Question

AVG Anti-Virus Free Edition will not totally remove Trojan horse Agent_r.OT from pc

Asked by: GMartin

Hi Everyone;

         Despite of repeated instances of moving a Trojan horse Agent_r.OT to the Virus Vault and emptying it, this infection keeps reappearing especially especially at restart of the pc or from a cold boot.  The message given by AVG is Trojan horse Agent_r.OT at c:\windows\system32\tdlwsp.dll was detected.  And, of course, one of the options I am given is to Move To Virus Vault.   Figuring that is the best choice, I simply move it to the Virus Vault and empty it.  Unfortunately, it does reappear when the pc is restarted in any way.

          Is there a way I can permanently remove this infection without doing any kind of wipe and reload?  Outside of this alarming message given by AVG, this pc is fully functional in everyway with no detectable damage or at least not yet.

          Any help to this question will be appreciated.  I will look forward to trying out any recommended suggestions or troubleshooting strategies.

          Thank you.

          George

This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.

Subscribe now for full access to Experts Exchange and get

Instant Access to this Solution

  • Plus...
  • 30 Day FREE access, no risk, no obligation
  • Collaborate with the world's top tech experts
  • Unlimited access to our exclusive solution database
  • Never be left without tech help again

Subscribe Now

Asked On
2009-11-06 at 21:35:35ID24879993
Topics

AVG

,

Security Utilities

Participating Experts
4
Points
500
Comments
20

Trusted by hundreds of thousands everyday for fast, accurate and reliable tech support.

  • "The time we save is the biggest benefit of Experts Exchange to Warner Bros. What could take multiple guys 2 hours or more each to find is accessed in around 15 minutes on Experts Exchange." Mike Kapnisakis, Warner Bros.
  • "Our team likes having a resource that is more secure than just using Google and most experts using this service really know their stuff. It's nice to look here first versus using Google." Dayna Sellner, Lockheed Martin
  • "Anytime that I've been stumped with a problem, 9 out of 10 times Experts Exchange has either the accepted solution or an open discussion of the potential solution to the problem." Kenny Red, eBay Inc.

See what Experts Exchange can do for you.

Got a question?

We've got the answer.

Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.

Screenshot of Experts Exchange Knowledgebase

Need individual assistance?

Our experts are ready to help.

If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.

Screenshot of Experts Exchange Knowledgebase

Want to learn from the best?

Read articles from industry experts.

Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.

Screenshot of an Article

Working on a long term project?

Store your work and research.

Save solutions to your questions, answers you’ve discovered through searching plus helpful articles in your personal knowledgebase for easy future access.

Screenshot of Experts Exchange Knowledgebase

Access the answers to your technology questions today.

Subscribe Now

30-day free trial. Register in 60 seconds.

What Makes Experts Exchange Unique?

Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Trusted by the world's most respected brands.

image of each brand's logo

Faithfully serving IT professionals since 1996.

Experts Exchange Logo

Try it out and discover for yourself.

Subscribe Now

30-day free trial. Register in 60 seconds.

Related Solutions

  1. Trojan Horse
    I have Trojan Horse on my computer I have deleted all the files in Quarinetine, but still the virus is on how can I get rid of if without reinstalling Windows. I have Window 2000 on my computer
  2. Trojan Horse Clicker.5.AP  / AVG
    I have one persistent virus identified and cleaned by AVG.....Trojan Horse Clicker.5.AP which is consistently found in Windows Temp/TMP AD5.TMP. Sometimes the TMP description changes but always found in the Temp Directroy. System XP Professional - have recanned in Safe Mode...
  3. AVG Finds: Trojan horse Downloader.Generic3.OAE
    AVG 7.5 running under Win XP finds: Trojan horse Downloader.Generic3.OAE I'm not sure if AVG can heal this as I can find no real info on what it actually is. Any help would be appreciated.
  4. Trojan horse BackDoor.Generic7.QQK virus - AVG del…
    AVG 7.5 keeps deleting a Trojan horse BackDoor.Generic7.QQK virus, file: c:\windows\temp\startdrv.exe. On reboot it comes back, and AVG deletes it again. I've run a full scan with SuperAntiSpyware. It found and corrected a bunch of items, including 2 trojan download files. Ho...

Free Tech Articles

  1. WARNING: 5 Reasons why you should NEVER fix a computer for free.
    It is in our nature to love the puzzle. We are obsessed. The lot of us. We love puzzles. We love the challenge. We thrive on finding the answer. We hate disarray. It bothers us deep in our soul. W...
  2. SCCM OSD Basic troubleshooting
    SCCM 2007 OSD is a fantastic way to deploy operating systems, however, like most things SCCM issues can sometimes be difficult to resolve due to the sheer volume of logs to sift through and the dispe...
  3. Migrate Small Business Server 2003 to Exchange 2010 and Windows 2008 R2
    This guide is intended to provide step by step instructions on how to migrate from Small Business Server 2003 to Windows 2008 R2 with Exchange 2010. For this migration to work you will need the fo...
  4. Create a Win7 Gadget
    This article shows you how to create a simple "Gadget" -- a sort of mini-application supported by Windows 7 and Vista. Gadgets can be dropped anywhere on the desktop to provide instant information, ...
  5. Outlook continually prompting for username and password
    There have been a lot of questions recently regarding Outlook prompting for a username and password whilst using Exchange 2007. There are a few reasons why this would happen and I will try to cover t...
  6. Backup Exchange 2010 Information Store using Windows Backup
    There seems to be quite a lot of confusion around the ability to backup Exchange 2010 using the built in Windows Backup feature. This stems from the omission of this feature prior to Exchange 2007 s...

Cloud Class Webinars

  1. Avoiding Bugs in Microsoft Access
    Alison Balter takes and in-depth look at avoiding bugs in Access. In this webinar you will learn about using the immediate window to debug your applications, invoking the debugger, using breakpoints to troubleshoot, stepping through code, setting the next statement to execute, ...
  2. Top 10 Best New Features in Visio 2010
    Scott Helmers gives live demonstrations of the top 10 new features in Visio 2010. This webinar will teach you how to create compelling diagrams by adding shapes to the page with a single click, linking the shapes in a diagram to data in Excel (or SQL Server, or SharePoint), ...
  3. IT Consultant Business Secrets Revealed
    Michael Munger, Experts Exchange tech pro and IT consultant, pulls back the curtain on his very successful businesses and answers question on every IT consultant and business owner should know about. He shares secrets on what he did to solve the 5 most common problems in IT, ...
  4. Disaster Recovery and Business Continuity
    Quest CTO, Mike Billon, gives an overview of the steps involved in building a dunamic disaster recovery plan. Through case studies and an examination of software/hardware tooles for monitoring and testing, you'll gain a better understandin of where you are, where you want ...
  5. Organize Your Visio Diagrams with Containers and Lists
    Scott Helmers uses cross functional flowcharts, wireframe diagrams, data graphic legends and seating charts to teach you: how to ustilize all three new structured diagram components in Visio 2010, the best practices for organizeing shapes in previous version of Visio, how to organize ...
  6. How to Us Objects, Properties, Events and Methods in Microsoft Access
    Alison Dalter gives an in-depbth look at objects, properties, events and methods in Microsoft Access. In this webinar you will learn about using the object browser, referring to objects, working with properties and methods, working with object variables, understanding the ...

Join the Community

Give a Little. Get a Lot.

Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.

Join the Community

Answers

 

by: jeff_01Posted on 2009-11-06 at 22:52:34ID: 25765237

I would suggest running Spybot in conjunction with AVG to get rid of the problem.

Spybot Website

Install Spybot SD and make sure to download update files. Immunize the pc and then Run a full system scan. Then remove any nasties found. Once you have done that then run AVG and let it remove anything it finds as well. Once both programs report nothing theneverything should be fine. As a last check, once you have rebooted run both programs again to verify that the Trojan is gone.



 

by: samithsukumarPosted on 2009-11-06 at 23:43:53ID: 25765358

Do a full scan with malwarebytes. Update it before going for a scan

Ref:

http://www.malwarebytes.org/

 

 

by: tmoore1962Posted on 2009-11-07 at 10:01:28ID: 25767287

Yes run a malwarebytes scan, but also turn off your system restore temporarily and delete the contents of the windows\prefetch folder then scan with malwarbytes and AVG.

 

by: GMartinPosted on 2009-11-07 at 16:52:40ID: 25768870

Hi Everyone;

         I am in the process of getting all of the suggested tools in place to install and update before running.  Just out of curiousity, what is normally stored in the c:\windows\prefetch folder?

          Thank you.

          George

 

by: optomaPosted on 2009-11-08 at 02:16:25ID: 25770016

Hi again George!
About prefetch
http://windows.microsoft.com/en-US/windows-vista/What-is-the-prefetch-folder

Run Atf cleaner to clear temp files-Select "select all" button http://www.atribune.org/index.php?option=com_content&task=view&id=25&Itemid=25

Try running this cloud based scanner to see if it removes that nasty
http://www.surfright.nl/en/hitmanpro (you can uninstall it after a restart)

 

by: GMartinPosted on 2009-11-08 at 15:49:50ID: 25772611

Hi

        The link certainly explained the prefetch folder in an easy to understand fashion.  With regards to the program Atf Cleaner, I have been using CCleaner.  Is that program just as good or will I need to still ust Atf Cleaner?  

        Thank you.

        George

 

by: optomaPosted on 2009-11-08 at 16:05:36ID: 25772656

No harm in running it. Its an executable so dosn't install on system :)

 

by: GMartinPosted on 2009-11-09 at 10:58:36ID: 25778816

Hi

         Just to update on this post, the infection, Trojan horse Agent_r.OT at c:\windows\system32\tdlwsp.dll, kept recurring despite of removal by AVG.  I also used Malwarebytes in addition to SpyBot Search & Destroy which both found other infections and removed them as well.  The recurring one, Trojan horse Agent_r.OT at c:\windows\system32\tdlwsp.dll, was also detected and removed by Hitmanpro.  So far, this infection has not come back upon restart.  

          Due to the frequent reocurrence of this infection, I would like to wait a day or two just to make sure it is completely gone.  It appears the battery of anti-malware utilities might have gotten rid of it.  

          At any rate, I will be back in touch with everyone regarding the status of this project in addition to providing proper closure.  

           Thanks again everyone for the shared input along with the recommended utilities to try out.  

            George

 

by: GMartinPosted on 2009-11-09 at 23:39:10ID: 25783141

Hi Everyone;

         Unfortunately, the message has come back this evening indicating a Trojan horse Agent_r.OT at c:\windows\system32\tdlwsp.dll.  The infected file was also detected by Hitman Pro.  Despite of it being deleted here too, this infected file keeps being redetected.  On a side note of possible troubleshooting merit,  Hitman Pro did detect 3 files labeled as "suspicious" which I never took any action on.  They are as follows:  MPCDx.ax at c:\windows\system32, RLMPCDec.ax at c:\windows\system32, and RLAPEDec.ax at c:\windows\system32.  Not knowing exactly what role or function these files serve, I decided to leave them alone instead of deleting them.

            In closing, I apologize for the complexity of this situation.  For a moment, it sure did look like this infection was gone.  It just puzzles me why it never permentally stays deleted.  It is almost like this infected file rebuilds itself after deletion.

          Any further help will certainly be welcomed and appreciated.

          Thank you.

          George

 

by: optomaPosted on 2009-11-10 at 00:05:34ID: 25783283

Locate those files and upload them to these online av scanners to see what they think
http://www.virustotal.com/
http://virusscan.jotti.org/en

 

by: jeff_01Posted on 2009-11-10 at 00:39:59ID: 25783430

Perhaps the antivirus/spyware is working correctly and removing the trojan correctly and then somehow there is a manual reinfection (USB flash drive or external drive or even another computer on your network which has the virus on it and reinfects via a share folder etc etc). Are all security updates and service packs for your OS installed?

 

by: GMartinPosted on 2009-11-10 at 19:31:46ID: 25792130

Hi Everyone;

          While Hitman Pro identified 3 suspicious items or files in addition to the reocurring Trojan, I could not find these files on the hard drive within the system32 folder of Windows to upload for analysis.  

           George

 

by: optomaPosted on 2009-11-10 at 23:27:12ID: 25792926

Jeff makes a good point above about manual infection.

If not the case try scanning that system with this live cd:
Kaspersky live cd http://devbuilds.kaspersky-labs.com/devbuilds/RescueDisk/
                                     READ ALL INFO BELOW!
--It is in iso/image format so you will have to burn it to a cd.
--Once the cd is created, boot the infected machine to that cd and scan your system
NB-Update the virus database in live cd before scanning.



Also, do you have your installation media?
If so you may have to do a repair installation afterwards, depending on what infected files Kaspersky live cd removes->ie.If system files are infected and removed,
the operating system will not start, thus resulting in a repair installation
http://michaelstevenstech.com/XPrepairinstall.htm

 

by: GMartinPosted on 2009-11-11 at 00:47:57ID: 25793242

Hi

        I should have everything together now.  Just out of curiousity, what exactly is the Trojan designed to do which has infected this pc?

         George

 

by: optomaPosted on 2009-11-11 at 01:15:14ID: 25793347

You could try this rootkit tdsskiller.exe + link also has info on it
http://support.kaspersky.com/viruses/solutions?qid=208280684 :)

 

by: GMartinPosted on 2009-11-12 at 07:46:34ID: 25805518

Hi Everyone;

          Thanks so much for the recent followup suggestions and links to additional tools which should prove helpful in resolving this problem.  At the present time, the main pc is starting to develop symptoms.  For instance, whenever I double click on Internet Explorer, I get a small box asking me to select the program to open it up with.  Much like a choosing a program to open up a movie file, picture file, audio file, etc.  The same things holds true if I double click on any internet shortcut saved on the desktop.  Interestingly, the "non-internet" links like WinDVD, DVD Shrink, etc. open just fine.  

           Of course, I have not used Kaspersky live cd  and rootkit tdsskiller yet.  I plan on picking up on those this weekend.  Luckly, I have a backup computer which I will be using to download these utilities.  I am hopeful I can resolve this issue without resorting to any kind of wipe and reload ordeal.  

            I will be back in touch with regards to the outcome of using these tools this weekend.  In the meantime, if other insights or ideas come to mind, please feel free to post them.  They will certainly be welcomed and used in this troubleshooting situation.  

            Many thanks again everyone for your continued help with this problem.

            George

 

by: GMartinPosted on 2009-11-13 at 21:10:15ID: 25819473

Hi;

      I am in the process of finalizing everything needed to hopefully provide closure to this pc concern.  At this point, I am needing some step by step instructions for creating the Kaspersky live cd.  Using the link provided, I was able to successfully download this utility and extract it to its original files.  There are a few folders and files.  While I do know how to record a single ISO file to a cd-r using Nero Ultra 7, I am not sure what to do in this situation which has several folders and files.  Should I combine all of these together and convert them to a single ISO file and record that file to cd-r?  Or, is the necessary ISO file needed already there within the extracted folders and files?  

          At any rate, any followup regarding the steps necessary to get the contents of Kaspersky over to a cd-r to make it bootable will be greatly appreciated.

          Thanks in advance for everyone's interest and especially patience with me as I struggle through these obstacles or technical hurdles.  

          George

 

by: optomaPosted on 2009-11-14 at 00:22:33ID: 25819804

Have you tried the Tdss killer?

 

by: GMartinPosted on 2009-11-15 at 02:04:37ID: 25824169

Hi Everyone;

          I am happy to say the Trojan mentioned is gone now.  But, it did take some time to figure out exactly what to use to permanently remove it because this infected file kept rebuilding itself upon restart of the pc or from a cold boot.  Of course, SpyBot S & D did find infection and removed what it found.  Also, Malwarebytes was found helpful as well because it removed infection as well as did Hitman Pro.  

           With regards to Kaspersky live cd, I never got a chance to use this utility because I never could figure out exactly how to make a bootable cd with what was downloaded from the link.  I did run Tdss killer, but, it did not seem to find anything.  

            After careful reflection of what I did in the past to permanently removed stubborn infections, ComboFix came across my mind.  So, I found the link to download the most recent copy of this program.  I downloaded the executable to my desktop and double-clicked on it.  Basically, the program restarted the pc and began removing processes and files which were infected.   Everything ComboFix did took about 10 to 15 minutes and everything was fully functional when I finally got to a fully loaded desktop.  To satisfy my curiousity about whether the infection was indeed removed, I ran both, AVG 9 and Hitman Pro.  Both failed to show the Trojan which confirmed that CombFix took care of it.

             With regards to the damage IE link and associated internet shortcut links not working, I fixed this program by copying the missing folder, en-US, and the missing executable file, IEXPLORE, from my fully working backup pc to the impaired one.  After doing that, I double clicked on IE and everything was fine.  Also, the internet shortcut links on the desktop also work again as well.  Apparently, the IEXPLORE.exe file must have gotten deleted because it was missing from the folder within Program Files which houses Internet Explorer.  Of course, this logically explains the non-working IE and internet related links on the desktop.  There was not .exe file to make a call to when the shortcut was double-clicked from the desktop.  

             On a sidenote, I am still interested in learning how to create a Kaspersky live cd.  Using the link mentioned earlier in this thread, I have various folders and files which make up this utility downloaded.  To be honest, I was expecting a single ISO file to be downloaded.  I know how to burn a single ISO file to cd-r using Nero Ultra Edition 7.  However, since there are a few folders and files, I am not quite sure how to carry out this goal.  I do have an open post addressing my interest in creating a Kaspersky live cd, but, no one has responded to it yet.  If someone would like to take a look at it, please feel free to.  I would love to get some feedback to that open post.  

             Thank you.

             George

 

by: GMartinPosted on 2009-11-15 at 02:09:37ID: 25824191

Hi

       Sorry for omitting this information, but, the link to the open post concerning my interest in learning step by step procedures in creating a Kaspersky live cd is as follows:
http://www.experts-exchange.com/Software/Internet_Email/Anti-Virus/Kaspersky/Q_24898573.html
The recording software I use is Nero Ultra Edition 7.0.  If more information is needed or if there are any questions, please feel free to let me know.

         Thanks in advance for any consideration given to this question.

         George

         

20120131-EE-VQP-002

3 Ways to Join

30-Day Free Trial

The Experts

98% positive feedback on 31,087 answers since March 2000. angeliii is a Microsoft Most Valuable Professional for his work with MS SQL Server & Develoment.

He has also proven his knowledge of Visual Basic Programming, PHP Scripting and Oracle Databases.

The Experts

97% positive feedback on 10,752 answers since July 2000. lrmoore has more than 18 years experience in the networking industry.

The six-time Mircosoft MVPs specialties include firewalls, virtual private networking, and network management.

Testimonials

"...and excellent source for support... Kind of like having your very own IT dept." Electriciansnet

Testimonials

"I was apprehensive at signing up at first. However... it has already made my life as an IT administrator much easier." JaCrews

Testimonials

"WOW! You guys have great, active, and knowledgeable people on here." moore50

Business Clients

Business Clients

In the Press

"If you’ve got a question... Experts Exchange can supply an answer.”

In the Press

"...an invaluable aid for both IT professionals and those who require tech support."

In the Press

"where IT professionals provide quick answers on just about any topic"

Business Account Plans

Loading Advertisement...