Did I get attacked today? Am I safe?

Discussion in 'NOD32 version 2 Forum' started by ejr, Dec 29, 2006.

Thread Status:
Not open for further replies.
  1. ejr

    ejr Registered Member

    Joined:
    Nov 19, 2005
    Posts:
    538
    I looked in the threat log today and saw the following:

    Time Module Object Name Threat Action User Information
    12/29/2006 6:49:50 AM AMON file C:\WINDOWS\system32\wextract.exe Win32/TrojanDropper.Agent.NDN trojan error while cleaning - operation unavailable for this type of object GMPASSOCIATES\Owner Event occurred at an attempt to access the file by the application: C:\Program Files\Spyware Doctor\swdoctor.exe.
    12/29/2006 6:48:36 AM AMON file C:\WINDOWS\system32\dllcache\wextract.exe Win32/TrojanDropper.Agent.NDN trojan error while cleaning - operation unavailable for this type of object GMPASSOCIATES\Owner Event occurred at an attempt to access the file by the application: C:\Program Files\Spyware Doctor\swdoctor.exe.
    12/29/2006 6:47:24 AM AMON file C:\WINDOWS\ServicePackFiles\i386\wextract.exe Win32/TrojanDropper.Agent.NDN trojan error while cleaning - operation unavailable for this type of object GMPASSOCIATES\Owner Event occurred at an attempt to access the file by the application: C:\Program Files\Spyware Doctor\swdoctor.exe.
    12/29/2006 6:41:30 AM AMON file C:\Program Files\Windows Media Connect\Redist\wmfdist95.exe Win32/TrojanDropper.Agent.NDN trojan error while cleaning - operation unavailable for this type of object GMPASSOCIATES\Owner Event occurred at an attempt to access the file by the application: C:\Program Files\Spyware Doctor\swdoctor.exe.
     
  2. ASpace

    ASpace Guest

    Hi ejr !

    Here is a current discussion about a possible false positive about the same trojan


    I would suggest you configure as per Blackspear's tutorial , make sure NOD32 will make a copy to the Quarantine and then perform full Scan & Clean from Control Center -> NOD32 -> Run NOD32 :thumb:
     
  3. ASpace

    ASpace Guest

    Sorry , erj !

    It was definitely a false positive . It is now fixed :)
     
  4. MaB69

    MaB69 Registered Member

    Joined:
    Dec 9, 2005
    Posts:
    540
    Location:
    Paris
    Hi all,

    Yes a big FP fixed by 1946
    Detected bitdefender 8 installer as Win32/TrojanDropper.Agent.NDN too

    MaB69
     
  5. Bubba

    Bubba Updates Team

    Joined:
    Apr 15, 2002
    Posts:
    11,271
    Indeed and We will continue the discussion there with any further questions.

    Nod32 & wextract.exe

    Bubba
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.