Malwarebytes 3.2.2 Detects Trojan.agent.gen When Scanning Memory

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by breh5, Oct 22, 2017.

  1. breh5

    breh5 Private E-2

    Hello and THANK YOU for taking your time to help me, someone you've never met. I'm a bit new to this but wanted to get help from a specialist, hopefully I've done everything correctly...

    Malwarebytes 3.2.2 detects Trojan.Agent.Gen in location C:\PROGRAMDATA\Update.exe

    When I quarantine or clean this file it almost never gets rid of it, or if the scan no longer finds malware, It does the next time I scan, after I've restarted my computer. I'm going to wait until after this has all been resolved before deleting my restore points (as I've been instructed in the guide).

    Best of luck, thanks.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Download OTM by Old Timer and save it to your Desktop.


    Code:
    :Processes
    explorer.exe
    
    :files
    C:\PROGRAMDATA\Update.exe
    
    :Commands
    [purity]
    [ResetHosts]
    [createrestorepoint]
    [emptytemp]
    [start explorer]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large http://farm3.static.flickr.com/2782/4174320048_f01c448b32_o.png button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it in your next reply.

    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach this log file to your next message.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach that document back here in your next post.

    Reboot if OTM hasn't. Rerun MBAM and attach the new log and the OTM log.
     
  3. breh5

    breh5 Private E-2

    New MBAM and OTM logs below.
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The file doesn't exist. If you open up MGLogs.zip and double click on Newfiles, you will see there is no Update.exe in
    C:\PROGRAMDATA.

    MBAM is giving you a false positive.
     
  5. breh5

    breh5 Private E-2

    Oh wow really? That's.. really great. But I figure I'll give you a few more details just to confirm?

    First, I *can* see the file itself, which I provided with a paint screen shot. (file at the bottom of the list of files there.) (Sorry for terrible paint skills)

    Additionally, when I right click ANY of the files or folders in PROGRAMDATA, within 1/4-1/2 of a second the menu pops up, displaying options like "Open, play, share, cut, copy, delete, rename" etc.., but when I right click "Update.exe" specifically, the progress circle spins for a good 4-5 seconds before showing options. Is this indicative of anything suspicious like the trojan "hiding something", or maybe it's just a broken file? Now I'm just curious why this file loads when I right click it..

    Thank you!
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yeah, I can read that screen shot....too small. OTM didn't find it. What happens when you right click it? What options do you get?
     
  7. breh5

    breh5 Private E-2

    I didn't realize how small the image showed up, sorry. Resized. falsepositive2.png

    Open, Run as admin, troubleshoot capability, (avast)scan update.exe, (winrar)..add to archive, add to 'update.rar', add to email, pin to startmenu, scan with malwarebytes, restore preivous versions, sent to.., cut, copy, name shortcut, rename, delete, properties

    scanning with malwarebytes.. scan time: 6s, items scanned: 31, threats detected/quarantined: 0

    Export txt summary added

    Hopefully slightly more usable image added (although still blurry, the bottom file is the file in question)
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Click on the following link and use the below steps to scan a file: Virustotal

    Click the Browse... button.
    Navigate to the file and submit it. Let me know the results.
     
  9. breh5

    breh5 Private E-2

    So I click "Upload and scan a file" and navigate the Update.exe

    When I click the file it gives me the message

    "Update.exe
    File Not Found
    Check the file name and try again"
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you are still "seeing" the file, right click and delete. Tell me if it does. If so, reboot and rescan with MBAM.
     
  11. breh5

    breh5 Private E-2

    Unfortunately I will be a few hours before being able to reply to your next response.

    When trying to delete the file, I cannot.

    "could not find this item. This is no longer located in C\Programdata. Veryify the item's location and try again."

    Rebooted and mbam picks it up
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Try this:

    File Assassin

    Simply download FileASSASSIN from the link below. Unzip to a convenient location such as C:FileASSASSIN. Navigate to the folder you unzipped the files to and double click on the file named FileASSASSIN.exe. Then select a file by dragging it onto the text area or select it using the (...) button. Next, select a removal method from the list. Finally, click delete and the removal process will commence.
     
  13. breh5

    breh5 Private E-2

    Thanks. First, should I still have User account control settings set to never notify? I turned it back to default later last night, but let me know if that should go back to being off.

    I have "Attempt FileASSASSIN's method of file processing" checked. Under that I have all four boxes check. (Unlock locked file handles. Unload modules. Terminate the file's process. Delete file.)

    I try both methods of selecting the Update.exe file. When I drag the file, it becomes a black circle with a black line through it when I put it over the text area, so I can't select the file with this method. So, I search the file by using the "..." button. I find 'update.exe' and when i press open it gives me the following error message...

    "Choose file to delete"
    Update.exe
    File not found.
    Check the file name and try again.
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Download this:
    RKill

    Run it then immediately rerun MBAM and delete what it finds.

    Then you can reboot and rescan with MBAM.
     
  15. breh5

    breh5 Private E-2

    Hey just to confirm that this is right.. I'm only getting an option to 'quarantine' the threats which mbam has identified, it doesn't specifically say "delete".

    Ran Rkill, and then MBAM, quarantined the threats, rebooted, scanned again. Got the threats both times in MBAM. here is the MBAM before and after txt files, if relevant.
     

    Attached Files:

  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Download this file to your desktop

    Kaspersky Virus Removal Tool

    Run the program you have just downloaded to your desktop (it will be randomly named )

    First we will run a virus scan.
    • On the first tab select all elements down to Computer and then select start scan.
    • Once it has finished select report and post that.

    Do not close AVPTool or it will self uninstall, if it does uninstall - then just rerun the setup file on your desktop.

    Now an analysis scan

    • Select the Manual Disinfection tab
    • Press the Gather System Information button
    • Once done , still on the Manual Disinfection tab click the little icon of a file which is the "reports" button. Now click on Manual Disinfection report.You should see an option to save a report here with a little button with an icon of a disk. Attach this log please.
    • The file is located at C:\Users\your name\Desktop\Virus Removal Tool\setup_9.0.0.722_05.01.2011_20-34\LOG\avptool_sysinfo.zip
     
  17. breh5

    breh5 Private E-2

    Just to be clear it is called KVRT, as in kaspersky virus removal tool, so it's no longer randomly named?

    "
    • On the first tab select all elements down to Computer and then select start scan.
    "


    The tab I see shows "system memory, startup objects, boot sectors, and system drive" I will also provide a screenshot. (One I hope will be somewhat usable to see what i'm seeing.)

    I'm going to assume that I should select all four options and run that.

    Once I select report I see an icon with date, oct 23 2017 showing the start and end times of the scan.

    "16:42:03.034" Scan Started
    "15:55:26.061" Scan Finished

    I do not see any option here to save or export a save file which I could pass on to you.

    I do not see any "manual disinfection tab" so I can't follow any further steps. Did I download the wrong tool?
     

    Attached Files:

  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Click the "scan" in the right panel and it will expand to show you what it found. Did you not get a window that opened and indicated what if found with the option to delete or skip?

    Did it find the file??
     
  19. breh5

    breh5 Private E-2

    When I click "scan" under the action column, nothing happens. The second screenshot I provided shows the furthest I can go down the chain, I've clicked the 16:42:03.034, the scan word, the word 'started' etc.

    I'm scanning again to see if I have better luck the second time around..
     
  20. breh5

    breh5 Private E-2

    Nope, second report yields the same issue
     
  21. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    This is what you should have:
     

    Attached Files:

  22. breh5

    breh5 Private E-2

    Yea, that's the one I've got.

    This is how I get there.

    main page --> report --> arrow 23 oct 2017 --> arrow next to scan.

    As far as I see, nothing which remains is expandable...
     

    Attached Files:

  23. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    After it scans, it will produce a window that shows what it found. Did it find the file???
     
  24. breh5

    breh5 Private E-2

    When the scan finishes , it does not find any threats, or the file in question
     
  25. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Open task manager and upload a screen shot of running processes, please.
     
  26. breh5

    breh5 Private E-2

     

    Attached Files:

  27. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am sorry, but that is too small to read. Are you using Paint to crop it?
     
  28. breh5

    breh5 Private E-2

    I was, sorry. Hopefully this is a good improvement.

    I've had 2 monitors going, and I've had to crop out half the image (the other monitor) every time, so now I've disabled the other monitor and I hope this is much better

    Also, I've included 2 images which are my task scheduler, in case that helps in any way (the first image I have a task highlighted, due to it's name similarity of what mbam thinks is a trojan), could be a coincidence, but still.. it caught my attention.
     

    Attached Files:

  29. breh5

    breh5 Private E-2

  30. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The file is legit. It belongs to Microsoft windows application experience.
     
  31. breh5

    breh5 Private E-2

    Is there a hypothetical explanation as to why update.exe loads for 4 seconds before displaying the menu when I right click it?
     
  32. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Frankly, I don't know.

    Since you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Re-enable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8 or 10, it is time to make sure you have re-enabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now go to the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 or 10 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. After doing the above, you should work thru the below link:
     
  33. breh5

    breh5 Private E-2

    Your attention to detail and persistence is awesome. Thank you so much, mostly for your patience.
     
  34. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome. Safe surfing.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds