<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Trojan.Win32.Agent.rju in Norton Internet Security / Norton AntiVirus</title>
    <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Trojan-Win32-Agent-rju/m-p/6483#M2558</link>
    <description>&lt;p&gt;I found a pointer in registry :&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Name: comtf&lt;/p&gt;&lt;p&gt;Type: REG_SZ &lt;/p&gt;&lt;p&gt; Data: C:\DOCUME~1\&amp;lt;current user&amp;gt;\LOCALS~1\Temp\&lt;strong&gt;orz.exe&lt;/strong&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;And that file did exist in that Temp directory.  Have deleted it and waiting to see what comes of it.  It did NOT show up as an infected file, neither did any of the c:\Windows\system#####.exe files that it had dropped in the last two days show up as infected. &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;After deletion of that file trojan.win32.agent.rju didn't appear to run on reboot.  Time will tell.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Just go to that Run key in the registry and get rid of anything suspicious. &lt;/p&gt;</description>
    <pubDate>Thu, 19 Jun 2008 00:02:38 GMT</pubDate>
    <dc:creator>pjgeek</dc:creator>
    <dc:date>2008-06-19T00:02:38Z</dc:date>
    <item>
      <title>Trojan.Win32.Agent.rju</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Trojan-Win32-Agent-rju/m-p/6423#M2523</link>
      <description>&lt;p&gt;Ok does anyone know how to get rid of Trojan.Win32.Agent.rju&lt;/p&gt;&lt;p&gt; &lt;/p&gt;It keeps coming back and creating a new file. It goes in my C:\windows\system and has a number then .exe after it. It has obviously slowed the computer down, I have run a separate virus scan and mid way it closes completely. I also had Ad-Aware running and it closed too.. I have even tried to delete instead of quarantining. It is obviuosly creating it from somewhere else. Any ideas on what to do?</description>
      <pubDate>Wed, 18 Jun 2008 16:41:58 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/Trojan-Win32-Agent-rju/m-p/6423#M2523</guid>
      <dc:creator>smokeeater</dc:creator>
      <dc:date>2008-06-18T16:41:58Z</dc:date>
    </item>
    <item>
      <title>Re: Trojan.Win32.Agent.rju</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Trojan-Win32-Agent-rju/m-p/6458#M2545</link>
      <description>&lt;p&gt;Click on this Web Link: &lt;a target="_blank" href="http://www.symantec.com/en/uk/security_response/writeup.jsp?docid=2005-042511-1823-99"&gt;http://www.symantec.com/en/uk/security_response/writeup.jsp?docid=2005-042511-1823-99&lt;/a&gt; .&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;It is advised that you only have one Anti-Virus Software Installed on your computer at any one time and other Programs related to what Anti-Virus Progams do.&lt;/p&gt;&lt;div class="message-edit-history"&gt;&lt;span class="edit-author"&gt;Message Edited by Floating_Red on &lt;/span&gt;&lt;span class="local-date"&gt;06-18-2008&lt;/span&gt;&lt;span class="local-time"&gt; 09:21 PM&lt;/span&gt;&lt;/div&gt;</description>
      <pubDate>Wed, 18 Jun 2008 20:21:42 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/Trojan-Win32-Agent-rju/m-p/6458#M2545</guid>
      <dc:creator>Floating_Red</dc:creator>
      <dc:date>2008-06-18T20:21:42Z</dc:date>
    </item>
    <item>
      <title>Re: Trojan.Win32.Agent.rju</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Trojan-Win32-Agent-rju/m-p/6461#M2546</link>
      <description>&lt;p&gt;Hi Smokeeater&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Please submit the file to Symantec&lt;/p&gt;&lt;p&gt;&lt;a target="_blank" href="https://submit.symantec.com/websubmit/retail.cgi"&gt;Malware Submission&lt;/a&gt;&lt;/p&gt;</description>
      <pubDate>Wed, 18 Jun 2008 20:56:04 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/Trojan-Win32-Agent-rju/m-p/6461#M2546</guid>
      <dc:creator>Stu</dc:creator>
      <dc:date>2008-06-18T20:56:04Z</dc:date>
    </item>
    <item>
      <title>Re: Trojan.Win32.Agent.rju</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Trojan-Win32-Agent-rju/m-p/6483#M2558</link>
      <description>&lt;p&gt;I found a pointer in registry :&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Name: comtf&lt;/p&gt;&lt;p&gt;Type: REG_SZ &lt;/p&gt;&lt;p&gt; Data: C:\DOCUME~1\&amp;lt;current user&amp;gt;\LOCALS~1\Temp\&lt;strong&gt;orz.exe&lt;/strong&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;And that file did exist in that Temp directory.  Have deleted it and waiting to see what comes of it.  It did NOT show up as an infected file, neither did any of the c:\Windows\system#####.exe files that it had dropped in the last two days show up as infected. &lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;After deletion of that file trojan.win32.agent.rju didn't appear to run on reboot.  Time will tell.&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt;Just go to that Run key in the registry and get rid of anything suspicious. &lt;/p&gt;</description>
      <pubDate>Thu, 19 Jun 2008 00:02:38 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/Trojan-Win32-Agent-rju/m-p/6483#M2558</guid>
      <dc:creator>pjgeek</dc:creator>
      <dc:date>2008-06-19T00:02:38Z</dc:date>
    </item>
    <item>
      <title>Re: Trojan.Win32.Agent.rju</title>
      <link>http://community.norton.com/t5/Norton-Internet-Security-Norton/Trojan-Win32-Agent-rju/m-p/6503#M2563</link>
      <description>&lt;p&gt;Ok&lt;/p&gt;&lt;p&gt;Please keep us posted&lt;/p&gt;</description>
      <pubDate>Thu, 19 Jun 2008 04:13:59 GMT</pubDate>
      <guid>http://community.norton.com/t5/Norton-Internet-Security-Norton/Trojan-Win32-Agent-rju/m-p/6503#M2563</guid>
      <dc:creator>Stu</dc:creator>
      <dc:date>2008-06-19T04:13:59Z</dc:date>
    </item>
  </channel>
</rss>

