Live Chat & Podcast at 1:00PM Eastern on Sunday!
There's no such thing as a stupid question, but they're the easiest to answer.
JoinTour
Login
Search
General Security
Tag Cloud
access acer asus bios bsod computer crash desktop driver drivers error ethernet excel freeze gaming hard drive hardware hdmi internet laptop malware memory modem monitor motherboard network printer problem ram registry router security slow software sound toshiba trojan ubuntu 11.10 uninstall usb video virus vista wifi windows windows 7 windows 7 32 bit windows 7 64 bit windows xp wireless
Search
Search for:
Tech Support Guy Forums > Security & Malware Removal > General Security >
Agent. UZM Trojan

Reply  
Thread Tools
hogndog's Avatar
Computer Specs
Member with 282 posts.
 
Join Date: Jan 2007
Location: In the departure zone
Experience: Depends on the computer.
01-Dec-2007, 01:38 PM #1
Exclamation Agent. UZM Trojan
I have this in my AVG Virus Vault, I haven't deleted because I've heard some of these
strains are difficult to remove manually. Here is an overview..

Trojan Downloader.Agent.UZM

A new Trojan Downloader was spammed today. Trojan is attached in zip archive to emails in HTML format with subject "Hot game" and body text that claims some Angelina Jolie or Lara Croft undressing game. xgame.zip attachment contains xgame.exe (20992B) which drops executes and deletes kernel driver C:\WINDOWS\System32\drivers\runtime.sys and downloads another downloader smartdrv.exe. runtime.sys runs injects and hides Iexplore.exe process and downloads another components. xgame.exe is detected as Trojan Downloader.Agent.UZM, smartdrv.exe is detected as Trojan Downloader.Agent.UZN, runtime.sys is detected as Trojan Downloader.Agent.THW and other downloaded components are detected as several variants of Trojan Backdoor.Ntrootkit.
November 10, 2007

Any suggestions would be much appreciated

AVG says they offer no tech support unless you pay for it, I guess what I need to know is,
is it or isn't it safe to delete?

Thanks,
hogndog
__________________
Proverbs 3:5 Trust in the LORD with all thine heart; and lean not unto thine own understanding.
3:6 In all thy ways acknowledge him, and he shall direct thy paths.
hogndog's Avatar
Computer Specs
Member with 282 posts.
 
Join Date: Jan 2007
Location: In the departure zone
Experience: Depends on the computer.
01-Dec-2007, 09:56 PM #2
Thumbs down Thanks Guys!
Ask a stupid question right, I came here because the sign said you knew your stuff Pfft!
lunarlander's Avatar
Computer Specs
Senior Member with 3,492 posts.
 
Join Date: Sep 2007
01-Dec-2007, 11:14 PM #3
It wont do any harm to empty your quarantine vault. From the description it seems it only does harm when xgame.exe is executed. So I hope you never double clicked it.

It's best to do online scan with ALL the online scanners listed in the sticky 'Security Help Tools', since none can pick out all the malware alone.
hogndog's Avatar
Computer Specs
Member with 282 posts.
 
Join Date: Jan 2007
Location: In the departure zone
Experience: Depends on the computer.
01-Dec-2007, 11:19 PM #4
O.k., thank you very much
Reply

THIS THREAD HAS EXPIRED.
Are you having the same problem? We have volunteers ready to answer your question, but first you'll have to join for free. Need help getting started? Check out our Welcome Guide.

Search Tech Support Guy

Find the solution to your
computer problem!




Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
WELCOME TO TECH SUPPORT GUY! Are you looking for the solution to your computer problem? Join our site today to ask your question -- for free! Our site is run completely by volunteers who want to help you solve your computer problems. See our Welcome Guide to get started.
Thread Tools



Facebook Facebook Twitter Twitter TechGuy.tv TechGuy.tv Mobile TSG Mobile
You Are Using:
Server ID
Advertisements do not imply our endorsement of that product or service.
All times are GMT -4. The time now is 10:43 PM.
Copyright © 1996 - 2011 TechGuy, Inc. All rights reserved.

Powered by Cermak Technologies, Inc.