trojan horse Backdoor.Agent.ETK

Discussion in 'Malware Help (A Specialist Will Reply)' started by musclegalore, Apr 1, 2007.

  1. musclegalore

    musclegalore Private E-2

    Hello,

    So I was recently scanning my computer, and out of nowhere, my AVG picked up this trojan horse. My AVG did delete it, but ever since, my computer has been very sluggish and slow. I've also noticed strange things such as when i goto add/remove programs, some of my applications say I used them on 3/31/07 when i havent touched them for ages! I've done all the steps that the Sticky had posted - they show no virus in the results yet my computer is still very slow. I hope someone can help me out. Thank you. My logs are attached.

    P.S. My Panda Activescan resulted in no viruses detected and i couldnt find a way to export a log or report from it.
     

    Attached Files:

  2. musclegalore

    musclegalore Private E-2

    Here are the rest of my logs.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Is there a reason for you creating two user accounts? I refer to gasgalore

    Well you missed a few parts of the READ & RUN ME. Also slow PCs are more frequently related to what you are running then they are due to malware.

    Now to the finer points of what was missed in the sticky.

    Step 0 - You did not uninstall Viewpoint Media Player in step 0.
    Step 3 - You still have Symantec Internet Security Suite installed and you also have AVG7.

    Uninstall all of the below now.
    • Symantec KB-DocID:2003093015493306
    • Symantec Technical Support Web Controls
    • Viewpoint Media Player
    If they do not show in Add/Remove programs or if they will not uninstall, tell me.

    Is your copy of Spy Sweeper a paid version or a free trial? If paid you should now uninstall AVG Antispyware to avoid conflicts and the additional use of system resources which will slow you down too. Note also that Spy Sweeper has been known to slow down some PCs.

    You should also uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 3
    Mozilla Firefox (1.5.0.11)

    Make sure you reboot after uninstalling the above!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Then install the current version of FireFox from: Mozilla Firefox

    You can also do the below to have HijackThis remove some non-malware items that are wasting system resources.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

    After clicking Fix, exit HJT.

    Now attach new logs from ShowNew and HJT and tell me what current malware problems you are having if any.
     
  4. musclegalore

    musclegalore Private E-2

    I initially created that account and tried posting a topic on the forum, but for some reason, even if I clicked submit, my topic wouldn't appear on the topic llist (but now it is for some reason confused ) . I assumed there was a problem and created a new one.


    I completed the tasks you posted above. I was wondering how come malware may not have anything to do with my computer being sluggish, because my computer started becoming this way after I discovered that trojan horse. Like I said, not only was my computer acting slow, it was doing weird things such as the clock being 2 hrs ahead, and the [add/remove programs] thing saying i used a program on a day I didnt.

    My computer seems to be a bit faster, and I will monitor it some more and let you know.
     
  5. musclegalore

    musclegalore Private E-2

    sorry, here are my logs
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you do not show any real signs of major malware after doing all the scans, then you just don't have any. You have to also consider whether you installed any new software just prior to the problems or even if you updated any software. Updates to anything including your Windows OS. Don't forget, you may have some software set to automatically update. Thus you would not even know it occurred.

    I cannot explain your clock but it is not malware. And Add/Remove programs typically gives incorrect information for when a program was last used. In fact, I often see it telling me something was last use a couple years ago when I just used it today. Again, this is not malware.

    You still have a component of Symantec installed which is also running a service and wasting resources. Uninstall LiveUpdate 3.0 (Symantec Corporation)

    Also have HJT fix the below left over from uninstalling Spy Sweeper:
    O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)


    Now attach a new HJT log. I want to make sure the service for LiveUpdate goes away.

    Is your PC running any better?
     
  7. musclegalore

    musclegalore Private E-2

    I followed your recent steps. My PC has been running a bit smoother, but it is quite slow most of the time. Could my PC be acting this way because a hacker had or is controlling my computer? He may have used that backdoor.agent.etk to get in, possibly? Thanks.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I doubt it, but let's dig a little deeper even though I do not expect to find anything.


    Now please download F-Secure's BlacklightBeta
    • Download fsbl.exe and save it to the Desktop.
    • Once saved... double click fsbl.exe to install the program.
    • Click accept agreement and Click scan
    • This application may trigger a warning from your antivirus. Let the driver load. Wait for it to finish.
    • If it displays any items...don't do anything with them yet. Just hit exit (close)
    • It will drop a log on Desktop that starts with fsbl....big number
    Please attach the BlackLight log.




    When is the last time you did a defrag of your hard disk?
    How about an error check on the hard disk?
     
  9. musclegalore

    musclegalore Private E-2

    Looks like it found nothing.


    The last time i did a disk defrag was about 2 days ago.
    I've never heard of error checking, so I've probably never done that.
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well that was what I suspected. I don't think you are having malware problems and I will probably be sending you off to the Software Forum, but first I want you to try something.

    Click Start, Run, and enter msconfig and click OK.

    • Now in MSconfig select the Services tab and check the box at the bottom to Hide all Microsoft Services
    • Now locate the service or services for ZoneAlarm. You should see TrueVector for the service and ZoneLabs for the Manufacturer.
    • Uncheck everything from ZoneLabs (it may just be TrueVector)
    • Now click Apply
    • Then click the Startup tab and uncheck zlclient which is also for ZoneAlarm
    • Now click Apply and OK
    Then reboot your PC. Does it seem significantly better?

    Do not run with ZoneAlarm disable for any length of time. Just check out to see if it is noticably better and then run MSconfig and select Normal Startup to get your firewall back in place.
     
  11. musclegalore

    musclegalore Private E-2

    I am on windows 2000, so I'm assuming i go to control panel, services, and disable TrueVector on startup ?
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Ooop! Sorry I forgot that you were on Win2K (too many threads in progress).

    Yes run services.msc and stop and disable the service. You will have to undo that at a later time.

    And to temporarily stop zlient from starting up, you can have HJT fix the below line:

    O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"

    It will be saved in HJT's backups and you can restore from the backups after checking things out.
     
  13. musclegalore

    musclegalore Private E-2

    Sorry for the late reply. I followed your instructions regarding zone alarm. The speed is still a bit sluggish. I'm assuming you'll be transfering me to the software forums now?
     

    Attached Files:

  14. musclegalore

    musclegalore Private E-2

    Also i was looking at the Processes window from task manager, and i noticed that vsmon.exe was using a whopping 38,000k and zlclient.exe was using about 9,000k of memory usage. Do you think zone alarm may in a way be slowing down my comp or should i ask this in the software forum. When i turned them off, like i said, the comp was still a bit slow and sluggish but maybe i couldnt notice the improvements?
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sometimes trying to stop a program from running is not as effective as uninstalling.

    Try uninstalling ZoneAlarm (just as a test) and then reboot and check your performance.

    Also just as an additional check, run the below.

    Now please download F-Secure's BlacklightBeta
    • Download fsbl.exe and save it to the Desktop.
    • Once saved... double click fsbl.exe to install the program.
    • Click accept agreement and Click scan
    • This application may trigger a warning from your antivirus. Let the driver load. Wait for it to finish.
    • If it displays any items...don't do anything with them yet. Just hit exit (close)
    • It will drop a log on Desktop that starts with fsbl....big number
    Please attach the BlackLight log.

     
  16. musclegalore

    musclegalore Private E-2

    No luck so far still.

    I already scanned fsbl and posted the log in one of my earlier posts. I did it again anyways and no items were found.
     

    Attached Files:

  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you uninstall ZoneAlarm?

    Sorry about that. I meant to just ask you to run a second scan just to make sure nothing showed up.

    How do things run when you boot in safe mode?

    What happens if you boot into normal mode but use a different user account?

    Note: you do have a few other items running at startup that you don't need.

    O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds