Troj_agent.L

  • ThATKiD
  • Proficient
  • Proficient
  • User avatar
  • Joined: Jan 23, 2004
  • Posts: 321
  • Loc: somewere over there
  • Status: Offline

Post May 11th, 2004, 5:19 pm

i got a computer where trend micro found a virus called Troj_Agent.L.
i did a google on it and trend is the only company that has any information on the virus. But none of it is in english. Trend log has a file called sysupd.exe and its repeated about 7 million times followed by what looks like encrypted file names.

it has the computer slowing down and kicks off network, shuts down IE and doesn't allow me to delete or fix quarantine file it shuts down trend.

if it helps ill try to post up the log later.

** trend is PCCILLIN
  • Anonymous
  • Bot
  • No Avatar
  • Joined: 25 Feb 2008
  • Posts: ?
  • Loc: Ozzuland
  • Status: Online

Post May 11th, 2004, 5:19 pm

  • ATNO/TW
  • Super Moderator
  • Super Moderator
  • User avatar
  • Joined: May 28, 2003
  • Posts: 23407
  • Loc: Woodbridge VA
  • Status: Offline

Post May 11th, 2004, 5:38 pm

Type sysupd.exe into google and click the first link re: pest patrol. It will redirect you here:

http://www.pestpatrol.com/pestinfo/t/tscash.asp

That is probably the solution.
"There's no place like 127.0.0.1 except for ::1."
Alexandria Networks. Leader in IT consulting for associations/non-profits, and small to medium sized businesses around the northern Virginia and Washington D.C. metro area.
  • Vladdrac
  • Mastermind
  • Mastermind
  • User avatar
  • Joined: Feb 04, 2004
  • Posts: 2136
  • Loc: Louisville, Ky
  • Status: Offline

Post May 12th, 2004, 9:55 am

hmmm my wife just got the virus agent.h, apparently it was a key logger.

I am not sure if this was the proper way to do it, but i deleted sysupd.exe in C:/windows, turned off system restore and ran my antivirus, then it healed it.

I hope that I havent caused any issues by deleting that file though.
  • plc_spec
  • Born
  • Born
  • No Avatar
  • Joined: Jun 08, 2004
  • Posts: 4
  • Status: Offline

Post June 8th, 2004, 11:47 am

I have also encountered the same problem except the file logged is named _update.exe. Did you find a solution to deleting this file?
  • Vladdrac
  • Mastermind
  • Mastermind
  • User avatar
  • Joined: Feb 04, 2004
  • Posts: 2136
  • Loc: Louisville, Ky
  • Status: Offline

Post June 8th, 2004, 11:49 am

well I hadn't found any other issues since I deleted said files
  • plc_spec
  • Born
  • Born
  • No Avatar
  • Joined: Jun 08, 2004
  • Posts: 4
  • Status: Offline

Post June 8th, 2004, 12:03 pm

I am unable to delete this file at all....it just keeps coming back as soon as it's deleted.
  • ATNO/TW
  • Super Moderator
  • Super Moderator
  • User avatar
  • Joined: May 28, 2003
  • Posts: 23407
  • Loc: Woodbridge VA
  • Status: Offline

Post June 8th, 2004, 12:28 pm

You have to disable system restore first if you are on XP or ME.
"There's no place like 127.0.0.1 except for ::1."
Alexandria Networks. Leader in IT consulting for associations/non-profits, and small to medium sized businesses around the northern Virginia and Washington D.C. metro area.
  • plc_spec
  • Born
  • Born
  • No Avatar
  • Joined: Jun 08, 2004
  • Posts: 4
  • Status: Offline

Post June 8th, 2004, 12:44 pm

thanks for the reply...I am using 98SE...does anything need to be disabled for this?
  • ATNO/TW
  • Super Moderator
  • Super Moderator
  • User avatar
  • Joined: May 28, 2003
  • Posts: 23407
  • Loc: Woodbridge VA
  • Status: Offline

Post June 8th, 2004, 1:10 pm

No, not with 98. Have you run virus scan on it and let that catch it?
"There's no place like 127.0.0.1 except for ::1."
Alexandria Networks. Leader in IT consulting for associations/non-profits, and small to medium sized businesses around the northern Virginia and Washington D.C. metro area.
  • plc_spec
  • Born
  • Born
  • No Avatar
  • Joined: Jun 08, 2004
  • Posts: 4
  • Status: Offline

Post June 8th, 2004, 1:30 pm

Yes...I'm using PC-cillin. It quarantines the file and as soon as I clean it the file comes right back. Pretty frustrating.

Post Information

  • Total Posts in this topic: 10 posts
  • Users browsing this forum: No registered users and 109 guests
  • You cannot post new topics in this forum
  • You cannot reply to topics in this forum
  • You cannot edit your posts in this forum
  • You cannot delete your posts in this forum
  • You cannot post attachments in this forum
 
 

© 2011 Unmelted, LLC. Ozzu® is a registered trademark of Unmelted, LLC.