Computer Forums

Member Login

Remember Me? Sign Up! | Forgot Password
 
Slogan
 
Computer Forums > The World Wide Web > Virus - Spyware Protection / Detection » [for a friednd] How bad is agnt_pnc.exe
Closed Thread
Old 05-28-2007, 06:53 PM   #1 (permalink)
Saxon's Avatar
 

Join Date: Feb 2007

Posts: 6,346

Saxon is just really niceSaxon is just really niceSaxon is just really niceSaxon is just really nice

Default [for a friednd] How bad is agnt_pnc.exe

[posted for a friend]

A friend of mine has agnt_pnc.exe I know it is a virus bu how bad is it? and how did he get it?

[/posted for a friend]

EDIT:

HIS AV isn't picking it up he needs help to remove it suggestions please.
__________________
I am not here for long I am deploying soon so please don't expect anything long winded.


Last edited by Saxon; 05-28-2007 at 06:57 PM. Reason: forgot to add something.
Saxon is offline  
Old 05-28-2007, 08:16 PM   #2 (permalink)
Osiris's Avatar
 

Join Date: Jan 2005

Location: Kentucky

Posts: 31,703

Osiris is a jewel in the roughOsiris is a jewel in the roughOsiris is a jewel in the rough

Send a message via ICQ to Osiris Send a message via AIM to Osiris Send a message via MSN to Osiris Send a message via Yahoo to Osiris Send a message via Skype™ to Osiris
Default Re: [for a friednd] How bad is agnt_pnc.exe

Have him post a log
__________________
Osiris is offline  
Old 05-28-2007, 08:23 PM   #3 (permalink)
Saxon's Avatar
 

Join Date: Feb 2007

Posts: 6,346

Saxon is just really niceSaxon is just really niceSaxon is just really niceSaxon is just really nice

Default Re: [for a friednd] How bad is agnt_pnc.exe

I will do it for him tomorrow I am going to try and fix it for him I will post a log tomorrow, from what I can tell there is two versions of it one with a key loger and one without. and we have tried a few way to do it but he is limited on what he can do.
__________________
I am not here for long I am deploying soon so please don't expect anything long winded.

Saxon is offline  
Old 05-28-2007, 08:46 PM   #4 (permalink)
Osiris's Avatar
 

Join Date: Jan 2005

Location: Kentucky

Posts: 31,703

Osiris is a jewel in the roughOsiris is a jewel in the roughOsiris is a jewel in the rough

Send a message via ICQ to Osiris Send a message via AIM to Osiris Send a message via MSN to Osiris Send a message via Yahoo to Osiris Send a message via Skype™ to Osiris
Default Re: [for a friednd] How bad is agnt_pnc.exe

ProAgent 2.1.9 Special Edition
(Trojan-Dropper.Win32.Agent.arr)

by ATmaCA
Written in C++
Released in April 2006
Made in Turkey
more versions

Server:dropped files:c:\WINDOWS\system32\agnt_mps.exe Size: 77,618 bytes c:\WINDOWS\system32\agnt_msn.exe Size: 76,594 bytes c:\WINDOWS\system32\agnt_pnc.exe Size: 9,216 bytes c:\WINDOWS\system32\drivers\KeenSense.sys Size: 16 bytes c:\WINDOWS\system32\drivers\ksdevice.sys Size: 16 bytes added to registry:HKEY_CURRENT_USER\Software\Microsoft\Wind ows\CurrentVersion\Run "qservices"data: C:\WINDOWS\qservice.exe tested on Windows XPOctober 04, 2006MegaSecurity
__________________
Osiris is offline  
Old 05-28-2007, 08:57 PM   #5 (permalink)
Saxon's Avatar
 

Join Date: Feb 2007

Posts: 6,346

Saxon is just really niceSaxon is just really niceSaxon is just really niceSaxon is just really nice

Default Re: [for a friednd] How bad is agnt_pnc.exe

Thanks that helps a **** of alot
__________________
I am not here for long I am deploying soon so please don't expect anything long winded.

Saxon is offline  
Old 05-28-2007, 09:08 PM   #6 (permalink)
Osiris's Avatar
 

Join Date: Jan 2005

Location: Kentucky

Posts: 31,703

Osiris is a jewel in the roughOsiris is a jewel in the roughOsiris is a jewel in the rough

Send a message via ICQ to Osiris Send a message via AIM to Osiris Send a message via MSN to Osiris Send a message via Yahoo to Osiris Send a message via Skype™ to Osiris
Default Re: [for a friednd] How bad is agnt_pnc.exe

NP...
__________________
Osiris is offline  
Old 05-29-2007, 02:33 PM   #7 (permalink)
Saxon's Avatar
 

Join Date: Feb 2007

Posts: 6,346

Saxon is just really niceSaxon is just really niceSaxon is just really niceSaxon is just really nice

Default Re: [for a friednd] How bad is agnt_pnc.exe

Ok fixed the problem by remote he had to scan his system 3 times with 3 different AV programs and all but one missed it, Kasperskey AV got it deleted and deleted it although we had to do it twice to fix it. Norton and Mcafee missed it.
__________________
I am not here for long I am deploying soon so please don't expect anything long winded.

Saxon is offline  
Old 05-29-2007, 03:39 PM   #8 (permalink)
Osiris's Avatar
 

Join Date: Jan 2005

Location: Kentucky

Posts: 31,703

Osiris is a jewel in the roughOsiris is a jewel in the roughOsiris is a jewel in the rough

Send a message via ICQ to Osiris Send a message via AIM to Osiris Send a message via MSN to Osiris Send a message via Yahoo to Osiris Send a message via Skype™ to Osiris
Default Re: [for a friednd] How bad is agnt_pnc.exe

what does the log look like
__________________
Osiris is offline  
Old 05-30-2007, 09:24 AM   #9 (permalink)
Saxon's Avatar
 

Join Date: Feb 2007

Posts: 6,346

Saxon is just really niceSaxon is just really niceSaxon is just really niceSaxon is just really nice

Default Re: [for a friednd] How bad is agnt_pnc.exe

clean, very clean in fact.
__________________
I am not here for long I am deploying soon so please don't expect anything long winded.

Saxon is offline  
 
Closed Thread

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On