Help - Search - Members
Full Version: Trojan-Spy.Win32.Agent.avvk
Kaspersky Lab Forum > English User Forum > Virus-related issues
m.alhebshi
Hi All,

This is my first time to be here ... To be focus on the subject I discover Trojan-Spy.Win32.Agent.avvk and I discover that Kasper cann't remove it and that torjan is impacting our network and speared to another machines by days.

DANGEROUS OBJECTS : client32.exe\ pcihooks.dll EXCEL.EXE\ pcihooks.dll winlogon.exe\ pcihooks.dll

I need your highly attention and help to remove it

BR,

m.alhebshi
phr3n1c
Please specify the name and version of Kaspersky product for example Kaspersky Anti-Virus for Windows Workstations 6.0.3.837.
And please attach here the report file of GetSystemInfo utility, upload that file on http://support.kaspersky.fr/getsysteminfo/ and post the link of that report here.

Please attach the zipped virusinfo_syscure.zip; instructions, see: http://forum.kaspersky.com/index.php?s=&am...st&p=678334
Amazing Kaspersky Programs
QUOTE(m.alhebshi @ 14.06.2009 18:38) *
Hi All,

This is my first time to be here ... To be focus on the subject I discover Trojan-Spy.Win32.Agent.avvk and I discover that Kasper cann't remove it and that torjan is impacting our network and speared to another machines by days.

DANGEROUS OBJECTS : client32.exe\ pcihooks.dll EXCEL.EXE\ pcihooks.dll winlogon.exe\ pcihooks.dll

I need your highly attention and help to remove it

BR,

m.alhebshi

I have a customer complaining about the same problem unsure.gif
Caos
Please attach the zipped virusinfo_syscure.zip; instructions, see: http://forum.kaspersky.com/index.php?s=&am...st&p=678334
m.alhebshi
Thanks All for your attention Please check the attached file

BR,

m.alhebshi
m.alhebshi
QUOTE(Caos @ 15.06.2009 12:05) *
Please attach the zipped virusinfo_syscure.zip; instructions, see: http://forum.kaspersky.com/index.php?s=&am...st&p=678334

m.alhebshi
QUOTE(phr3n1c @ 15.06.2009 07:44) *
Please specify the name and version of Kaspersky product for example Kaspersky Anti-Virus for Windows Workstations 6.0.3.837.
And please attach here the report file of GetSystemInfo utility, upload that file on http://support.kaspersky.fr/getsysteminfo/ and post the link of that report here.

Please attach the zipped virusinfo_syscure.zip; instructions, see: http://forum.kaspersky.com/index.php?s=&am...st&p=678334



The Product is Kaspersky Business Space (Admin Kit + Kasper for WindowsWorkStation latest version 6.0.3.837)

This virus in 6 systems now we are uptodate and even after restart it apears again
Amazing Kaspersky Programs
I had the same problem with cutomer, and i solve it by adding Net Support program to trusted zone

It seems like false positive as I think.
Caos
Files for review:

The possible infected file client32.exe\ pcihooks.dll EXCEL.EXE\ pcihooks.dll winlogon.exe\ pcihooks.dll
C:\WINDOWS\system32\AIBMRUNL.dll
C:\WINDOWS\system32\pwdmon.dll
NAVAPEL.sys

Upload this files to http://www.rapidshare.com o http://www.megaupload.com compressed with winrar and password protected "infected" (without "") and send me a private message with the download link.

Also upload screenshot of Detected > Active threats , Quarantine, Backup, All detected malware (with the complete route of the detection).

This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2009 Invision Power Services, Inc.