I have a problem with Win32:Agent-OLD [trj] and there is very little information on the net.
Whilst running a system scan, Avast! reported that “C:\System Volume Information\catalog.wci\00000002.PS2” was a Win32:Agent-OLD trojan.
Being part of an active system process it was impossible to get rid of. Unless anyone has a workaround this also prevents me from copying it and sending Avast! a sample for analysis.
I live in France and I got some help from a French message board. I did all the “turn off system restore” stuff. I rebooted in safe mode, scanned my computer with Avast!, Kaspersky online scanner, AVG & AntiVir, ran a whole bunch of spyware programs.
The only program which reports “C:\System Volume Information\catalog.wci\00000002.PS2” as being a Trojan/virus is Avast!
This seems to be a very recent problem. It started on or around the 20th december and may be due to changes in Avast’s! virus definitions. This is why I’m contacting Avast! about this.
Maybe it’s a false positive, but I’m not 100% sure.
When Avast! detects “C:\System Volume Information\catalog.wci\00000002.PS2” and I click on the “more info from Avast!” link, 3 pages open in my browser.
One is the Avast! site, the second a “page not found” error and the third…opens a “seek spiritual enlightenment/find God” sort of site.
Someone may be pulling our chains… >:(
Has anybody from avast! or this message board any answers about this, please? I’ve been trying to solve this problem for the past 4 days and I’m a little tired with it. >:(
One morning around the 20th December on booting up my system Windows signaled me the it had to shut down explorer.exe due to something “interfering” with (or was it “writing to”) the System Volume Information folder. It indicated that the problem had occurred the night before. At that time my daughter was using MSN with 2 correspondents (1 Mac/1 Windows). The same night some programs that I was using were slow or crashed.
I ran Avast! and it reported a Win32:Agent-OLD [trj] as a keylogger Trojan. When I clicked on the “Complete our virus report" on the bottom left hand of the window I got these 3 tabs opened in my browser (Firefox beta 3).
How strange that the 3rd site is “trj.com” a bit like the [trj] in the Trojan. Which leaves the suspicion that it may not be a false positive.
I have tried to copy the file in safe boot mode in an Administrator role, but the folder is empty and “access is denied”. If anyone has a walkthrough (or a link) for the procedure of how to copy the file I’m very interested.
Whatever happens, the Win32:Agent-OLD [trj] file doesn’t go away even when all the old restore points have been erased.
Files on C:\System Volume Information\ have always access denied even to Administrators.
You need to grand the access (take the ownership) or allow access to Administrators. It’s an advanced procedure. You can delete the old restore points and you’ll get rid of these files.
I suggest:
Disable System Restore and reenable it after step 3.
Clean your temporary files.
Schedule a boot time scanning with avast with archive scanning turned on.
Use AVG Antispyware; SUPERantispyware and/or Spyware Terminator to scan for spywares and trojans. If any infection is detected, better and safer is send the file to Quarantine than to simple delete than.
It’s ok, clean.
The files reported couldn’t be scanned by avast: due to an internal problem into the package or avast unpackers couldn’t be able to manage them. Don’t worry, it does not mean the files are infected.
I have the exact same problem described by RufusO on December 28, 2007:
“Avast! reported that “C:\System Volume Information\catalog.wci\00000002.PS2” was a Win32:Agent-OLD trojan.” I have been able to delete it but it keeps reappearing.
I’ve also tested it with Norton Security, AVG Antivirus, AVG Antispyware, AVG AntiRootkit, Spybot, and AdAware but none of them identify the file as a problem. The first time it was identified I was able to move it to the Moved directory. Avast found it there during the next scan and I was able to move it from there to the Chest. It looks like I can email it to Alwil from the Chest if you wish.
Unfortunately it soon reappeared in the original folder C:\System Volume Information\catalog.wci. I have been marking it for deletion on reboot and Avast is able to delete it that way but it always comes back again within a couple of hours.