C:\Windows\svchost.exe Trojan.Agent

Discussion in 'Malware Help (A Specialist Will Reply)' started by Snuffleupagus, Jan 1, 2013.

  1. Snuffleupagus

    Snuffleupagus Private E-2

    WIN 7 PRO 64-bit OS.
    Lenovo T530 Think Pad
    Running Norton Security Suite and Comcast Constant Guard

    I noticed that I couldn't launch Norton Security Suite. So I uninstalled and reinstalled it. No luck. So I uninstalled Constant Guard and reinstalled Norton Security Suite, still couldn't launch it.

    I downloaded and ran Malware Bytes (see attached log). I selected two files to delete: Trojan.Agent & Trojan.Agent.NIX.

    Now Malwarebytes is displaying a message that it has blocked and quarantined a threat: C:\Windows\svchost.exe Trojan.Agent. This popup keeps popping up every few seconds.

    Downloaded and ran RogueKiller, scanned and deleted the registry entries that were listed (see logs).

    I then went to the Read & Run Run Me First webpage and followed the instructions there (log files attached).

    TDSSKiller ran and generated two errors: Cannot initialize Logs & Cannot load driver. (no log file to upload)

    MGTools is not a free app. And when it ran it was generating errors creating the .zip file. (No MGTools.zip to upload)

    Still cannot launch Norton Suite.

    Let me know if you need any more information.

    Thanks!
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please make sure that all protection software is disabled and try again. If it still does not run, please try to run it in safe boot mode. It will be a key program in fixing your infection.

    Not true!!! It is totally free.

    This is due to your infection. Normally the indiviual log files will be created anyway as long as you did not stop MGtools from running all the way thru. Try the below which will try to package up the individual logs.

    Please right click on C:\MGtools\ReZip.bat and select Run As Adminstrator and tell me if that runs. If it does, it should tell you that C:\MGtools\MGlogsR.zip was created. If so, attach it.
     
  3. Snuffleupagus

    Snuffleupagus Private E-2

    I tried running tdsskiller. I get a Windows Security error: "Your Internet security settings prevented one or more files from being opened" I disabled Protected Mode on the Security Tab of my IE options from the Tools menu and I still get the same error message.

    -Kirk
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You should not be running TDSSkiller from Internet Explorer. You should be downloading and saving it to your Desktop. Then you should locate it on your Desktop and Right click on it and select Run As Adminstrator.
     
  5. Snuffleupagus

    Snuffleupagus Private E-2

    Ran tdsskiller.exe in safe mode as administrator and I go the same Internet Security settings error.
     
  6. Snuffleupagus

    Snuffleupagus Private E-2



    Tried downloading it to Desktop and got an error message: "Your current Security settings do not allow you to download this software (sic) file"
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    See if you can use another PC to download it and then copy it to the problem PCs Desktop. Do the same for MGtools.exe

    Note: We could try running a fix with Hitman Pro to remove that infected Boot Sector issue it pointed out, but you should be aware that even using Hitman or TDSSkiller to fix this, could result in the PC being unbootable. Important data should be backed up first if possible.
     
  8. Snuffleupagus

    Snuffleupagus Private E-2

    Downloaded tdsskiller.exe on another PC to a Flash Drive. ran it as Admin. from the flash drive on this laptop. It detected Rootkit.boot.pihar.c.

    What next? "cure" ??
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes but you should be running it from the Desktop of the infected PC as I stated. The same goes for MGtools. If you do not run MGtools from the infected PC's harddisk, it will not work.
     
  10. Snuffleupagus

    Snuffleupagus Private E-2

    Well, I think tdsskiller.exe worked even though I launched it from the flash drive instead of the C: drive.

    I downloaded MGTools.exe from the clean PC and will copy it to my laptop Desktop and run that too.

    Any way we can confirm that tdsskiller worked?
     
  11. Snuffleupagus

    Snuffleupagus Private E-2

    So I ran MGTools.exe from the hard drive on the infected PC and attached is the .zip file.

    Let me know if you think we need to continue this process.

    If you need more info. please feel free to contact me.

    Kirk
     

    Attached Files:

    Last edited: Jan 2, 2013
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes you have more to do.

    First uninstall the below:
    Java(TM) 6 Update 25
    Optimizer Pro v3.0
    Wajam

    And what is the below that you seem to have installed at the same time as Optimizer Pro?
    Office Suite X 3.3

    Is this a hack?


    Now please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Note: That JRT may reset your home page to a google default so you will need to restore your home page setting if this happens.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • the JRT.txt log
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!


    I'll be back tomorrow night!
     
  13. Snuffleupagus

    Snuffleupagus Private E-2

    Sucessfully uninstalled the designated software. Office Suite X.3.3 is the free Open code Office suite software. And try as I may I cannot download and install JRT.exe
     
  14. Snuffleupagus

    Snuffleupagus Private E-2

    OK. I was able to download JRT.exe on my clean maching after disabling some Norton antivirus tasks. I was able to copy it to a Flash Drive and then copy it to the Desktop of my infected laptop.

    Attached is the JRT.txt file

    I've already attached the MGlogs.zip file a few posts back. Do you want me to run it again?

    Thanks!
     

    Attached Files:

    • JRT.txt
      File size:
      4.5 KB
      Views:
      7
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes you need to follow the instructions I gave to create a NEW log and attach it.

    I'm not sure that Office Suite X.3.3 is the same thing as Open Office which has a differnent name and is from Apache ( http://www.openoffice.org/download/ ) but I could be mistaken as I never installed it.
     
  16. Snuffleupagus

    Snuffleupagus Private E-2

    OK new MSGlogs.zip is attached and Louisville just picked off a FLA pass in the endzone....sorry distractions ya know!

    Take a look and advise next steps. Thanks!
     

    Attached Files:

  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Your logs are clean.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Go back to step 4 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    6. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    7. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  18. Snuffleupagus

    Snuffleupagus Private E-2

    OK. Just ran the MGtools.exe and here is the current log (see attached)
     

    Attached Files:

  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I did not ask for a new log. I gave you final instructions already.
     
  20. Snuffleupagus

    Snuffleupagus Private E-2

    Sorry, I was replying to an older message. I've completed the instructions that you have provided and I am quite satisfied that your instruction and guidance have helped me to clean my laptop of the trojan.agent infection. Is there anything else in your opinion that I need to do now?

    Thanks!

    Kirk
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Just the final instructions.
     
  22. Snuffleupagus

    Snuffleupagus Private E-2

    Done & Done!

    I'm looking clean!

    Thanks much Chaslang & have a Happy New Year!

    Cheers!

    :dancer

    Kirk
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. And Happy NY to you too.

    Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds