Trojan Horse Agent_r.XJ Infection

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Ark07, Apr 30, 2011.

  1. Ark07

    Ark07 Private E-2

    Hi

    I had a trojan Horse Agent_r.XJ attack yesterday. My AVG Anti virus detected it but could not remove/heal it. Today I came across one of your thread on the same virus and many people had recommended running TDSS Killer, I tried running it but everytime I tried to install it - it stopped at 80%.

    Then I came across Malware Removal/Cleaning Procedure thread and i followed all the instructions and I still have the infection.

    Out of all the tools mentioned in the Malware removal thread, I could not run
    combofix.exe and RootRepeals

    When I try to run combofix.exe, i get the following BSOD

    https://lh5.googleusercontent.com/_vivsr_KOJ9M/TbwjJ-5xHaI/AAAAAAAABGY/1r-StNUVWuw/Error_after_running_combofix.jpg

    And when I tried to run RootRepeals, I got the following message

    https://lh6.googleusercontent.com/_vivsr_KOJ9M/TbwjY1TilGI/AAAAAAAABGk/34j9-PxZ5QA/Rootrepeal_error.jpg

    I will attach the logs of MBAM, Super Anti Spyware and MGTools below

    I think i have run all those programs correctly. I'm not sure what steps to take next, any help would be greatly appreciated. Thanks in advance!
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Do you have your Win7 install disc? If so, you need to boot to the bios and change the boot order to cd/dvd as first boot device. Then put in your disc and boot to the cd. Then:

    To run the Bootrec.exe tool, you must start Windows RE. To do this, follow these steps:

    1. Put the Windows Vista or Windows 7 installation disc in the disc drive, and then start the computer.
    2. Press a key when you are prompted.
    3. Select a language, a time, a currency, a keyboard or an input method, and then click Next.
    4. Click Repair your computer.
    5. Click the operating system that you want to repair, and then click Next.
    6. In the System Recovery Options dialog box, click Command Prompt.
    7. Type Bootrec.exe /fixmbr , and then press ENTER.

    Boot into normal mode and then do this:

    Download The Avenger by Swandog469, and save it to your Desktop.

    * Extract+ avenger.exe from the Zip file and save it to your desktop

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    * Run avenger.exe by double-clicking on it.
    * -Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now run Ccleaner to clean out only temp files and nothing else!

    Make sure this folder is cleaned out:
    C:\Windows\Temp\

    Please also download MBRCheck to your desktop

    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...

    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:

    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).Make sure that you watch for the license agreement for TrendMicro HijackThis and click on the Accept button TWICE to accept ( yes twice ).

    Then attach the below logs:
    * MBRCheck log
    * C:\Avenger.txt
    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  3. Ark07

    Ark07 Private E-2

    The problem is I don't have the Windows 7 installation disc. :( Is there no way I can repair without having to boot with the Installation disc?
     
  4. Ark07

    Ark07 Private E-2

    Can I perform the Windows Startup Repair? Is it equivalent to repairing with a Win7 Install disc?
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    No, as this will not repair the MBR infection you have. You can create a Recovery Console disc here:
    Vista and Win7 Recovery disc

    Then you can follow my previous instructions.
     
  6. Ark07

    Ark07 Private E-2

    Tim, I have followed all your Instructions and I am attaching all the logs.
    Please suggest what steps I should take next if I haven't got rid of the malware yet.

    Thanks!
     

    Attached Files:

  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You need to run TDSSKiller now and then give Tim a description of how things are running now. If there is any remaining malware Tim will find it.

    Attach the TDSSKiller log.
     
  8. Ark07

    Ark07 Private E-2

    Thanks Kestrel13,

    I did run TDSS KIller and it worked this time! I will attach the log.
    And I haven't had any BSOD's but I have had some rather odd things going on, like when I boot, at the beginning explorer.exe won't load and I have to do it myself by using 'Run'. And my Internet speed has gone horribly slow on this system whereas when I am connected by other systems it is Normal. Also my AntiVirus database is completely missing!
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please attach it so I can see if it did complete properly.

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now copy just the bold text below to notepad (Do not include any space above the word REGEDIT). Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now use windows explore to find and delete:
    C:\Windows\system32\drivers\svciyyyt.exe

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).Make sure that you watch for the license agreement for TrendMicro HijackThis and click on the Accept button TWICE to accept ( yes twice ).

    Then attach the below logs:

    * TDSSKiller log
    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  10. Ark07

    Ark07 Private E-2

    Tim,
    I did everything as you told me.
    1) I did a System Scan through Hijack This and fix all the files you had named.
    2) I created fixME.reg and double clicked it and allow it to merge with the registry. And Yes, I got A "Successfully added to the Registry" Message.
    3) Then I deleted svciyyyt.exe and then ran C:\MGtools\GetLogs.bat file. I also ran the TDSS Killer and It said it did Not find any threat. Anyway I'll attach the logs below.

    However when I re-enabled the Resident shield of my AntiVirus, it detected another(?) malware. The Infection is Trojan Horse SHeu3.BYDG

    Hopefully you will be able to help me get rid of this too. Thank you in advance for your assistance.
     

    Attached Files:

  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You need to tell me exactly what your AV software found. The name it gives is meaningless. You also need to run CCLeaner and empty out this folder:
    C:\Windows\Temp\
     
  12. Ark07

    Ark07 Private E-2

  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes, you can just remove them. What other malware issues are you still having, if any?
     
  14. Ark07

    Ark07 Private E-2

    Everything is back to Normal. I have not experienced any odd things.
    Now Can I perform the remaining operations on Malware Removal/Cleaning Procedure thread like Enabling User Account Control and Toggle System Restore?

    Thanks So much for your help. I Really appreciate it. :)
     
  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good to know!!

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:


    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0

    Help Support MajorGeeks
    Buy Discounted Software @ Majorgeeks Store. Giveaways Too!

    Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies

    MajorGeeks on FaceBook
     
  16. Ark07

    Ark07 Private E-2

    Thanks for all the Help. Thank you. :)
     
  17. Ark07

    Ark07 Private E-2

    And One Another thing. When I was switching back to Selective startup from Normal startup. I noticed one Motive Report Agent which was not there before(?). Is it Necessary? Is it Harmful?
     
  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It's not harmful, as I believe it is related to your ISP. ;)
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You should not be using Selective Startup. The below is a quote from step 4 of the READ & RUN ME and this is always true under all circumstances. See the last link.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds