Page 1 of 4 123 ... LastLast
Results 1 to 10 of 32
  1. #1
    Supernova
    Overall activity: 76.0%

    Join Date
    Feb 2010
    Location
    Calcutta, India, India
    Posts
    3,730
    Liked
    667 times
    Points
    48,426

    Bug SYSTEM32.dll (Trojan.Agent)

    I have three PCs in my household. whenever I scan with MBAM firsttime after a first time it always finds SYSTEM32.dll (Trojan.Agent) in C:\Users\user\AppData\Roaming\
    I installed my vista desktop ~ 4days ago. I wanted to test mbam beta in it. It finds the same system32.dll in it. So, I am wondering how can I be infected with same malware all times, even is I reinstall everything after a clean format of all drives. I also redownloaded all the softwares again. I am attaching MBAM log, hijackThis log and NoVirusThanks Hijack Hunter log here.
    logs.zip

  2. #2
    Whiz Kid
    Overall activity: 0%

    Join Date
    Sep 2008
    Location
    Albania
    Posts
    1,771
    Liked
    80 times
    Points
    20,857
    Probably a false positive. Or this is causing the problem:
    O4 - HKLM\..\Run: [avast5] C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe /nogui
    O4 - HKLM\..\Run: [COMODO Internet Security] "C:\Program Files\COMODO\COMODO Internet Security\cfp.exe" -h
    You have 2 AV installed side by side. Other problems will come up for you untill you uninstall one of them.

    Screw Google! Ask me!


  3. #3
    *nix Technical Support
    Overall activity: 35.0%

    Join Date
    Jan 2009
    Location
    /home/hellnoire
    Posts
    9,845
    Liked
    319 times
    Points
    26,077
    Comodo can always be the Firewall only.

    I also don't think that's a False Positive, since System32.dll shouldn't be located there....
    pacman -Syyu life not found in sync db

  4. #4
    Whiz Kid
    Overall activity: 0%

    Join Date
    Sep 2008
    Location
    Albania
    Posts
    1,771
    Liked
    80 times
    Points
    20,857
    I doubt he has deactivated the AV engine. He has also installed Immunet though. I don't know why this guy needs this much real time security.

  5. #5
    Supernova
    Overall activity: 76.0%

    Join Date
    Feb 2010
    Location
    Calcutta, India, India
    Posts
    3,730
    Liked
    667 times
    Points
    48,426
    @hellnoire and Alboguy: I installed only comodo firewall standalone during the installation. But it shows comodo internet security don't know why. I thought immunet can be run together with any AV as told in their website. But as I said this alart is very old. I mean Malwarebyte detects it in all of my PC's at first run, even if I reinstalled it recently. This happens much before before even immunet were in the market.

  6. #6
    Whiz Kid
    Overall activity: 0%

    Join Date
    Sep 2008
    Location
    Albania
    Posts
    1,771
    Liked
    80 times
    Points
    20,857
    Where did you get the Widows Cd? Maybe the virus is inside in there...

  7. #7
    Moderator
    Overall activity: 73.0%

    Join Date
    Dec 2008
    Location
    Italy
    Posts
    6,895
    Liked
    1067 times
    Points
    71,755
    Hi,
    System32.dll simply doesn't exist
    It is not a system file. I mean.
    Would you please upload System32.dll to www.virustotal.com?
    Roger and out

  8. #8
    Supernova
    Overall activity: 76.0%

    Join Date
    Feb 2010
    Location
    Calcutta, India, India
    Posts
    3,730
    Liked
    667 times
    Points
    48,426

    Spin

    Quote Originally Posted by Alboguy View Post
    Where did you get the Widows Cd? Maybe the virus is inside in there...
    I purchased it from a retailer. But it couldn't be inside the CD. Because the same system32.dll problem occurred in my laptop which has windows7.
    Quote Originally Posted by leofelix View Post
    Would you please upload System32.dll to www.virustotal.com?
    surely I will. Actually right now I am not in my Desktop. Would u mind if I do it a little later. But I already uploaded it to virustotal with 0 detection.

  9. #9
    Moderator
    Overall activity: 73.0%

    Join Date
    Dec 2008
    Location
    Italy
    Posts
    6,895
    Liked
    1067 times
    Points
    71,755
    Quote Originally Posted by sujay View Post
    surely I will. Actually right now I am not in my Desktop. Would u mind if I do it a little later. But I already uploaded it to virustotal with 0 detection.
    Ok. I can wait of course

    Even if it looks very strange since system32.dll doesn't exists as far as I know.
    MBAM sould have deleted and/or quarantined.

    However, I think some experts will help you soon

  10. #10
    Supernova
    Overall activity: 76.0%

    Join Date
    Feb 2010
    Location
    Calcutta, India, India
    Posts
    3,730
    Liked
    667 times
    Points
    48,426
    Quote Originally Posted by leofelix View Post
    MBAM sould have deleted and/or quarantined.
    yes MBAM deleted this. So should I restore this..!! MBAM does not give a option to save it to other location.
    Quote Originally Posted by leofelix View Post
    Even if it looks very strange since system32.dll doesn't exists as far as I know.
    I have googled about system32.dll and got a information that it is related to harnig trojan. Not a reliable source though.
    Quote Originally Posted by leofelix View Post
    However, I think some experts will help you soon
    You are wise enough.. to find that I have asked about this in malwarebyte forum. No answer yet from them. I've asked in the wilders also.
    Last edited by sujay; 03-25-2010 at 02:10 AM.

 

 
Page 1 of 4 123 ... LastLast

Similar Threads

  1. System32 File changer
    By ha14 in forum Latest Releases
    Replies: 7
    Last Post: 11-28-2010, 08:33 PM
  2. Bios Agent Plus
    By snarff in forum Software
    Replies: 2
    Last Post: 11-09-2009, 06:53 AM
  3. NetStat Agent
    By ha14 in forum Software
    Replies: 2
    Last Post: 08-17-2009, 02:24 AM
  4. help: i messed with system32 files
    By vgb_stylecs in forum General Forum
    Replies: 7
    Last Post: 10-17-2008, 06:56 AM
  5. System32\Drivers\ntfs.sys
    By putingcow in forum General Forum
    Replies: 1
    Last Post: 03-27-2008, 09:53 PM
All times are GMT +8. The time now is 08:55 AM.