PDA

View Full Version : Did I get attacked today? Am I safe?


ejr
December 29th, 2006, 12:13 PM
I looked in the threat log today and saw the following:

Time Module Object Name Threat Action User Information
12/29/2006 6:49:50 AM AMON file C:\WINDOWS\system32\wextract.exe Win32/TrojanDropper.Agent.NDN trojan error while cleaning - operation unavailable for this type of object GMPASSOCIATES\Owner Event occurred at an attempt to access the file by the application: C:\Program Files\Spyware Doctor\swdoctor.exe.
12/29/2006 6:48:36 AM AMON file C:\WINDOWS\system32\dllcache\wextract.exe Win32/TrojanDropper.Agent.NDN trojan error while cleaning - operation unavailable for this type of object GMPASSOCIATES\Owner Event occurred at an attempt to access the file by the application: C:\Program Files\Spyware Doctor\swdoctor.exe.
12/29/2006 6:47:24 AM AMON file C:\WINDOWS\ServicePackFiles\i386\wextract.exe Win32/TrojanDropper.Agent.NDN trojan error while cleaning - operation unavailable for this type of object GMPASSOCIATES\Owner Event occurred at an attempt to access the file by the application: C:\Program Files\Spyware Doctor\swdoctor.exe.
12/29/2006 6:41:30 AM AMON file C:\Program Files\Windows Media Connect\Redist\wmfdist95.exe Win32/TrojanDropper.Agent.NDN trojan error while cleaning - operation unavailable for this type of object GMPASSOCIATES\Owner Event occurred at an attempt to access the file by the application: C:\Program Files\Spyware Doctor\swdoctor.exe.

ASpace
December 29th, 2006, 12:16 PM
Hi ejr !

Here (http://www.wilderssecurity.com/showthread.php?t=159698) is a current discussion about a possible false positive about the same trojan


I would suggest you configure as per Blackspear's tutorial , make sure NOD32 will make a copy to the Quarantine and then perform full Scan & Clean from Control Center -> NOD32 -> Run NOD32 :thumb:

ASpace
December 29th, 2006, 12:24 PM
Sorry , erj !

It was definitely a false positive . It is now fixed :)

MaB69
December 29th, 2006, 01:32 PM
Hi all,

Yes a big FP fixed by 1946
Detected bitdefender 8 installer as Win32/TrojanDropper.Agent.NDN too

MaB69

Bubba
December 29th, 2006, 01:36 PM
-{ Quote: "Here (http://www.wilderssecurity.com/showthread.php?t=159698) is a current discussion about a possible false positive about the same trojan" }-Indeed and We will continue the discussion there with any further questions.

Nod32 & wextract.exe (http://www.wilderssecurity.com/showthread.php?t=159691)

Bubba