Re: Win32.Trojan.Spy.Agent.kb detected by ZoneAlarm Internet Secur



I also was warned by ZASuite today about win32 spy agent.

Looking in the registry, this is "driver YMAX MagicJack USB Device" which is
my MagicJack internet phone. It has been installed since Christmas and works
fine. I don't know why ZASuite picked it up as a virus today. My computer
seems to be functioning normaly. I will watch my outgoing email activity.


"smc" wrote:


David Williams;3761921 Wrote:
I just googled the virus,was led to this page, am having the exact same
problem.In CA Yahoo Anti-Spy,the virus is called Konvoy B,with
absolutely no practical removal instructions that can be
understood.Although it could just be my computer,many anti-malware
sites and their forums are inaccessible,as well as Notepad.exe and
msnmsgr.exe failing on activation,immediately.AntiSpywareMaster is
advertised continuously while surfing FireFox,even when in Safe Mode.
I'll help in any ways I can,but please help me get this infection off
of my computer.
Just as well,I am running a Vista with Zone Alarm Security Suite with
all of the newest updates.

Again,I am posting only what I'm told by ZA.




[SMC - reply]
Win32.Trojan.Spy.Agent.kb has been an issue with my network. First
indications I had a problem was the inability to "send" email. Email
on two of the computers on the network is hosted on Comcast servers,
who finally killed my email port and my ability to send email due to
the massive amounts of email going through my system. It appears that
this virus opened the door for unsolicited email ("spam") to be sent
through one of the network computers. I've since re-directed email to
be sent through another port and email once again is functional.

Both computers are updated daily with the latest ZA virus definitions
and email is scanned inbound and outbound. After running a ZA Spyware
scan, Win32.Trojan.Spy.Agent.kb surfaced on one computer only, this
one running Outlook Express.

After quarantined in ZA the trojan re-surfaced during the next scan.
So far I've re-quarantined AND deleted both in quarantine. Another
scan after re-boot showed a clean computer, however I realize the
probability of this returning is still relatively high. -smc


--
smc
------------------------------------------------------------------------
smc's Profile: http://forums.techarena.in/member.php?userid=50407
View this thread: http://forums.techarena.in/showthread.php?t=974108

http://forums.techarena.in


.



Relevant Pages

  • Re: Win32.Trojan.Spy.Agent.kb detected by ZoneAlarm Internet Secur
    ... this is "driver YMAX MagicJack USB Device" which ... I don't know why ZASuite picked it up as a virus today. ... [SMC - reply] ... Win32.Trojan.Spy.Agent.kb has been an issue with my network. ...
    (microsoft.public.security.virus)
  • RE: Securing a Local Network
    ... How much would it cost if a virus infected one ... be if a competitor hacked into their network and was able to access all ... Third issue is virus protection. ... can infect you from numerous other sources. ...
    (Security-Basics)
  • >>>> REMOVE MY <<<<
    ... Remove Secrurity From My Wireless Network ... How Can I Remove My Virus ... Remove My Search Tool Bar ... Remove My Bluetooth Desktop Icon ...
    (comp.lang.tcl)
  • RE: Using viruses in pen-test
    ... I wonder if there is some type of "fake" virus you could use in this case. ... David A. Swafford, Network Engineer ... I wish to know your views on "Using viruses in pen-test"I ... Cenzic Hailstorm finds vulnerabilities fast. ...
    (Pen-Test)
  • Re: If you used to use Windows or now used Windows less because of FreeBSD why?
    ... > but I've never had any virus or other malware on it. ... > network. ... then build a recommended s/w suite on that. ... toaster, not very expensive crap computers made to be less useful than ...
    (comp.unix.bsd.freebsd.misc)