\avgserv.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINNT\System32\nvsvc32.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\Explorer.exe
C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe
C:\WINNT\anvshell.exe
C:\WINNT\System32\spool\DRIVERS\W32X86\3\E_S10IC1.EXE
C:\WINNT\System32\P2P Networking\P2P Networking.exe
C:\Program Files\Common files\updater\wupdater.exe
C:\program files\altnet\points manager\points manager.exe
C:\PROGRA~1\Altnet\DOWNLO~1\asm.exe
C:\WINNT\System32\ctfmon.exe
C:\WINNT\system32\services.exe
C:\Program Files\blueyonder IST\bin\mpbtn.exe
C:\WINNT\System32\taskmgr.exe
C:\WINNT\system32\ntvdm.exe
C:\Program Files\mozilla.org\Mozilla\mozilla.exe
C:\PROGRA~1\WINZIP\winzip32.exe
C:\Documents and Settings\G-Force\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.shef.ac.uk/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = ,
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = ,
R1 - HKCU\Software\Microsoft\Internet Explorer,SearchAssistant = ,
R1 - HKCU\Software\Microsoft\Internet Explorer,CustomizeSearch = ,
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,(Default) = ,
R3 - URLSearchHook: (no name) - {6CC1C918-AE8B-4373-A5B4-28BA1851E39A} - (no file)
R3 - URLSearchHook: PerfectNavBHO Class - {A045DC85-FC44-45be-8A50-E4F9C62C9A84} - C:\PROGRA~1\PERFEC~1\BHO\PERFEC~1.DLL
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: NavErrRedir Class - {A045DC85-FC44-45be-8A50-E4F9C62C9A84} - C:\PROGRA~1\PERFEC~1\BHO\PERFEC~1.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [LiveNote] livenote.exe
O4 - HKLM\..\Run: [AVG_CC] C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe /STARTUP
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [anvshell] anvshell.exe
O4 - HKLM\..\Run: [EPSON Stylus C42 Series] C:\WINNT\System32\spool\DRIVERS\W32X86\3\E_S10IC1.EXE /P23 "EPSON Stylus C42 Series" /O6 "USB001" /M "Stylus C42"
O4 - HKLM\..\Run: [P2P Networking] C:\WINNT\System32\P2P Networking\P2P Networking.exe /AUTOSTART
O4 - HKLM\..\Run: [updater] C:\Program Files\Common files\updater\wupdater.exe
O4 - HKLM\..\Run: [AltnetPointsManager] c:\program files\altnet\points manager\points manager.exe -s
O4 - HKLM\..\Run: [NeroCheck] C:\WINNT\System32\NeroCheck.exe
O4 - HKLM\..\Run: [Sysscan] C:\winnt\system32\drivers\etc\dll.bat
O4 - HKLM\..\Run: [Microsoft Windows System Kernel Initializer] SysInt32.exe
O4 - HKLM\..\RunServices: [Microsoft Windows System Kernel Initializer] SysInt32.exe
O4 - HKCU\..\Run: [ctfmon.exe] ctfmon.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: GStartup.lnk = C:\Program Files\Common Files\GMT\GMT.exe
O4 - Global Startup: blueyonder Instant Support Tool.lnk = C:\Program Files\blueyonder IST\bin\matcli.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O15 - Trusted Zone: *.teen-me.com
O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} (Web P2P Installer) -
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} - http://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2003120501/housecall.antivirus.com/housecall/xscan53.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?37957.3644560185
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab

Please help I am somewhat bewilderd by all this.

Thanks


Report Offensive Follow Up For Removal







Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home








Do you have your own blog?

Yes
No
I did before
I will soon


View Results

Poll Finishes In 4 Days.
Discuss in The Lounge
Poll History




Data Recovery Software