Trojan.Agent

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by meloney, Jun 23, 2008.

  1. meloney

    meloney Private E-2

    Hello:major

    What is the best thing to get rid of a TROJAN.AGENT?

    I run malware bites, it says its removed it and then its back again, the little bugger!

    Im in the process of using AGB Ghostbuster that i got from your site. Will this be enough?

    Mel the Moo:tas
     
  2. meloney

    meloney Private E-2

    Its hyding in
    HKEY_LOACALMACHINE\SOFTWARE\MICROSOFT\windows NT\currentVersion\drivers32\midi2

    SO could i go into reg edit and remove MIDI2 or could i copy a MIDI2 from another PC to it and clear it?
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please follow the instructions in the below link and attach the requested logs when you finish these instructions. If something does not run, write down the info to explain to us later but keep on going. Do not assume that because one step does not work that they all will not.

    READ & RUN ME FIRST. Malware Removal Guide
     
  4. meloney

    meloney Private E-2

    Hi Ok all went ok..

    Spybot, said it had a lot of crap but it cleared it. So it says!

    Malware bites, had virus, again says its cleared but dont think it is!!!

    and when i had to cut and paste that section in cf.exe it woudlnt do it.


    so thats it so far.
     

    Attached Files:

    • log.zip
      File size:
      40.1 KB
      Views:
      1
  5. abri

    abri MajorGeek

    Hi meloney,
    There are very specific instructions in the READ & RUN ME. When you complete them, please attach the requested logs. If you aren't able to complete a scan, describe what happens and what error messages you get. If the scan reports that everything is clean, we still want to see the results.
    Thanks.
    abri
     
  6. meloney

    meloney Private E-2

    here is the cf.exe run report, ahve you everything you need now?
     

    Attached Files:

    • log.txt
      File size:
      11.7 KB
      Views:
      1
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Actually you attached everything we needed in you first ZIP file except the log from SUPERAntiSpyware. Please attach this. Also in the future, please do not make your own zip files unless the files are too larger to upload when unzipped. Just attach the files as requested.

    Do you have any idea what the below files are?
    Code:
    2008-06-23 18:40 . 2008-06-23 18:40 0 --a------ C:\WINDOWS\system32\11.CPX
    2008-06-16 23:00 . 2008-06-16 23:00 495 --a------ C:\WINDOWS\system32\121.CPX
    2008-06-16 23:00 . 2008-06-16 23:00 316 --a------ C:\WINDOWS\system32\112.CPX
    What actual malware problems/symptoms were you having that prompted you to run Malwarebytes to begin with? Based on your logs, I would say none.

    Please do the below.

    Click Start, Run and copy and paste the below string into the Run box and then click OK.

    regedit /E C:\driver32.txt "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32"

    Then attach the C:\driver32.txt file that will be created to your next message.

    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 10
    J2SE Runtime Environment 5.0 Update 3
    Java 2 Runtime Environment Standard Edition v1.3.1_04
    Java(TM) 6 Update 2
    Java(TM) 6 Update 3
    Java(TM) SE Runtime Environment 6 Update 1

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - (no file)
    O3 - Toolbar: (no name) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file)
    O4 - Startup: PowerReg Scheduler.exe
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.

    Then attach the below log:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Jun 24, 2008
  8. meloney

    meloney Private E-2

    I had a Trogen Agent and in malware bites it would remove it then it would return! I didnt get offered to keep a report for super anti spyware..

    I will do the enclosed and get back to you.
     
  9. meloney

    meloney Private E-2

    Ok I put all 4 logs in a zip as there was not enough room for them on here..

    I did the copy and paste of

    regedit /E C:\driver32.txt "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32"

    It didnt work and this didnt work C:\MGtools\GetLogs.bat it said

    PROCESS Dll.EXE ERROR FAILED (OXC0000135)

    But after doing all that and running malware bites its clean.
     

    Attached Files:

    Last edited: Jun 24, 2008
  10. meloney

    meloney Private E-2

    and here is regedit
     

    Attached Files:

  11. meloney

    meloney Private E-2

    regedit was ok
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I did not ask for this?
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes they both worked and the processdll.exe error is explained on the Using MGtools download page.


    It does not matter anyway since based on your log it appears to be a false positive. You still show the same midi2 subkey and it is just set to "midi2"="wdmaud.drv" This is not a problem.
     
  14. meloney

    meloney Private E-2

    Does this mean, everything is fine now with the PC?

    Only I really dont understand , due to the fact that I followed the process you wrote down on here, and then was told it was not what you asked for so im confused.!
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes everything is fine. You did not have any malware from the start. What we fixed were just some old Java software versions, some left over registry keys from GoogleToolbar, and a couple of other unnecessary items.

    Abri was incorrect. As I said in message # 7 you only left out the SUPERAntispyware log.

    Now we need to cleanup from running the READ & RUN ME.
    1. You can uninstall SUPERAntiSpyware now.
    2. We recommed you keep Malwarebytes Anti-Malware as a scanner. It uses no resources except a little disk space until you run a scan.
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\cf" /u
        • Notes: The space between the cf" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\cf folder from combofix.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  16. meloney

    meloney Private E-2

    Thank you very much for your time and help..

    Meloney from the UK but based in sunny Spain..:wave
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome Meloney. Enjoy the sun :) and surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds