Return Styles: Pseud0ch, Terminal, Valhalla, NES, Geocities, Blue Moon. Entire thread

HELP Please: win32.agent.yr

Name: Anonymous 2007-03-04 13:34 ID:++raJvjl

WinXP Pro ver 2002 SP2
Firefox 1.5.0.10
Spybot S&D 1.4 definitions updated 2007-02-28 (latest as of now)
AdAware SE Personal Build 1.06r1 def 2007-03-03
Symantec AntiVirus Corporate Ed. 9.0.1.1000 Scan Engine 71.1.0.11 def 2007-03-02 rev. 52

AdAware and SAV caught nothing. Spybot s&d scan said I have the trojan win32.agent.yr and claimed to have fixed the problem. I scanned my system once more but it was still there (again it told me the problem was fixed). Rebooted in safe mode, Spybot s&d didn't even find the trojan in safe mode (found some tracking cookie called avenue a or something instead). Rebooted normally, scanned again, win32.agent.yr still there; back to square one.

How do I get rid of it?

The only place that appears to offer a solution is here but alas, I don't speak the language of the moon:
http://forum.zebulon.fr/lofiversion/index.php/t116672.html

Thanks!

Name: Anonymous 2007-03-04 19:23 ID:hZTGYbKS

Boot with ERD Commander or BartPE or something like that and delete the file.

Name: Anonymous 2007-03-05 2:40 ID:4ATxGqWm

>>2
Thank you but one problem:

HKEY_USERS\S-1-5-21-606747145-1979792683-839522115-1004\Software\Microsoft\Windows\ShellNoRoam\MUICache\*\keygen.exe

That's the infected file (numbers between HKEY_USERS and Software are different). I can't find it anywhere, not even in the registry. Suggestions?

Name: Anonymous 2007-03-06 4:09 ID:xiFnYIYA

Its completely possible its not infected at all. I've had overzealous AV software label scene released apps as harmful executables. But the previous comment is the most effective method, if you can't find the file then it doesn't exist. Or you could always run this http://www.rootkitdetector.com/

Name: Anonymous 2007-03-06 9:46 ID:2lEzwQw1

Name: Anonymous 2007-03-06 12:01 ID:PHzhcnWw

Rootkit detected
It's name is "WINDOWS VISTA"
Recommend format, install *Ubuntu

Name: Anonymous 2007-03-06 12:54 ID:8eD1EBQt

vista isnt a rootkit. its so ugly you know its there.

Newer Posts
Don't change these.
Name: Email:
Entire Thread Thread List