Trojan.Win32.Agent.akk help

Discussion in 'Malware Help (A Specialist Will Reply)' started by boarderair, Dec 5, 2007.

  1. boarderair

    boarderair Private E-2

    I have been getting a box (looks like a windows system message) that pops up periodically and randomly on my screen that says my computer has Trojan.Win32.Agent.akk, then says to click below to get the software to clear the trojan (recommended). I can click "OK" or "No thanks" (I think - I only copied down the name of the trojan).

    My computer seems to be running somewhat slower than normal and seems like it may be starting to overheat.

    I tried a system restore to 3 days ago and this did not fix my problems.

    I have run Norton Internet Security Full System Scan, Spyeraser, and AVG Antivirus (Free Edition), but nothing has been found. I downloaded hijackthis and did a scan.

    I am not great with computers, but follow directions well. I have not done the "Read and Run me first". Any suggestions?

    Thank you so much for your time and your willingness to help!
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Yes! Run it and attach the requested logs! ;)

    Did you purchase Spy Eraser?
     
  3. boarderair

    boarderair Private E-2

    The trojan message just popped up again and it reads:
    "Critical System Error!
    Your browser was hijacked by Trojan.Win32.Agent.akk
    You need to clean your system immediately, in other case it can be crashed soon!
    Click OK to download the high-tech antispyware protection software! (recommended)"
    Then I can click "OK" or "Cancel", but every time I just click the X in the corner to close the box.

    Does anyone know anything about this trojan? (What it does, the information it gathers/steals, the long-term consequences?)
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  5. boarderair

    boarderair Private E-2

    I have done "run and read me". I even did the "Basic computer maintenance everyone should do". Unfortunately, I am still having this problem. And it is actually occurring much more frequently now (almost every time I click on a link or even the "back" arrow in internet explorer).

    Attached are the logs from the run and read me steps. Would it be useful for me to post the hijackthis log file too?

    Also, when I tried to run msconfig, I get a message that says "windows cannot find msconfig". I made sure it was spelled correctly and tried different possibilities of capital and lowercase letters, but just got the same message. I don't know if this is due to this Trojan or if it is a preexisting, unrelated problem.

    I bought The Uniblue PowerSuite a few months ago, so I have Spyeraser, Registry Booster 2, and Speed Up My PC. In attempt to fix this problem, I have run all 3 of these programs.

    Thanks again for all of your help!
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not attach a log file from AVG Antispyware. You have to create it as instructed in the READ ME.

    No it would be a waste of time. We already have one from running MGtools. ;)

    We will see later after fixing any malware. The msconfig.exe file is on your PC. I can see it in your logs.

    C:\WINDOWS\pchealth\helpctr\binaries\msconfig.exe


    At the very beginning of the READ ME, we specified that you must not use multiple antivirus programs. You must uninstall either AVG 7.5 or Norton now. Do this before you continue on to the below.

    You MUST stop storing executable files and other files in the C:\Program Files folder. In fact you need to remove all of the stuff you have save there. This folder MUST only be used for installed programs. Thus you should only see folders here that are the folders for the installed programs. You have load of things you saved here and may of them look like malware to us and to scanners simply because of where they are located. This is a dangerous place to save your downloads. Here is an example of some of the items I see:
    Code:
    2007-03-12 23:40 17 ----a-w C:\Program Files\stng260.opt
    2006-10-15 07:11 41,473,256 ----a-w C:\Program Files\NIS07100.exe
    2006-10-15 07:05 5,043,712 ----a-w C:\Program Files\SymADataWeb.msi
    2006-07-12 15:56 39,634,472 ----a-w C:\Program Files\sp31101.exe
    2006-06-16 14:23 1,502,848 ----a-w C:\Program Files\taskmanager16.exe
    2006-02-15 19:15 4,844,728 ----a-w C:\Program Files\SP30655.exe
    2006-02-15 19:14 5,906,896 ----a-w C:\Program Files\SP29528.exe
    2006-02-15 19:14 1,285,080 ----a-w C:\Program Files\SP30222.exe
    2006-02-10 00:19 1,296,020 ----a-w C:\Program Files\ePOStg256.Zip
    2006-02-10 00:17 17 ----a-w C:\Program Files\stinger.opt
    2005-12-15 01:08 2,336,720 ----a-w C:\Program Files\SMFCUSetup09152.exe
    2005-12-15 00:55 703,909 ----a-w C:\Program Files\SonicStageInstaller.exe
    2005-11-20 00:14 948,936 ----a-w C:\Program Files\install_flash_player.exe
    2005-11-02 15:59 2,855,080 ----a-w C:\Program Files\aawsepersonal.exe
    2005-10-15 14:02 6,660,880 ----a-w C:\Program Files\awmaw.exe
    2005-04-08 15:01 9,964 ----a-w C:\Program Files\o2003PIA_ReadMe.rtf
    2005-04-06 00:46 5,231,104 ----a-w C:\Program Files\O2003PIA.MSI
    2005-03-22 19:10 10,603 ----a-w C:\Program Files\o2003PIA_EULA.txt

    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 2
    J2SE Runtime Environment 5.0 Update 4
    J2SE Runtime Environment 5.0 Update 6

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - (no file)
    O2 - BHO: System DivX4 - {2FA3B736-1AC7-454D-8E94-8BA8158BF064} - C:\WINDOWS\system32\sysvideo32.dll
    O3 - Toolbar: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it
    double click it and allow it to merge with the registry.
    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    Make sure you tell me how things are working now!
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    By the way, can you tell us where you got this infection from. This HijackThis line

    O2 - BHO: System DivX4 - {2FA3B736-1AC7-454D-8E94-8BA8158BF064} - C:\WINDOWS\system32\sysvideo32.dll

    reminds us of another infection and we would like to investigate this in more detail by attempting to get the infection on a test PC where we can evaluate exactly what it does.
     
  8. boarderair

    boarderair Private E-2

    Well, it seems that the trojan is gone, as the message has not popped up yet today (even when I click on folders/files/links that used to make it pop up). :)

    The file is attached. I had done everything right except finding the correct file when attaching. Sorry! :eek:

    I only downloaded AVG 7.5 in attempt to remove the trojan. It was a recommendation given to someone in another post (on another site) so I figured I would try it. I did not realize it was equivalent to Norton. It has since been uninstalled.

    I did not know that it is not a good idea to store those files there. They have all been deleted.
    The avenger log indicated that C:\\WINDOWS\Temp\slu6a42.tmp is a folder, not a file, so I ran avenger again, with:
    Folders to delete:
    C:\\WINDOWS\Temp\slu6a42.tmp
    and the next log indicated that the deletion had been successful.
    Additionally, avenger could not delete C:\Documents and Settings\Kim\Desktop\hijackthis.log, so I deleted it manually.

    Actually, I am in medical school and doing a rotation in OB/GYN and we have been learning about sex therapy and patients who practice bestiality. In an attempt to research more about this, I clicked on the following link:
    -LIVE MALWARE URL REMOVED - ~SPD~ Thanks I have it now for analysis
    Embarrassing to admit, but hopefully it will help you.

    Should I do something about this? Or is it not important?

    Any suggestions on what else I can do to protect myself from problems like this in the future? (Other than not clicking on bad things again, running norton internet security, etc; Are there any programs I should download/buy and/or make a point to run regularly?) Also, since you have seen my logs, do you have any suggestions on how to improve my computer's performance and/or how to best protect my computer (is it worth the $ to renew norton internet security/Uniblue powersuite annually?)

    I think that's about it. Thank you so much for your help and sticking with me on this! It is greatly appreciated!!!
     

    Attached Files:

    Last edited by a moderator: Dec 6, 2007
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay but remember that in the future you should never under any circumstances, install another antivirus program without first having uninstalled the first one. This can cause many problems including make each program much less effective and it can totally mess up your Windows Security Center.


    Not a problem! ;) We are not here to judge what people do with their computers. We only recommend against doing various things for security reasons. Thanks for owning up and posting the link. As you can see ShadowPuterDude (SPD) got it and removed it for everyone's security. We can now experiment with this to improve malware removal techniques. SPD is constantly improving a tool called FixIEDefender and your form of infection will now be added to it.

    If you click Start, Run, and enter msconfig and click OK. What happens?

    All covered in my final steps.

    Personally I would say no. The free tools in my final instructions work perfectly fine with less drain on your system resources and pockets! ;)

    You're welcome.


    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, C:\combofix.txt and C:\ComboFix-quarantined-files.txt logs that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    9. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    10. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    11. After doing the above, you should work thru the below link:
     
  10. boarderair

    boarderair Private E-2

    I get a box that pops up that says "Windows cannot find 'msconfig'. Make sure you typed the name correctly, and then try again. To search for a file, click the start button, and then click search."

    Thanks again for your help! :D Truly a lifesaver!!!
     
  11. boarderair

    boarderair Private E-2

    Oh, and I had one last question. When I did the avenger step in your directions, I saw in the log that the C:\WINDOWS\system32\sysvideo32.dll file was not able to be deleted.

    Could it be possible that the trojan is still on my computer, even though I am no longer having problems? (Since that file was not deleted by avenger)

    Thanks again!!!
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No it was deleted at some point. It would show in your newfiles.txt log if it was still there. You can compare your first log to your last log and see it is gone. I never saw an Avenger log that said it was not deleted. You overwrote it when you ran Avenger a second time and you only posted the second log.
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Right click Start and select Explore to open a Windows Explorer window. Now navigate to the below folder:

    C:\WINDOWS\PCHealth\HelpCtr\Binaries

    You should see the MSCONFIG.EXE file here.
    • Double click on it and tell me what happens.
    • If it does not run, right click on the MSconfig.exe file and select Open. Tell me if that runs it.
     
  14. boarderair

    boarderair Private E-2

    The System Configuration Utility box pops up and looks normal (or at least how I think it should).
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay let's retry something we previously did but with a slight change.


    Click Start, Run, and enter msconfig.exe and click OK. What happens?

    Note: this time I have msconfig.exe not msconfig.
     
  16. boarderair

    boarderair Private E-2

    Same message... "Windows cannot find msconfig.exe..."
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Click Start, Run, and enter regedit and click OK. What happens?

    Also try the below:

    Click Start, Run, and enter cmd and click OK. What happens?
     
  18. boarderair

    boarderair Private E-2

    The registry editor pops up and looks normal.

    The C:\\WINDOWS\system32\cmd.exe box pops up and looks normal.
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Now Copy the bold text below to notepad. Save it as fixMSC.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Now reboot!
    After reboot, can you run MSconfig now from the Start, Run box.
     
  20. boarderair

    boarderair Private E-2

    It works!!!
    Thank you so much again for all of your help. It's nice to know that not everyone who's good at computers likes to make other people's lives miserable by creating viruses!
    Keep on doing what you do. We all find a way to make a difference in the world and you're doing a great job!
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Make sure you have complete all of my final isntructions from message # 9.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds