Re: AVG and Trojans
Posted by: mmf123456 (IP Logged)
Date: February 28, 2005 11:42PM
I had the exact same problem with AVG detecting Trojan 20.AG and the associated 41.exe file in my temp directory. None of the anti-virus/anti-spyware solutions could fix the problem. Here's what I did to fix it.
There was a file on my C drive named C:\Program Files\Parallel Tasking\ptask.exe. That's the culprit. If you have this file, delete it. You may have to kill the ptask.exe process first in the Windows Task Manager. I also deleted the Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\Parallel Tasking, which kicks off ptask.exe each time you boot windows. I did all this with Windows Restore turned off, just to be sure.
Ptask.exe would run once an hour. It would connect to a website www.amxgames.net and download a program (41.exe) from that site. The program 41.exe would then create a small .exe file (around 6K). The name of the newly-created .exe file was random each time, but it was always a series of numbers with an .exe extention (i.e., 2653.exe). This program would then run. It connected to the internet and send data somewhere (I don't know where). The file would then disappear.
I'd been trying for about 2 weeks to get rid of this thing with no luck, so I decided to try and trap it. I installed ZoneAlarm firewall (much better than Windows XP firewall because ZoneAlarm doesn't let anything get in or out of your computer without your explicit permission) and waited for the next hourly run of the trojan. As soon as ptask.exe woke up and tried to run, ZoneAlarm trapped it and the resulting alert log enabled me to see what was happening and take corrective action.
Good luck!
p.s. AVG started detecting this trojan on Feb 22nd, but I'd had the trojan since Jan 11. AVG recognized the 41.exe, but not the ptask.exe causing the problem