trojan.win32.agent.akk

Discussion in 'Malware Help (A Specialist Will Reply)' started by redandblues, Dec 7, 2007.

  1. redandblues

    redandblues Private E-2

    i have the dreaded "trojan.win32.agent.akk" problem as it seems everyone else does that is using this forum. I have tried ALL of your steps to remove this manually with no luck. Can anyone help
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    1. Download FixIEDef.zip by ShadowPuterDude to the Desktop.
    * NOTE: It must be saved to your Desktop or it may not work properly
    2. Double-click FixIEDef.zip, this will create a folder named FixIEDef on your Desktop.
    3. Double-click of the FixIEDef folder.
    4. Locate FixIEDef.bat and double-click on it.
    5. FixIEDef will now run.
    6. Press any key to close the CMD Console when the script is finished.

    Note: process.exe is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool". It is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  3. redandblues

    redandblues Private E-2

    here it is...hopefuly you can help me with this damn thing!! thanks!
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Did you run the FixIEDef tool?
     
  5. redandblues

    redandblues Private E-2

    yes. i followed your instructions as you told me.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    At the very beginning of the READ AND RUN ME is the below very very important note which you seem to have ignored
    You need to either uninstall Avast of CA etrust.

    Then you should C:\MGtools\GetLogs.bat and attach the new MGlogs.zip file so that TimW can continue to help you. Also please explain any malware symptoms that remain.
     
  7. redandblues

    redandblues Private E-2

    ok...i uninstalled CA antivirus and ran MGTools. The .zip file is attached.Thanks

    Very strange....i just got off work 10pm est and got online to find the "pop up" is not manifesting itself. I dont know if it has been destroyed but it isnt bothering as usual. My computer seems to be running better also. I dont know?:confused
     
  8. redandblues

    redandblues Private E-2

    sorry...forgot to attach...here it is.:D
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It should be running a lot faster without all the stuff that CA eTrust had installed. ;)

    Your log shows that you have MSconfig being used. Please set it to Normal Startup as requested in the READ ME and then attach a new MGlogs.zip file from running C:\MGtools\GetLogs.bat again.
     
  10. redandblues

    redandblues Private E-2

    here ya go...hope this is the right one

    if you dont already know, i stopped getting the generic pop up message from trojan.win32.agent.akk...i dont know what happened and i would like to think my pc is cured lol. i would still like to have it confirmed if possible...thanks again
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not completely clean yet. After the below you should be.



    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O2 - BHO: System DivX4 - {2FA3B736-1AC7-454D-8E94-8BA8158BF064} - (no file)
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

    After clicking Fix, exit HJT.

    Please put a copy of the below file into a ZIP file and attach it here.
    C:\WINDOWS\system32\swsc.exe

    There are valid files with this name but it is normally a different size. I want to see if yours is valid.

    Delete the below file which is part of your infection
    C:\WINDOWS\system32\sysvideo32.dll

    Also delete all files in the below folder except ones from the current date (Windows will not let you delete the files from the current day).
    C:\Documents and Settings\Matthew Stobbe\Local Settings\Temp

    Now run CCleaner

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    Make sure you tell me how things are working now!
     
  12. redandblues

    redandblues Private E-2

    here they are....i am not sure what you are talking about "avenger"...could you explain further?
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry! That was something that is part of a boilerplate that needed to be edited out for your fix. I forgot to do it. ;)

    The swsc.exe file is okay. It is just a newer version of the tool I was referring to.


    You're logs are clean. If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, C:\combofix.txt and C:\ComboFix-quarantined-files.txt logs that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    9. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    10. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    11. After doing the above, you should work thru the below link:
     
  14. redandblues

    redandblues Private E-2

    i have done everything you have asked but i have one last thing. In the "how to protect yourself from malware" post I went through the post (following the instructions)and ran into a problem. When the post reccomended a firewall, I chose the OUTPOST firewall program. After DL'ing the software i rebooted and started back up. I didnt do anything spectacular with the new firewall(few options it asked me to complete at first) and was absolutely not able to connect to the internet whatsoever.

    I think it is a good idea to have a firewall(other than microsoft)after reading the info on microsoft's firewal but i had to uninstall just to get back on here to ask you this question. What did i do wrong and why wasnt i able to get on the net?
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sounds like you may have blocked your browser from having internet access thru the firewall. iexplore.exe (or whatever browser you use) must be allowed internet access. And so do a variety of other processes. A firewall will often ask you whether to allow or deny a process the first time it sees he process run. For a process like iexplore.exe you need to allow and tell it to Always allow so that you don't get asked everytime.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds