Help needed to remove Torjan.Agent.cn

Discussion in 'Windows 7 Help and Support' started by Gil80, Jan 2, 2013.

  1. Gil80

    Gil80 Senior Member

    Joined:
    Oct 2, 2009
    Messages:
    207
    Likes Received:
    0
    Help please.

    I'm using Malware Bytes and every restart it quarantines this trojan as svchost.exe

    How can I remove it completely?
     
  2. patcooke

    patcooke Microsoft MVP
    Staff Member Premium Supporter Microsoft MVP

    Joined:
    May 16, 2010
    Messages:
    5,456
    Likes Received:
    268
    svchost is a valid Windows application so there are a few possibilities:

    It is a false alert to a valid application
    It is a valid alert to malware masquerading as svchost
    It is an alert to malware which is being executed by svchost (execution of code is the basic function of svchost)

    You need to examine more information from the mbam report to identify what is actually happening here.
     
  3. Gil80

    Gil80 Senior Member

    Joined:
    Oct 2, 2009
    Messages:
    207
    Likes Received:
    0
    I'm pretty sure it's a Tojan. I cannot start my security center service nor windows firewall. After each restart I they revert to disabled mode.
    when I thought i did remove it, I was able to have them back on but the trojan is up again.
     
  4. patcooke

    patcooke Microsoft MVP
    Staff Member Premium Supporter Microsoft MVP

    Joined:
    May 16, 2010
    Messages:
    5,456
    Likes Received:
    268
    Have you checked the additional data offered by mbam from the scan results?
     
  5. Gil80

    Gil80 Senior Member

    Joined:
    Oct 2, 2009
    Messages:
    207
    Likes Received:
    0
  6. bassfisher6522

    bassfisher6522 Essential Member

    Joined:
    Aug 27, 2008
    Messages:
    4,884
    Likes Received:
    318
    I would run Malwarebytes in safemode running a full scan and remove the infection that way.
     
  7. Joe S

    Joe S Excellent Member

    Joined:
    Jan 12, 2009
    Messages:
    3,785
    Likes Received:
    113

Share This Page

Loading...