Win32.trojan.agent removal from XP - check results

Discussion in 'Malware Help (A Specialist Will Reply)' started by camep, Mar 22, 2008.

  1. camep

    camep Private E-2

    Hello Everybody!

    Just let me tell you that I have already run all indications to remove this trojan placed in http://forums.majorgeeks.com/showthread.php?t=139313

    I really appreciate your help if you can confirm that my PC is cleaned. I enclosed the result logs from the instructions above.

    Thanks!
    Camep :)
     

    Attached Files:

  2. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Hi and Welcome to Majorgeeks

    Please do follow this guide to the letter and attach the full MGlogs.zip file as instructed in the guide as the other logs are needed.

     
  3. camep

    camep Private E-2

    Hello Halo!

    Thanks for the indications! :) Just found the file in "C:\" and attached it in this post.

    Thanks,
    Camep
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to attach the requested log from ComboFix as stated in the READ & RUN ME. Based on your logs I can see you ran it. Just attach the C:\combofix.txt log.


    Uninstall the below as requested in the READ ME:
    J2SE Runtime Environment 5.0 Update 6
    J2SE Runtime Environment 5.0 Update 9
    Then reboot your PC.

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment


    You need to also go back to step 1 of the READ ME and put your system into normal startup mode using MSconfig as was requested. You have malware items trapped in there and we cannot finish cleaning your PC until you follow the instructions properly.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.

    Then attach the below log:
    • C:\MGlogs.zip
     
  5. camep

    camep Private E-2

    Dear Chaslang,

    Thank you for your patience. I have already followed instructions stated in the READ & RUN ME.

    After I reboot in Normal Startup Mode I let all applications run despite WinPatrol kept asking me whether or not allow them to auto-run. Just disable one: "Antivermins.exe". I thought I got rid of it before but it seems still there - I am aware it is a dangerous malware!

    Anyway I enclosed the logs again. I hope you can help me. Many thanks! :)

    Camep
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Which is one of many reasons why we specify not to use MSconfig. It is trapped in there and we needed to get it fixed and now it is.


    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to Symantec Core LC
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Click OK until you get back to Windows.


    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {7c1ce531-09e9-4fc5-9803-1c2956615786} - (no file)
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - Global Startup: PowerReg Scheduler.exe
    O9 - Extra button: Coches - {AF0828BC-CB46-4C8D-95B6-8A7C4988F9FF} - c:\europillamusica2\entrar.html (file missing)
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    After clicking Fix, exit HJT.

    Now reboot your PC.

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.

    Then attach the below log:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  7. camep

    camep Private E-2

    Hello Chaslang,
    I have followed all steps on your post and now I enclosed the file. Please confirm if everything is ok now.

    Thanks for your help! ;)
    Camep
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your logs are clean.


    If you are not having any other malware problems, it is time to do our final steps:
    1. Uninstall COMBOFIX (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\cf" /u
        • Notes: The space between the cf" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    2. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    3. If you are running Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    4. After doing the above, you should work thru the below link:
     
  9. camep

    camep Private E-2

    Thank you! I believe everything is ok now! :D

    Just a question, after I uninstalled combofix a folder was created in "C:" with the name "cf" and there are the following files inside: "nircmd.cfexe", "CF31380.exe"

    Can I erase these files or should be kept in there?

    Camep
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You can delete this folder now.


    You're welcome. Surf safely.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds