I am finding more about the virus BKDR_AGENT.YWQ :
- The file that was the detected by the antivirus was the following: C:\Windows\system32\8cbf9856.dll
- Service running: BE812AAC = C:\Windows\System32\C5A3BFDE.EXE
- Registry: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BE812AAC and few entries more.
I have removed the file and all the registry entries with that reference (BE812AAC) on Safe Mode (System Restore Off).
Anyway, the registry entries are created again. I cannot find the file C:\Windows\System32\C5A3BFDE.EXE that is supposed the service executes.
The trojan tries to send some info to a chinese webiste: http://alexa.veryinx.cn
I will keep finding but I hope someone can give me a hand ;-)
Thanks!!
*---------------------------------------------------------------------------------*
First post
*---------------------------------------------------------------------------------*
Hi,
My dear antivirus (Trend Micro's PC-Cillin) has found a virus once the computer was infected and now it cannot delete it. The virus is BKDR_AGENT.YWQ but I cannot find any information in Internet about it.
The file infected is C:\Windows\system32\8cbf9856.dll. I can delete it in safe mode but obviously it comes back when I restart the computer.
Any help?
Much appreciated!
HJT log attached.
- The file that was the detected by the antivirus was the following: C:\Windows\system32\8cbf9856.dll
- Service running: BE812AAC = C:\Windows\System32\C5A3BFDE.EXE
- Registry: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BE812AAC and few entries more.
I have removed the file and all the registry entries with that reference (BE812AAC) on Safe Mode (System Restore Off).
Anyway, the registry entries are created again. I cannot find the file C:\Windows\System32\C5A3BFDE.EXE that is supposed the service executes.
The trojan tries to send some info to a chinese webiste: http://alexa.veryinx.cn
I will keep finding but I hope someone can give me a hand ;-)
Thanks!!
*---------------------------------------------------------------------------------*
First post
*---------------------------------------------------------------------------------*
Hi,
My dear antivirus (Trend Micro's PC-Cillin) has found a virus once the computer was infected and now it cannot delete it. The virus is BKDR_AGENT.YWQ but I cannot find any information in Internet about it.
The file infected is C:\Windows\system32\8cbf9856.dll. I can delete it in safe mode but obviously it comes back when I restart the computer.
Any help?
Much appreciated!
HJT log attached.