Go Back   IceInSpace > Equipment > Software and Computers
Register FAQ Calendar Today's Posts Search

Reply
 
Thread Tools Rate Thread
  #1  
Old 09-09-2007, 05:20 PM
[1ponders]'s Avatar
[1ponders] (Paul)
Retired, damn no pension

[1ponders] is offline
 
Join Date: Nov 2004
Location: Obi Obi, Qld
Posts: 18,778
Help please. Problems with AstroPlanner

Last night I received an AVG Resident Shield warning that Astroplanner.exe contained a trojan (this has never happened before and there had been no updates as I was not connected to the internet). Astroplanner was not running. Selecting the heal option the message came back, Heal successful (or some such thing).

Then about half an hour ago I noticed my Astroplanner Icons had changed to the boring windows generic "I don't know what this is so I'll put this icon to it". When I clicked on the icon to open Astroplanner nothing happened. So I went and check the program folder and there was no Astroplanner.exe there Damn. So I thought I'd reinstall it. Up pops the AVG Resident Shield warning that D:/windowsintall.exe has the Trojan horse Dropper.Agent.FCB. In fact the installer icon on the CD is the same boring windows standard one as well. When I click ignore I get "Windows cannot access the specified device, path or file. You may not have the appropriate permission to access the item." Even if I turn AVG off I still can't access it.

Not only can I not install it again, I can't even find the program under control panel "Add Remove Programs" to completely remove it and start again.

Can anyone give me any ideas how to fix this problem

Thanks
Reply With Quote
  #2  
Old 09-09-2007, 05:55 PM
Shawn
Mostly Harmless

Shawn is offline
 
Join Date: Jun 2006
Location: Cairns
Posts: 1,352
Try , doing a restore till just before all this stuff happened, then run a virus check...Not too invasive...

S
Reply With Quote
  #3  
Old 09-09-2007, 06:01 PM
[1ponders]'s Avatar
[1ponders] (Paul)
Retired, damn no pension

[1ponders] is offline
 
Join Date: Nov 2004
Location: Obi Obi, Qld
Posts: 18,778
Thanks Shawn, I'll give it a try.
Reply With Quote
  #4  
Old 09-09-2007, 06:10 PM
acropolite's Avatar
acropolite (Phil)
Registered User

acropolite is offline
 
Join Date: Feb 2005
Location: Launceston Tasmania
Posts: 9,021
I have had AVG do this to a couple of my apps as well, all of a sudden it decides there's a virus in an exe file. I know it wasn't an infection as AVG deleted the same file on 2 different machines, one of which the app hadn't been used on for over 2 years. I suspect it is a bug in the AVG software. I intend changing back to Nod32, despite the fact that I will have to pay for Nod.
Reply With Quote
  #5  
Old 09-09-2007, 06:10 PM
[1ponders]'s Avatar
[1ponders] (Paul)
Retired, damn no pension

[1ponders] is offline
 
Join Date: Nov 2004
Location: Obi Obi, Qld
Posts: 18,778
Nope, no go Shawn. Thanks anyway
Reply With Quote
  #6  
Old 09-09-2007, 06:10 PM
[1ponders]'s Avatar
[1ponders] (Paul)
Retired, damn no pension

[1ponders] is offline
 
Join Date: Nov 2004
Location: Obi Obi, Qld
Posts: 18,778
How can I get my application back again Phil? Any ideas?
Reply With Quote
  #7  
Old 09-09-2007, 06:11 PM
Shawn
Mostly Harmless

Shawn is offline
 
Join Date: Jun 2006
Location: Cairns
Posts: 1,352
Np....
Reply With Quote
  #8  
Old 09-09-2007, 06:36 PM
acropolite's Avatar
acropolite (Phil)
Registered User

acropolite is offline
 
Join Date: Feb 2005
Location: Launceston Tasmania
Posts: 9,021
The astroplanner.exe file should be quarantined, you should be able to get it back, the executable will be in the virus vault. Whether or not AVG will delete it again I'm not sure. In my case the app was an old version so I just upgraded to a later version. I just looked at my vault and the files it thought were infected were ACDsee32.exe and a heap of flash animations that I have had for years and that I know have no problems. All in all the damn thing took 11 executables, none of which were really infected.
Reply With Quote
  #9  
Old 09-09-2007, 06:48 PM
[1ponders]'s Avatar
[1ponders] (Paul)
Retired, damn no pension

[1ponders] is offline
 
Join Date: Nov 2004
Location: Obi Obi, Qld
Posts: 18,778
Tried that and while it returned the exe file to the directory it still wouldn't work. I'll go and look for an updated version, though I've only just recently received the disk.
Reply With Quote
  #10  
Old 09-09-2007, 06:58 PM
Shawn
Mostly Harmless

Shawn is offline
 
Join Date: Jun 2006
Location: Cairns
Posts: 1,352
did a restore piont not work, ??

S
Reply With Quote
  #11  
Old 09-09-2007, 07:26 PM
[1ponders]'s Avatar
[1ponders] (Paul)
Retired, damn no pension

[1ponders] is offline
 
Join Date: Nov 2004
Location: Obi Obi, Qld
Posts: 18,778
No it didn't Shawn.
Reply With Quote
  #12  
Old 09-09-2007, 08:15 PM
Shawn
Mostly Harmless

Shawn is offline
 
Join Date: Jun 2006
Location: Cairns
Posts: 1,352
Wow, Restore has allways been my first option and never failed, so I am at odds as to any other help I can give, Ill watch this post with interst as to your outcome...

Good Luck...

S
Reply With Quote
  #13  
Old 09-09-2007, 11:49 PM
Doug
Registered User

Doug is offline
 
Join Date: Mar 2006
Posts: 645
Phil, I have the same trojan in my PC from time to time. where it comes from, I have no idea! it has infected various files on the C drive including some file or other to do with restore. Today it was reported as being in the 'F' drive, my second HDD, also in a directory supposedly connected with restore. (Restore on a second drive????) F:\System Volume Information\_restore{.......} A large string of hex values were inside the parenthesis. Anyway, according to AVG, it has been there in times past and the infected file was healed. However on rebooting the PC the trojan was back!! So before running any program I hit the main power switch (no subtlety here) that got rid of it, and it remained gotten rid of for days/weeks before returning. The only effect I nave noticed is a slowing up of the PC, or last night and on one previous occasion, Windows simply would not shut down, neither by way of the start menu, nor the task manager. I don't like just pulling the plug on the PC, but so far that has been the only remedy I have.
I suspect that the trojan is actually coming in with the AVG updates; I do not use astroplanner. I'm no computer whizz kid, but I think Trojans live in memory but write themselves to disc on normal power down and wake up on a subsequent reboot. That is why I pull the plug on my PC; to deny the virus time to protect itself.
HTH,
Doug
Reply With Quote
  #14  
Old 10-09-2007, 12:23 AM
netwolf's Avatar
netwolf
Registered User

netwolf is offline
 
Join Date: Jan 2005
Posts: 2,949
Its most likely a false positive. The new pattern detection methods used in modern AV's often do that.

See thread on same issue reported on CN
http://www.cloudynights.com/ubbthrea.../o/all/fpart/1

Apparently a update from AVG should fix it.

Regards
Fahim
Reply With Quote
  #15  
Old 10-09-2007, 07:16 AM
[1ponders]'s Avatar
[1ponders] (Paul)
Retired, damn no pension

[1ponders] is offline
 
Join Date: Nov 2004
Location: Obi Obi, Qld
Posts: 18,778
Quote:
Apparently a update from AVG should fix it.
But will it give me back my Astroplanner Fahim?
Reply With Quote
  #16  
Old 10-09-2007, 09:38 AM
netwolf's Avatar
netwolf
Registered User

netwolf is offline
 
Join Date: Jan 2005
Posts: 2,949
An online update to have fixed it for others. Paul who is the author seems to have indicated that other AV software are also doing this with recent updates and he is contacting them for similar updates. I think the application has been blacklisted by AVG on your system and it will not let it run until its not on its list of threats. I am a user of AP but I dont use AVG so I cant offer first hand advise.

Regards
Fahim
Reply With Quote
  #17  
Old 10-09-2007, 09:42 AM
[1ponders]'s Avatar
[1ponders] (Paul)
Retired, damn no pension

[1ponders] is offline
 
Join Date: Nov 2004
Location: Obi Obi, Qld
Posts: 18,778
Thanks Fahim, I'll see how it goes.
Reply With Quote
  #18  
Old 10-09-2007, 09:56 AM
Doug
Registered User

Doug is offline
 
Join Date: Mar 2006
Posts: 645
Fahim, my AVG is current and updated daily.

Paul, the attached file shows the prevalence of this nuisance. Re4member, it can attach to any program. Sorry, the print is small you'll need to magnify screen to 150%
Attached Thumbnails
Click for full-size image (trojan.gif)
38.8 KB16 views
Reply With Quote
  #19  
Old 10-09-2007, 10:02 AM
[1ponders]'s Avatar
[1ponders] (Paul)
Retired, damn no pension

[1ponders] is offline
 
Join Date: Nov 2004
Location: Obi Obi, Qld
Posts: 18,778
The strange thing is Doug that this has picked up the problem on a CD with the program direct from the supplier, in an freshly unzipped copy of the program downloaded from the site in zip form as well as the existing program.

It is very frustrating.
Reply With Quote
  #20  
Old 10-09-2007, 10:23 AM
netwolf's Avatar
netwolf
Registered User

netwolf is offline
 
Join Date: Jan 2005
Posts: 2,949
Doug, you may have the real trojan not a false postiive and though you have removed it from the live system its still there in saved restore point. I would celar the restore point and renable it on your F drive. Right click on my computer icon and select properties from the drop down menu. Then goto the System restore tab. You should see a list of drives on your system and you can disable and enable system restore points. This is a very common step mentioned in most malware removal instructions I have stepped through. Often removing the virus is not sufficient you must clear old restore points incase the malware has created its own or infected existing ones.

Regards
Fahim
Reply With Quote
Reply

Bookmarks


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT +10. The time is now 11:05 AM.

Powered by vBulletin Version 3.8.7 | Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.
Advertisement
Bintel
Advertisement
Astrophotography Prize
Advertisement