trojan.win32/agent

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Joey Jiggles, Feb 9, 2012.

  1. Joey Jiggles

    Joey Jiggles Corporal

    My computer is running very slow. Everything freezes constantly and once to the point of no return. I did whatever I could to try and help the computer so I ran a system care test and saw the trojan.win32/agent. I then ran a malware and nothing came up and then a superantivirus. Mgtools will not work! It says the path can't be found. I attached the superanti.

    Thank you guys!
     

    Attached Files:

  2. Joey Jiggles

    Joey Jiggles Corporal

    I finally got MGTools to work!
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It looks like you may have a faked partition:
    Disk #0, Partition #2 4984519680 Unknown

    Preferably from a clean computer, I need you to download: gparted-live-0.11.0-7.iso (114 MB)
    Create a bootable CD for GParted. You can use ImgBurn to accomplish this.
    If you need help on how to use ImgBurn, please view this guide by dr.m -- Using ImageBurn to Burn an ISO image

    Now boot off of the newly created GParted CD.
    [​IMG]
    You should be here...
    Press ENTER
    [​IMG]
    By default, do not touch keymap is highlighted. Leave this setting alone and just press ENTER.
    [​IMG]
    Choose your language and press ENTER. English is default [33]
    [​IMG]
    Once again, at this prompt, press ENTER
    You will now be taken to the main GUI screen below
    [​IMG]
    According to your logs, the partition that you want to delete is 4984519680B (4.98MB)
    Click the trash can icon to delete and then click Apply.
    You should now be here confirming your actions:
    [​IMG]
    Now you should be here:
    [​IMG]
    Is boot next to your OS drive? According to your logs, your OS drive is the 293.39 GB sized partition.
    [​IMG]
    If boot is not next to your OS drive under Flags, right-mouse click the OS drive while in Gparted and select Manage Flags

    In the menu that pops up, place a checkmark in boot like the picture below:
    [​IMG]
    Now press the Close button to save these changes.
    Now double-click the [​IMG] button.
    You should receive a small pop up like this:
    [​IMG]
    Choose reboot and then press OK.


    Now reboot from the Windows XP Recovery Console CD and execute the following commands pressing ENTER after each:

    • fixmbr
    • fixboot
    • exit
    Once back in Windows...
    [​IMG] Re-run another scan with MBRCheckand attach its latest log. (How to attach)
     
  4. Joey Jiggles

    Joey Jiggles Corporal

    How do you reboot using that cd? And I don't think I have a windows recovery cd. So what should I do?
     
  5. Joey Jiggles

    Joey Jiggles Corporal

    Ok so my computer wasn't picking up the cd but I searched it and hit F12. That worked. I came to this screen and got scared. Can you please tell me which one to do? The unallocated was the smallest size technically (trash icon wouldn't light up when I selected it anyway) and the next one up in size was labeled DellRestore so I was nervous. Can you please tell me which one to throw in the trash? I post a pic from my phone. I also downloaded a recovery console cd as well. So I will be prepared for that step.

    Thank you.
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Frankly, that is not what I expected to see. Your logs don't even see the 2.98 unallocated partition. And yes, the Dell recovery partition was not recognized as such, which you don't want to remove. Let me think on this. If anything, we probably want to remove the unallocated one. Hang on.
     
  7. Joey Jiggles

    Joey Jiggles Corporal

    Ok thank you so much. It's my work computer and my boss is not happy with me haha. So I will be sitting here waiting on my laptop. The unallocated one I can't delete because the trash icon does not become available when I click on it.

    For an update.. my computer will start to the password screen. Once I type my password and hit enter it freezes. Just throwing it out there.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Why are multiple firewalls installed and running??????

    You need to uninstall Comodo immediately!

    Also uninstall the below:
    Advanced SystemCare 5
    Ask Toolbar
    Java(TM) 6 Update 26

    Then reboot your PC and see how it is running.

    Also install the current version of Sun Java from: Sun Java Runtime Environment


    Why weren't copies of logs from Malwarebytes and ComboFix posted?
     
  9. Joey Jiggles

    Joey Jiggles Corporal

    I dont know man. I guess I was being extra cautious. The problem is, I can't get my computer started! It freezes after I try to log in. Now you have me really nervous. Please help.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try safe boot mode
     
  11. Joey Jiggles

    Joey Jiggles Corporal

    Ok so Safe Mode worked, but I can not uninstall Comodo, Ask toolbar, or Java. Advance system care did remove. This is the message I get when I try to remove the others.

    Add or Remove Programs:
    The windows installer service could not be accessed. This can occur if you are running windows in safe mode, or if the windows installer is not correctly installed. Contact your support personnel for assistance.

    Update:
    And I tried restarting it normally. It did get pass the password screen, but then the hour glass just sits there and I can't click on anything.
     
    Last edited: Feb 13, 2012
  12. Joey Jiggles

    Joey Jiggles Corporal

    Update 2:
    I looked up how to uninstall in Safe Mode and was going to use it, but now it won't start in Safe Mode either. The black and white list loads up and then just stays there.
     
  13. Joey Jiggles

    Joey Jiggles Corporal

    Update 3:
    My computer now does this when I try to restart it normally (blue screen):
    Stop: c0000218 {Registry File Failure}
    The registry cannot load the hive (file):
    \systemroot\system32\config\software
    or its log or alternate.
    It is corrupt, absent, or not writable
     
  14. Joey Jiggles

    Joey Jiggles Corporal

    You guys are going to kill me, but I just want to give you all of the info I possibly can by the time you read this. I have been just trying to get my computer started and it started up out of nowhere noramlly! So I uninstalled the things you told me. I am going to do another mgtools log and send it to you shortly.
     
  15. Joey Jiggles

    Joey Jiggles Corporal

    Ok so I have not restarted my computer since I did all of the removals of the programs you listed because I just want to be able to work today unless you think I am good. I attached my MGtools log to this post. Looking forward to your reply.
     

    Attached Files:

  16. Joey Jiggles

    Joey Jiggles Corporal

    So I left it on and tried doing some work. Nothing online or crazy. It froze then went to the blue screen. Now it won't start in either modes.
     
  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Have you tried hitting F8 and going to Last Known Good config?
     
  18. Joey Jiggles

    Joey Jiggles Corporal

    I tried and the screen just goes to black. Just like when I try and start it up normally. I don't understand I had everything running today.

    Did you see my logs?

    Update:

    Windows could not start because the following file is missing or corrupt:
    \Windows\System32\Config\System

    You can attempt to repair this file by starting Windows Setup using the original Set up CD-ROM.
    Select 'r' at the first screen to start repair.
     
    Last edited: Feb 13, 2012
  19. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I did, but there isn't much we can do it you can't boot. What is the message when you got the BSOD?
     
  20. Joey Jiggles

    Joey Jiggles Corporal

    Windows could not start because the following file is missing or corrupt:
    \Windows\System32\Config\System

    You can attempt to repair this file by starting Windows Setup using the original Set up CD-ROM.
    Select 'r' at the first screen to start repair.
     
  21. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  22. Joey Jiggles

    Joey Jiggles Corporal

    The first step they are talking about a CD I do not have, is this the same as the Recovery Console you have told me to download earlier?

    If I can get it to start. Do you have any steps I should follow so I can act immediately?
     
  23. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes, you need a Recovery Console disc or your install disc.
     
  24. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It's been suggested that trying Last Known Good Config multiple times may get it to boot.
     
  25. Joey Jiggles

    Joey Jiggles Corporal

    I downloaded the recovery console and tried to start it up with the disc. It just goes to black. Is there any steps you can think of for me to try? Also, can you sort of explain what is going on here!? I'm so confused on why this computer is just dying and it is very important.

    Thank you.
     
  26. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    In order to access the Recovery Console, you have to first go into the bios and change the start up order to CD/DVD as first boot device. Then insert the disc and reboot.

    Your issues are more system related than malware. Just follow the instructions in the link I gave you to MS once you boot to the RC.
     
  27. Joey Jiggles

    Joey Jiggles Corporal

    I tried again my recovery console cd by hitting F12 and selecting to start from my cd-rom which I have Recover Console burned onto. To make sure I even have that right, I downloaded Recovery console to my desktop as a .rar file. Then used ImageBurn and burned it to a cd as an image. Right?

    So the Windows Setup screen came up and there was a grey bar at the bottom loading stuff and then it went back to the blue screen of death after about a 1 min. of loading.

    I can't believe this is happening!
     
  28. Joey Jiggles

    Joey Jiggles Corporal

    ok.. So I finally got through to the Windows Setup. I hit 'r' for repair and then when I am at the prompt screen I start off with what that site you gave me says.. I type 'md tmp' and it responds Access Denied. Or I type in the next line they gave me and it says access denied.
     
  29. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Try typing:
    fixboot
     
  30. Joey Jiggles

    Joey Jiggles Corporal

    It says.. FIXBOOT cannot find the system drive, or the drive specified is not valid.
     
  31. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It sounds like it is no longer recognizing your hard drive. I suggest you post in the software forum to try to get your system to boot again.
     
  32. Joey Jiggles

    Joey Jiggles Corporal

    ok thank you.
     
  33. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are welcome. I see you have been helped in the software forum. Good luck and I hope everything works out. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds