This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Avira found TR/Agent.2560

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi. On 6/19/2010 I ran and Avira AntiVir scan (I updated the virus definition the night before) and it gave the following report:

The file 'C:\System Volume Information\_restore{0AB5023C-B9FC-4058-B687-9CC9BB5AFF8B}\RP1169\A0071885.exe'
contained a virus or unwanted program 'TR/Agent.2560' [trojan]
Action(s) taken:
The file was moved to '4c4cd639.qua'!

The file 'C:\System Volume Information\_restore{0AB5023C-B9FC-4058-B687-9CC9BB5AFF8B}\RP1170\A0071972.exe'
contained a virus or unwanted program 'TR/Agent.2560' [trojan]
Action(s) taken:
The file was moved to '4c4cd63a.qua'!

I couldn't find anything on this particular trojan via Google.

Since the quarantined files were just restore points I felt it was OK to delete them, and did so.
I ran ATF Cleaner, CCleaner, and TFC.exe (which required a system reboot) to clean everything up.

After reboot, I ran another Avira scan and it found noting. I updated Malwarebyte's Antimalware and SuperAntiSpyware, ran both of their quickscans, and found nothing.

This morning (6/21/10) I ran a GMER scan and nothing was highlighted.
I also ran the BitDefender Online Virus Scan and it found nothing.

I used Add/Remove Programs to remove HijackThis 2.0.2 (it instructed me to remove the HijackThis.exe file manually - I found there was an old Hijackthis.exe vers.1.x which I also deleted). An alert popped up saying Verify Class ID encountered a problem and had to close, followed by a dwwin.exe - Application Error message (The instruction at "0x77df0717" referenced memory at "0x00000004". The memory could not "read". Click on OK to terminate the program).

I downloaded and installed Hijackthis.msi to get the latest 2.0.4 vers. After it installed I saw another of the Verify Class ID alerts.

I don't notice anything very odd with the laptop other than the alerts I've mentioned (it's old - 256 mb ram - tends to run pretty slow, but fine enough for web surfing). The one thing is that, when clicking Start –>All Programs the blue cursor sometimes is not carrying over to the next menu (Accessories, Games, etc.) I have to click on the desktop to close the menu and then reopen it, in which case it then seems to work.

Another thing I noticed after the Avira scan was that only 28 items were appearing in Task List Manager - usually it's 29 when no browser, email program, etc. is open. I noticed the missing .item was cmdagent.exe, which is part of Comodo - cfp.exe, the firewall, was still there. I had a tricky time updating Comodo Firewall a few weeks ago (it decided it was incompatible with my Antivirus program) but seemed to finally get installed OK. cmdagent.exe reappeared after the system reboot.

Anyway, sorry to drone on. I wanted to make sure the malware was real, and not a false positive, and, if it is real, that it's all gone. Thanks in advance.

Here's the HJT report - the 08 item seems to be a hanger-on - I removed Google Toolbar a few weeks ago. The two 022 items are not anything I'd ever seen with HJT 2.0.2. The 023 item for ASP.NET is also a hanger-on - I believe I removed that program quite a while ago.

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 11:49:08 AM, on 6/21/2010
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Dell\AccessDirect\dadapp.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\COMODO\COMODO Internet Security\cfp.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Trend Micro\HijackThis\HiJackThis.exe
C:\Program Files\Mozilla Firefox\firefox.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ikariam.org/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [DadApp] "C:\Program Files\Dell\AccessDirect\dadapp.exe"
O4 - HKLM\..\Run: [SynTPLpr] "C:\Program Files\Synaptics\SynTP\SynTPLpr.exe"
O4 - HKLM\..\Run: [SynTPEnh] "C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
O4 - HKLM\..\Run: [NvCplDaemon] "C:\WINDOWS\system32\RUNDLL32.EXE" C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] "C:\WINDOWS\system32\nwiz.exe" /installquiet
O4 - HKLM\..\Run: [WorksFUD] "C:\Program Files\Microsoft Works\wkfud.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] "C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [COMODO Internet Security] "C:\Program Files\COMODO\COMODO Internet Security\cfp.exe" -h
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O8 - Extra context menu item: Google Sidewiki… - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_2EC7709873947E87.dll/cmsidewiki.html
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {076169AA-8C3D-4CFC-AC23-3ACA88FC21B5} (F-Secure Online Scanner Launcher) - http://download.sp.f-secure.com/ols/f-secu…/fslauncher.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} - http://www.eset.eu/buxus/docs/OnlineScanner.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/…can8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1263481292217
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - http://download.eset.com/special/eos/OnlineScanner.cab
O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} (F-Secure Online Scanner 3.3) - http://support.f-secure.com/ols/fscax.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://games.pogo.com/online2/pogo/bejewel…aploader_v6.cab
O20 - AppInit_DLLs: C:\WINDOWS\system32\guard32.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe

–
End of file - 5336 bytes
Posted Image

You should be XP SP3

You need to apply Service Pack 3 for Windows XP. Without this update, you're wide open to re-infection. Click here:

Apply the update, reboot, and let me know how it's running.
Hi LDTate, Thanks for the reply. This computer has pretty well been kept up tp date with High Priority MS updates other than SP3, but I'll install it (not sure why I get nervous about the big SP updates, but I do). So should I not be concerned about an infection based on my first post? I'd like to be sure it's a clean machine before installing SP3. Some updated info since 6/21: 1.I had that Verify Class ID error once more, while opening Outlook Express. When I clicked to send MS an error report, it said "In order to correctly diagnose thise problem, the following information is required: Copies of these files: %MODDIR%\unknown" I canceled out of the report then. 2. On 6/22 I updated my antivir and antimalware programs, rebooted to Safe Mode, ran CCleaner and ATF cleaner, then ran Avira, MalwareByte's, SuperAntiSpyware, and CWShredder, none of which found any infection. 3. While still in Safe Mode I Defragmented the hard disk. 4. I rebooted to normal. The Comodo icon down on the taskbar showed a red warning symbol - it turned out Defense+ wasn't functioning properly and suggested I "run diagnostic to fix the problem". Diagnostic didn't find any problem. I ran TFC.exe, rebooted, and everything was functioning normally after that (though the problem I metioned in my first post, about the cursor sometimes not carrying over from the Start menu to adjacent menus, persists). Thanks again for your help. I'll have time tomorrow to set aside for backing up some files and then doing the SP3 update.
Support for SP2 is ending from MS. There are a lot of security iussues SP3 fixed. I've used SP3 after it was out for about 6 months and haven't had any issues. It's your call though. I don't see anything bad in your log but that doesn't mean anything.
Hi again. I didn't realize the support for SP2 would be ending. Thanks for the head's up. I've just completed the update to SP3. There are still a bunch of further SP3-related updates to follow, but this machine's been chugging along (took about 75 minutes for the download and install) on a hot afternoon, so I'll let it rest a while and then take care of them. Thanks for the help. I'll let you know how the machine is performing in a couple days.
Hi, Things seem OK. There were an additional 61 High Priority MS updates once I installed SP3, so I divided their installations over three days, just so I'd be able to narrow things down somewhat if there were any complications. Comodo Defense+ still occasionally doesn't function correctly after rebooting the system, but I see on the Comodo forums that it is a known issue, and will try one of the fixes I've seen there. Thanks for the help, LD. Feel free to close this thread :)

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI