PDA

View Full Version : win32.agent.pz



pkarvani
2008-05-06, 18:31
Hello,

I had a serious problem with my laptop couple of days. I can not open any program because an error window says that "c:/program files/....exe" is not an invalid acess. My mcafee antivirus is disabled. my firewall too. I had spybot I ran it it found win32.agent.pz. I dont have the software in my system any more... I just can save a repot of its scan... I download various remover programs(such as sdfix...) but none of them worked even in safe mode...

I will appreciate if any one can help...

--- Search result list ---
Win32.Agent.pz: Settings (Registry value, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit=...C:\WINDOWS\system32\ntos.exe,...

Win32.Agent.pz: Program directory (Directory, nothing done)
C:\WINDOWS\system32\wsnpoem\

Win32.Agent.pz: Library (File, nothing done)
C:\WINDOWS\system32\wsnpoem\audio.dll

Win32.Agent.pz: Library (File, nothing done)
C:\WINDOWS\system32\wsnpoem\video.dll


--- Spybot - Search & Destroy version: 1.4 (build: 20050523) ---

2005-05-31 blindman.exe (1.0.0.1)
2005-05-31 SpybotSD.exe (1.4.0.3)
2005-05-31 TeaTimer.exe (1.4.0.2)
2007-10-08 unins000.exe (51.41.0.0)
2005-05-31 Update.exe (1.4.0.0)
2007-05-23 advcheck.dll (1.5.3.0)
2005-05-31 aports.dll (2.1.0.0)
2005-05-31 borlndmm.dll (7.0.4.453)
2005-05-31 delphimm.dll (7.0.4.453)
2005-05-31 SDHelper.dll (1.4.0.0)
2007-07-31 Tools.dll (2.1.2.0)
2005-05-31 UnzDll.dll (1.73.1.1)
2005-05-31 ZipDll.dll (1.73.2.0)
2007-10-04 Includes\Cookies.sbi (*)
2007-07-25 Includes\Dialer.sbi (*)
2007-10-04 Includes\DialerC.sbi (*)
2007-08-29 Includes\Hijackers.sbi (*)
2007-10-04 Includes\HijackersC.sbi (*)
2007-10-04 Includes\Keyloggers.sbi (*)
2007-10-04 Includes\KeyloggersC.sbi (*)
2004-11-29 Includes\LSP.sbi (*)
2007-10-04 Includes\Malware.sbi (*)
2007-10-04 Includes\MalwareC.sbi (*)
2007-09-05 Includes\PUPS.sbi (*)
2007-10-04 Includes\PUPSC.sbi (*)
2007-10-04 Includes\Revision.sbi (*)
2007-05-30 Includes\Security.sbi (*)
2007-10-04 Includes\SecurityC.sbi (*)
2007-09-12 Includes\Spybots.sbi (*)
2007-10-04 Includes\SpybotsC.sbi (*)
2007-08-21 Includes\Tracks.uti
2007-10-04 Includes\Trojans.sbi (*)
2007-10-04 Includes\TrojansC.sbi (*)
2007-06-06 Plugins\TCPIPAddress.dll


http://forums.spybot.info/showthread.php?t=27737

spybotsandra
2008-05-07, 11:02
Hello,

You seem to be using a dated version of Spybot-S&D.
Please download our current version Spybot - Search & Destroy 1.5.2. That should fix it.
You will find links to several download locations for this new version on our web site:
http://www.safer-networking.org/en/mirrors/index.html
Please search for new updates after installing Spybot-S&D 1.5.2.

Best regards
Sandra
Team Spybot

Pleasekillthisvirus
2008-07-18, 16:16
I updated spybot as much as possible as far as i can see, and i am still having problems with this virus. spybot detects it, and deletes most of it, but can't kill the directory it seems, and then asks to run after a restart. i say yes, and then not only does it not run but it has all the virus back again. further,it keeps asking me about userinit, whihc i denyed as a change to winlogon and said to remember, and now the the edge of my screen is filled with denyed messages as long as i am plug into the internet. are there any solutions you could suggest, such as manual deletion or regedit changes? thank,

pleasekillthisvirus

md usa spybot fan
2008-07-18, 17:35
Pleasekillthisvirus:

Consider posting in the Malware Removal (http://forums.spybot.info/forumdisplay.php?f=22) forum and having someone take a look at your system.

If you decide to have an experienced malware removal specialist assist you, please follow the procedure in this link to run scans and produce a HijackThis log: "BEFORE you POST"(READ this Procedure BEFORE Requesting Assistance) ( http://forums.spybot.info/showthread.php?t=288).
After you have completed the required scans and produced the requested logs, start your own thread in the Malware Removal (http://forums.spybot.info/forumdisplay.php?f=22) forum, making sure to post the HijackThis log produced from the above instructions.