Welcome to Tech Support Forum home to more then 136,000 problems solved. Issues have included: Spyware, Malware, Virus Issues, Windows, Microsoft, Linux, Networking, Security, Hardware, and Gaming Getting your problem solved is as easy as:
1. Registering for a free account
2. Asking your question
3. Receiving an answer

Registered members:
* Get free support
* Communicate privately with other members (PM).
* Removal of this message
* See fewer ads.
* And much more..

 



Want to know how to post a question? click here Having problems with spyware and pop-ups? First Steps
Go Back   Tech Support Forum > Security Center > General Computer Security
User Name
Password
Site Map Register Donate Rules Blogs Mark Forums Read


General Computer Security Get Help With System Security - This forum is not for malware removal assistance. For malware removal assistance, read the sticky topic at the top of the Virus/Trojan/Spyware Help forum, or the "First Steps" link at the top right of each page.

Closed Thread
 
LinkBack Thread Tools
Old 10-14-2007, 07:41 PM   #1 (permalink)
Wox
TSF Enthusiast
 
Wox's Avatar
 
Join Date: Jan 2007
Location: Seattle
Posts: 638
OS: XP Pro SP2

My System

[SOLVED] C:\autorun.inf keeps on getting detected by Nod32 (W32/PSW.Agent. NDP trojan

This is happening on a XP laptop with Nod32 as antivirus (duh!)
A few minutes after logging on Nod pops up saying C:\autorun.inf is infected (Win32/PSW.Agent.NDP trojan).
I chose to delete the file and it pops back up.
Looks like either
[1] Nod is finding a sytem file (keeps on regenerating) as false positive
[2] I'm infected by a weird trojan

I would be doing some online scanning and stuff, will be creating a thread in HJT forum.
For now can someone tell me what they know please...
Wox is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Important Information
Join the #1 Tech Support Forum Today - It's Totally Free!

TechSupportForum.com is a leading support website for your computer needs. We offer free, friendly and personalized computer support. Why pay to have your computer fixed when you can do it for free.

Join TechSupportforum.com Today - Click Here

Old 10-14-2007, 08:20 PM   #2 (permalink)
Moderator, Microsoft Support
 
Go The Power's Avatar
 
Join Date: Mar 2007
Location: South Australia
Posts: 10,981
OS: Windows XP Home SP2


Blog Entries: 1
Send a message via MSN to Go The Power Send a message via Skype™ to Go The Power
Re: C:\autorun.inf keeps on getting detected by Nod32 (W32/PSW.Agent. NDP trojan)

Hiya Wox

Here is some information:
http://www.sophos.com/security/analy...legmiraqk.html
__________________


Go The Power is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 10-14-2007, 08:50 PM   #3 (permalink)
Wox
TSF Enthusiast
 
Wox's Avatar
 
Join Date: Jan 2007
Location: Seattle
Posts: 638
OS: XP Pro SP2

My System

Re: C:\autorun.inf keeps on getting detected by Nod32 (W32/PSW.Agent. NDP trojan)

Hi GTP, thanks for the info, but I still don't know how to get rid of it.. :

EDIT: I seemed to have found one.
Can anybody "review" the info that I found and tell me if that solves it?

Quote:
Originally Posted by alpha (simplified and translated by me)
1. Turn off System Restore.
2. Clean out all the temp files.
3. Using regedit, search for and delete all the entries for these- [c0nime.exe 、iexpl0re.exe 、winlog0n.exe, rundl132]
4. Delete the following files with Killbox-
Code:
C:\\DOCUME~1\\[user]\\LOCALS~1\\Temp\\Rav20.dll      
                                    C:\\DOCUME~1\\[user]\\LOCALS~1\\Temp\\Rav21.dll  
                                               C:\\DOCUME~1\\[user]\\LOCALS~1\\Temp\\Gjzo0.dll    
                                             C:\\DOCUME~1\\[user]\\LOCALS~1\\Temp\\LgSy2.dll   
                                              C:\\DOCUME~1\\[user]\\LOCALS~1\\Temp\\LgSy1.dll   
                                              C:\\DOCUME~1\\[user]\\LOCALS~1\\Temp\\rundl132.exe   
                                              C:\\DOCUME~1\\[user]\\LOCALS~1\\Temp\\c0nime.exe    
                                             C:\\DOCUME~1\\[user]\\LOCALS~1\\Temp\\iexpl0re.exe      
                                           C:\\DOCUME~1\\[user]\\LOCALS~1\\Temp\\winlog0n.exe
5. Reboot and re-enable System Restore.
Thanks

P.S. by "simplified and translated" I mean by removing all the instructions on downloading Killbox, turning off System Restore, running regedit, etc etc; then I translated it from Chinese to English.

Last edited by Wox; 10-14-2007 at 09:04 PM.
Wox is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 10-15-2007, 05:24 PM   #4 (permalink)
Wox
TSF Enthusiast
 
Wox's Avatar
 
Join Date: Jan 2007
Location: Seattle
Posts: 638
OS: XP Pro SP2

My System

Re: C:\autorun.inf keeps on getting detected by Nod32 (W32/PSW.Agent. NDP trojan)

Alright, no need to confirm that anymore you guys, cos it ain't working.
Seems like Nod32 is really worked up, today it found W32/Pacex.Gen on C:\ntdelect.com and www.microsofttw.com/gto/ubs.exe. Seems like some website is trying to feed me viruses?
Doing scans right now.
Wox is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 10-15-2007, 06:09 PM   #5 (permalink)
Wox
TSF Enthusiast
 
Wox's Avatar
 
Join Date: Jan 2007
Location: Seattle
Posts: 638
OS: XP Pro SP2

My System

Re: C:\autorun.inf keeps on getting detected by Nod32 (W32/PSW.Agent. NDP trojan)

Jeez.. spent some 35 minutes on this issue and finally got it solved.
Turned out to be a Kavo virus, directions on solving here and the final Kava killer here..
Kava is also known to spread via USB drives, and the killer for that is here
Be nice to Chinese (and Taiwanese) people- they apparently know a lot..
Wox is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 10-15-2007, 09:36 PM   #6 (permalink)
Wox
TSF Enthusiast
 
Wox's Avatar
 
Join Date: Jan 2007
Location: Seattle
Posts: 638
OS: XP Pro SP2

My System

Re: C:\autorun.inf keeps on getting detected by Nod32 (W32/PSW.Agent. NDP trojan)

This thread is solved, and I might write a short guide on using five important tools (that I gathered) to get rid of it... I just might.
Wox is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Closed Thread


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off




All times are GMT -7. The time now is 08:23 AM.



Copyright 2001 - 2009, Tech Support Forum
Home Tips Plus | Outdoor Basecamp | Automotive Support Forum

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85