Wilders Security Forums  

Go Back   Wilders Security Forums > Archived Forums > Closed Sub-Forums > Archived ESET Support Forums > NOD32 version 2 Forum
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old July 25th, 2008, 11:23 AM
Mister Natural's Avatar
Mister Natural Mister Natural is offline
Frequent Poster
 
Join Date: May 2007
Location: 3rd density St. Louis
Posts: 225
Default Info on Win32/Spy.Agent.NES trojan

I would like more information on a recent activity log I received from a user's computer.

First I am unable to learn anything about this particular threat, what it is, what is does, etc.

Second, as you can see I am unable to determine the location of the attempted infection. It says "invalid_name". If I knew more info on this particular malware I might know where to look for it.

My biggest concern are the dates listed. It looks like it was detected during computer shutdown and again when the computer was booted the following morning. My concern is that something has infected the computer and is now being detected, but unable to remove. I am unable to reboot the computer at this time and will have to wait to see if this situation repeats itself.

Any feedback appreciated.

Column Name Value
Alert Id Alert 548
Client Name ******
Primary Server xxx.xxx.xxx.xxx
Date 2008-07-24 16:07:47
Received 2008-07-25 06:52:46
Module IMON
Object archive
Virus Win32/Spy.Agent.NES trojan
Name invalid_name
Action connection terminated
Info
Log Details Ready
Comment

Log Details
invalid_name
invalid_name »ZIP »INVOICE_8712.exe - Win32/Spy.Agent.NES trojan
  #2  
Old July 25th, 2008, 04:44 PM
BFG BFG is offline
Frequent Poster
 
Join Date: Oct 2004
Location: San Diego
Posts: 482
Default Re: Info on Win32/Spy.Agent.NES trojan

Hello,

When IMON terminates the connection as it did in your case, it was stopped before it got on the machine.

BFG
 

Wilders Security Forums > Archived Forums > Closed Sub-Forums > Archived ESET Support Forums > NOD32 version 2 Forum « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 12:02 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums