Can't get rid of trojan.win32.agent.cs

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by emilyc, May 5, 2005.

  1. emilyc

    emilyc Private E-2

    Hi! I desperately need your help.

    I started receiving a message from my anti-virus that W32/Agent.MY was found in an infected file C:\WINDOWS\Fonts\abrlib.dll. It was unable to disinfect the file so I tried some other anti-virus software and ultimately went through all of the suggested scans as advised on your site (Trend Micro, Symantec, McAfee Stinger, Ad-Aware, etc.). Most of the programs found the virus but were unable to delete it (I have taken notes of messages I received if you need further information). After all of those were unsuccessful I installed the Hijack This program and saved a log file. I am reluctant at this point to start deleting because although I read the instructions carefully, I am not confident that I will choose the right files to delete.

    My next step would be to take my computer to a professional but would prefer to save some money and do it myself if possible...which is where you come in! I would greatly appreciate any advice you can give.

    Thanks so much!
     
  2. Seargent Geek

    Seargent Geek Private First Class

  3. AbbySue

    AbbySue MajorGeeks Administrator

    Please take the time to familiarize yourself with how things work in this forum before offering your help to members. Hijack this is not a virus or spyware remover...there are other steps that need to be taken before using it. Additionally, if providing links to downloads we ask that you link to downloads here at MajorGeeks rather than to other sites. Thank You.:)



    @ emilyc:

    Please read the Announcement at the top of everypage in the Spyware Forum. Also please read and follow the sticky thread guidelines.

    - Run ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal Make sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.


    After doing ALL of the above you still have a problem:

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
    Last edited: May 5, 2005
  4. emilyc

    emilyc Private E-2

    Okay, I have attached my log.

    Thank you!!!
     

    Attached Files:

  5. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Please look in Add/Remove Programs and uninstall the following programs:

    Viewpoint

    NEXT:
    Please EXTRACT HijackThis from the ZIP File to a Safer location. Here's how:

    To create a new folder:
    Click START > My Computer > Local Disc C: > Program Files
    Now, RightClick on an Empty Area and select New > Folder & name it HijackThis and ENTER

    To Extract HijackThis:
    Now, Right Click your HijackThis ZIP File and select Extract All > Next > and browse to your newly created HijackThis Folder
    (C:\Program Files\HJT) and click Next.

    Now run HJT from there. Please save your HJT Log as a .txt File and attach it via the "Manage Attachments" tool in the Additional Options section when you post.

    The reason HJT needs its own safe folder is so that backups will be safely preserved. That way, if a mistake is made in the removal process, the mistakenly deleted entry can be restored.
     
  6. emilyc

    emilyc Private E-2

    Okay, here's the new log...

    Thanks!
     

    Attached Files:

  7. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Download Pocket KillBox
    (Don't run it yet)

    The first thing I notice is that your running Command Software Systems Anti-Virus and Kaspersky Anti-Virus. Running two antivirus programs is NOT recommended. It can cause conflicts on your computer so pick ONE and uninstall the other.

    Now scan with HijackThis and Check the Boxes for the following:

    Make sure All Browser Windows are Closed when you Click FIX.

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qca10.hpwis.com/
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-qca10.hpwis.com/
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-qca10.hpwis.com/
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://v4.windowsupdate.microsoft.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-qca10.hpwis.com/
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://qca10.hpwis.com/

    O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
    O2 - BHO: MSEvents Object - {B8B55274-0F9A-41E5-9067-A3539BD9E860} -C:\WINDOWS\Fonts\abrlib.dll
    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)

    O4 - HKLM\..\Run: [Win Comm] C:\Program Files\Win Comm\WinComm.exe

    O16 - DPF: {6F750200-1362-4815-A476-88533DE61D0C} (Ofoto Upload Manager Class) - http://www.ofoto.com/downloads/BUM/BUM_WIN_IE_1/axofupld.cab
    O16 - DPF: {C81B5180-AFD1-41A3-97E1-99E8D254DB98} (CSS Web Installer Class) - http://www.commandondemand.com/eval/cod/cabs/cssweb.cab

    O20 - Winlogon Notify: abrlib - C:\WINDOWS\Fonts\abrlib.dll

    Again, make sure All Browser Windows are Closed when you Click FIX.

    NOW:
    Locate PocketKillbox

    Now, Copy and Paste C:\WINDOWS\Fonts\abrlib.dll into the box – If it exists, it will show up in Blue. Check the option to Delete on Reboot and Click the Red X and Yes to the confirmation message. A message will ask if you want to reboot now – Click YES.

    DURING THE REBOOT, BOOT INTO SAFE MODE!

    NOW:
    Navigate to and DELETE the following if they should remain:

    C:\Program Files\Win Comm ←–– Delete this whole folder if it exist!

    C:\WINDOWS\Fonts\abrlib.dll ←–– Double check to make sure this file is gone, if not right click and delete it!

    NEXT:
    Run CCleaner and Spybot S&D and have Spybot fix what it finds.
    Note: Dont forget to update Spybot S&D by selecting "Search For Updates"

    Then, as an added precaution, Go to Start > Run and type: cleanmgr and then click OK. Make sure the boxes for these are checked:
    Temporary Files
    Temporary Internet Files
    Recycle Bin


    And Click OK.


    Reboot to Normal Windows

    FINAL STEP

    Reset Web Settings & Default Security Settings:


    To Reset Web Settings:
    Right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK


    To Default Security Settings:
    Right click on your desktop Internet Explorer icon and select Properties. Then click the Security Tab and click Default Level for Internet, Local Intranet, Trusted Sites, and Restricted Sites.


    After doing ALL of the above,
    Scan with HijackThis and attach the new log.
    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now.

    Good Luck!:)
     
  8. emilyc

    emilyc Private E-2

    No luck unfortunately!

    The virus is still being found. I also receive an error message everytime I restart my computer which has only happened since I went through all of the scans the other day. It says "Runner Error: Invalid BackWeb application id '1940576'".

    I have attached the new hijack this log.

    Thanks for your help.
     

    Attached Files:

  9. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Have HJT create a startup list. Post that log to your next post.
     
  10. emilyc

    emilyc Private E-2

    Here you go!
     

    Attached Files:

  11. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Boot into Safe Mode

    Click Start > Run > type in the following:

    regsvr32 /u C:\WINDOWS\Fonts\abrlib.dll

    If you get any errors or anything let me know!

    Special step to delete abrlib.dll:
    - Click Start, Run, and enter cmd in the box and click OK. This opens a commend prompt windows.
    - Enter the following command lines each followed by the enter key
    cd C:\WINDOWS\Fonts\
    attrib -r -h -s abrlib.dll
    del abrlib.dll
    exit


    Now, run CCleaner!

    After running CCleaner reboot into Normal Mode and attach a fresh HJT log.
     
  12. emilyc

    emilyc Private E-2

    Okay, so part 1 went fine with a RegSvr32 message saying it "succeeded".

    Part 2 did not. After I typed the command "del abrlib.dll" it said "This process cannot access the file because it is being used by another process".

    I still ran CCleaner and have attached a new HJT log.

    I really appreciate all of your help and your patience! I'm still staying positive that we will get rid of this!

    Thanks.
     

    Attached Files:

  13. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    If everything went ok with the unregistering. Boot back into Safe Mode and try to manually delete the file.

    While in Safe Mode scan with HJT and have it fix the below entries:

    O2 - BHO: MSEvents Object - {B8B55274-0F9A-41E5-9067-A3539BD9E860} -C:\WINDOWS\Fonts\abrlib.dll

    O20 - Winlogon Notify: abrlib - C:\WINDOWS\Fonts\abrlib.dll
     
  14. emilyc

    emilyc Private E-2

    Okay, I went into safe mode and tried to delete the file and it said "Can not delete the file because it is being used by another person or program".

    I was able to delete the 2 entries from HJT though.

    Does it make a difference if I boot in "safe mode" or "safe mode with networking"? Should I unplug my modem when I am trying to delete the file? I'm not really sure what this file is and don't know much about these viruses but is someone actually accessing my computer from somewhere else? While in safe mode, should I ctrl+alt+del and end a process that is running?

    Where did this thing come from and why is it so difficult to delete!!??

    Thank you.
     
  15. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Safe Mode w/ Networking is Safe Mode with networking components so your able to access the internet in safe mode, very nice.

    I prefer regular Safe Mode for this removal as its a pain to remove sometimes. Anyway, this is part of Trojan.Vundo and can be difficult to remove sometimes.

    Lets procede with the fix, download the following removal tools:
    Now, Reboot into SAFE MODE and run these removal tools one at a time. Afterwards reboot into normal mode and attach one last HJT log.

    Also, as a reminder, be sure System Restore IS DISABLED!
     
  16. emilyc

    emilyc Private E-2

    Neither of those tools even found the virus. Very strange.

    Also, when I boot into regular safe mode, my computer becomes unstable or something and my screen goes black after only a minute or so. It does not seem to do that when I boot in safe mode with networking.

    I have also tried to manually delete the file again using the safe mode with command prompts and was still told it was being used by another process. Is there any way of finding the process that is using the file, ending it, then deleting the file?

    I can't believe this! Please don't cut me off!

    I have attached another HJT log. Oh yeah, and I double checked that my system is not set to restore.

    Thanks!!!!!!!!!!!!!!!
     

    Attached Files:

  17. Seargent Geek

    Seargent Geek Private First Class

    Quote AbbySue

    No Problem, sorry for that ;)

    Quote AbbySue
    I think, the best before running Hijackthis, would be to reboot on to "safe Mode" :)
     
  18. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Running HJT from Safe Mode does NOT show all entries & processes as normal mode would show. NEVER run HJT from Safe Mode unless special requested by a professional. Sometimes the infection(s) are so bad you have to start by doing this, but very rare.

    Closing your browsers and other progams is the easiest thing to do. If you cant follow those simple instructions then you dont need a computer. LOL!
     
  19. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    emilyc,

    Copy the contents of the Quote Box below to Notepad. Then click File and then Save As. Change the Save as Type to All Files. Name the file fix.reg and then click save. (make sure you save it somewhere you can find it. Saving it to your Desktop may make that easy.)

    Double-click on the fix.reg file on your desktop (or locate it with Windows Explorer and double click on it if not saved to the Desktop) and when it prompts to merge, click YES!

    NOW, Boot Into Safe Mode!

    After your in Safe Mode, open the folder C:\WINDOWS\FONTS

    Now, hit Control+Shift+Esc to open Task Manager. End TASK on explorer.exe
    (Your desktop will disappear, this is normal)

    Now, use Alt+Tab to scroll back to the C:\WINDOWS\Fonts

    Now, delete the file:

    abrlib.dll

    Reboot and attach a HJT log.
     
  20. emilyc

    emilyc Private E-2

    I added the fix.reg to the registry but had problems with the other part. Two things:

    1) While in safe mode, alt+tab does not work. When I end "explorer.exe" the font folder I opened seems to close also so I have no way of getting back to it; and

    2) I do not see the file abrlib.dll in the fonts folder but when I do a search it is there (even though I have it set to show hidden files) so I'm not sure I would be able to just delete it from the folder.

    Hmmmm...
     
  21. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Attach a current HJT log, lets see what remains.
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    First download: - ProcessExplorer for Win NT/2K/XP

    Reboot in Safe Mode (do not open any other processes)

    - Run Process Explorer

    In the top section of the Process Explorer screen double click on winlogon.exe to bring up the winlogon.exe properties screen. Click on the Threads tab at the top.

    Once you see this screen click on each instance of abrlib.dll once and then click the kill button. After you have killed all of the abrlib.dll's under winlogon click ok.

    Next double click on explorer.exe and again click once on each instance of abrlib.dll then click the kill button. Once you have done that click ok again.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: MSEvents Object - {B8B55274-0F9A-41E5-9067-A3539BD9E860} - C:\WINDOWS\Fonts\abrlib.dll
    O20 - Winlogon Notify: abrlib - C:\WINDOWS\Fonts\abrlib.dll

    Copy the bold text below to notepad. Save it as fix.reg to your desktop.
    Be sure the "Save as" type is set to "all files"
    Once you have saved it double click it and allow it to merge with the registry.
    Now run Pocket Killbox:
    Choose Tools > Delete Temp Files and click OK.
    In Killbox - put a check next to "Delete on Reboot"
    Copy & paste the following line in bold into the "Full Path of File To Delete" box:

    C:\WINDOWS\Fonts\abrlib.dll

    Then click the red button with the X and allow Killbox to reboot then post a new HijackThis log.
     
    Last edited: May 10, 2005
  23. emilyc

    emilyc Private E-2

    Oh my gosh I think it's gone!!! Yay!!!!!!! Thank you so much!!!

    Now, my only problem is when I reboot I get the message "Runner Error: Invalid BackWeb application id '1940576'".

    Attached is the new log.

    Thank you!!!
     

    Attached Files:

  24. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Your HJT log is clean!

    Now, for the other problem you mentioned. Since you are now Malware free, please post this problem in the Software Forum. Those guys will get you all fixed up.

    For the time being, please follow all of the steps in this thread.

    How to Protect yourself from malware!
     
  25. emilyc

    emilyc Private E-2

    Excellent! Thank you so much for all of your help...I know it was a huge pain. I feel like I should pay for it. Is there anywhere I can donate or something?

    Thanks!
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    So was it the steps I gave you in message #22 that removed the MSEvents (Virtumundo) problem?

    Do you still have the problem with backweb?

    In the below, replace username with your actual user name.

    Look in C:\documents and settings\username\Start Menu\Programs\Startup
    Do you see a reference in there, like a .lnk file or anything else that is trying to load the backweb file? If so, delete that link.
     
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you did not find it in the location I specified in my previous message look in:

    C:\documents and settings\All Users\Start Menu\Programs\Startup
     
  28. emilyc

    emilyc Private E-2

    Yes, #22 did the trick - thanks!

    So I have looked in C:\documents and settings\username\Start Menu\Programs\Startup. Instead of "username" I have "administrator", "all users", "default user" and "owner". The only file in common with all of them in the startup folder is "desktop.ini".

    I posted my question to the Software Forum and had a user instruct me to do the following:
    "Start>Run>type "msconfig" and hit enter>goto "Startup">Scroll down and find the Backweb Agent and untick the box> Click Apply/Ok>Restart the computer and see if it helps

    *Again* Backweb is an unneccessary program provided by HP/Compaq that sends information from your computer to the HP Centre. Aas it has no effect on your computer whatsoever, it is safe to disable from the Startup options . If the warning should re-appear after doing the above steps, then if you are WinXP, you would need to turn off your System Restore before doing the above steps and then turn on System Restore after you are done....then restart your computer which will give you a brand new restore point without Back Web in it........ "

    I haven't done it yet. Do you agree with this?

    Thanks!
     
  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes! That would work if it is loading at Startup. But what I gave you should find it too. It is basically the same thing. But my method permanently removes it from loading whereas the msconfig method just disables it from loading but then you are never booting your system normally. You will always be in a selective startup mode and msconfig will show as running.

    Try the below for each user account:

    Generate a StartupList log using HijackThis.
    Run HJT and on the first screen, click the button that says "Open the Misc Tools section". In the next window first select "List also minor sections (full)" and then click the button that says "Generate StartupList log". CLick Yes to the Do you want to continue prompt. Now a notepad window will come up with the Startuplist.txt file. It is already saved in the the directory HJT is running from. So just come back here and upload the file as an attachment to your next message.
     
  30. emilyc

    emilyc Private E-2

    Okay, attached is the Startup List Log. I don't really understand what you mean by doing that for each user. There doesn't seem to be any way to specify the user. Also, I couldn't find that .lnk file so couldn't delete it (as per #26).

    Thanks!
     

    Attached Files:

  31. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Notice in the log you just posted:

    You have a shortcut link that is trying to load the file. You need to locate where it is at. Normally this is in the Startup folder as I specified earlier.

    Search your PC for Compaq Connections.lnk and tell me where you find it. It may be something on your Desktop too.
     
  32. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It's like that Compaq Connections.lnk is in one of the Startup folder names I gave you earlier.
     
  33. emilyc

    emilyc Private E-2

    Okay, I searched for Compaq Connections.lnk and it found it 4 times (they are all shortcuts).

    One is just called Compaq Connections and is in C:\Documents and Settings\All Users\Start Menu\Programs\Startup.

    The other 3 are called Compaq Connections, About Compaq Connections, and Disable Compaq Connections are all found in C:\Documents and Settings\All Users\Start Menu\Programs\PC Help & Tools\Compaq Connections.

    Should I click on Disable Compaq Connections?

    Thanks!
     
  34. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    From Windows Explorer, right click on the .lnk file and select Properties and look at the Target. When you find the one that refers to the backweb file, you should just delete that file. It's probably the one in:
    C:\Documents and Settings\All Users\Start Menu\Programs\Startup
     
  35. emilyc

    emilyc Private E-2

    When I click delete it says "Deleting the shortcut to Backweb-1940576 only removes the icon. It does not uninstall the program." Should I uninstall the program? Do I need it for anything?

    Thanks!
     
  36. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do not uninstall it for now. Just make sure you no longer get that message at reboot.

    Do you need this program? I doubt it. But it as long as it is not loading you should not have to worry about it. It is not a true bad malware issue but it does fit into the broad definition of what malware covers.
     
  37. emilyc

    emilyc Private E-2

    Sorry...I'm high maintenance!

    After deleting 2 shortcuts, I just found "BackWeb-1940576.exe" in C:\Program Files\Compaq Connections\1940576\Program\. That's what I should be deleting right? Just want to make sure. I searched for "backweb" and found about 60 for Spybot and 4 others under BackWeb Client/6.2.3.66L/Program. Are they bad?

    Thanks!
     
  38. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You don't need to delete it. We are just trying to get rid of the error message you saw at startup.
    And if we decided you did want to remove this program, the proper method to remove this would be to first look in Add/Remove programs for an uninstall. If that does not exist or did not work, we would then manually approach the removal.

    If you remove these files without removing the items (links) that are referring to them, you will get error messages when they try to load.
     
  39. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Is the below line still in your HJT log:

    O4 - Global Startup: Compaq Connections.lnk = C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe

    If so, just have HJT fix that line. That should stop your system from trying to load the file and get rid of the error message.
     
  40. emilyc

    emilyc Private E-2

    Well, it looks like deleting the shortcuts worked!

    Thank you very much for your help. My computer is running so perfectly now - what a relief!
     
  41. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    emilyc,

    Glad everything is running good for you:)

    To keep your system clean, I would recommend following ALL of the steps in this thread.

    How to Protect yourself from malware!

    Browse Safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds