AVG Virus Vault has trojans in it

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Denise_M, Nov 29, 2006.

  1. Denise_M

    Denise_M MajorGeek

    Hi,

    I downloaded a program and wanted to make sure it was virus free, so I ran an AVG scan of the folder where I put the program. The scan results said that there were no viruses in the program.

    Out of curiosity, I clicked on the virus vault tab and saw that there are 4 trojans in it:


    1. Trojan horse Downloader.Agent.GPZ, detected on 10/31/06. The path was C:\Windows\system32\ActiveScan\Sporder.dll
    Healable: No
    Source: Backup Copy
    Status: Infected

    2. Trojan horse Dropper.Agent.BMH, detected on 10/11/06. The path was C:\ProgramFiles\Setup\Setup.exe
    Healable: No
    Source: Backup Copy
    Status: Infected

    3. Trojan horse Generic2.DNV, detected on 10/9/06. The path was C:\Document and Settings\owner\Local Settings\Temporary Internet Files\Content.IE5GDAFCLMF\FU-Setup_LE(1).exe
    Healable: No
    Source: Backup Copy
    Status: Infected

    4. Trojan horse Downloaded.Agent.GPZ, detected on 10/31/07. The path was C:\System Volume Information\_restore{61EFFF9C-29EB-4676-87D2-D2E4374E4620}\RP172\A0043363.dll
    Healable: No
    Source: Backup Copy
    Status: Infected

    I've never looked inside the virus vault and didn't know that AVG had found trojans. I'm sure that I'm supposed to delete them, so that's not my concern. What I'm concerned about is the last 3 lines of each virus, Healable, Source and Status. I can read that information 2 ways. It could mean that even after I delete them, my pc will continue to suffer the consequences of having them in my pc, or that the trojan can't be healed but once I delete them, my pc will be completely free of any damage that they could have caused.

    I exported a report of the contents in the Virus Vault as tab delimited. I wasn't sure if that's the type of file you need in order to convert it back to html so I typed the info above, but I'm attaching the tab deliminted file also.

    I also export the test result of the virus scan of the folder that I saved the mpg to avi conversion program and saved it as tab delimited, and I've attached this file as well.

    If you need to see these reports in a different format, just let me know. I won't delete the trojans until I hear from you either.

    I don't understand why these trojans are getting past Sygate Firewall.
     
  2. Denise_M

    Denise_M MajorGeek

    Ok, I was smart . . . I forgot to attach the files in my first post but when I tried to attach them as *.tab, they weren't accepted so I saved the AVG Test Result to a .txt document. Again, if another type of file is preferable, just let me know.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Item 1 is a false positive. That file is for PandaActiveScan.
    Item 2 may or may not be malware. But it is very suspect to just have a folder named Setup and then a file named setup.exe in that folder.
    Item 3 was just an item in your IEcache that could simply have been deleted by emptying your cache.
    Item 4 is in System Restore which can only be removed by disabling system restore.
     
    Last edited: Nov 30, 2006
  4. Denise_M

    Denise_M MajorGeek

    Hi, Thanks for the info Chaslang. :)
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds