Agent_r.XJ infection

Discussion in 'Malware Help (A Specialist Will Reply)' started by docdan, Apr 27, 2011.

  1. docdan

    docdan Private E-2

    Hi Guys

    I discovered (via AVG) this infection on my Dell Dimension 5150 running XP sp3 a few days ago. My own stupid fault (old enough to know better) - probably when told to download a video codec. Ho-hum.:-o

    I have Googled around and read the various threads on your great site several times and hope you will be able to help me. I have read the READ and RUN ME section ;)

    The main symptom is that I regularly get the 'Generic host process for Win32 services.....' error. The error signature is:

    szAppName : svchost.exe szAppVer : 5.1.2600.5512 szModName : ntdll.dll
    szModVer : 5.1.2600.6055 offset : 00022235

    and the current error report files are attached to this email. Everything continues to run OK for a while, providing I don't acknowledge the error message - then my PC slows and stops, forcing a reboot.

    In my next post I will attch logs from AVG, Malwarebytes, and MGTools - I don't want to touch Combofix yet and am aware I will have to uninstall AVG first.

    I have tried TDSSKiller - running from the root, desktop and as a renamed file, but it always stops at 80%.

    Thanks in anticipation

    docdan
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    You need to use your Windows XP CD to boot to the Recovery Console and run the fixmbr to clear a Master Boot Record infection that you have.

    You can read the below to help you do this:

    http://support.microsoft.com/kb/307654


    After running the fixmbr command then boot back to normal mode Windows and try running TDSSkiller now. Then attach the log. Also explain if you are still having any malware problems.
     
  3. docdan

    docdan Private E-2

    Hi

    Thanks for the quick reply. Unfortunately I have a problem with RC - I do not have the XP disc (Dell don't give you one!) but got the RC installed by running the command from the i386 folder on my C drive.

    WHen booting, the RC to setup but I get a BSOD. Hitting F6 during RC setup shows that it is not loading support for any mass storage devices. Hitting S to specifiy disk controllers gets me a message to insert hardware support disk into drive A:..... i.e a floppy! You guessed it - no drive A on my system :cry

    Can Setup be altered to look on a CD on D, and how do I find my correct drivers?

    docdan
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You may want to try creating and using Hiren's CD to fix the MBR. See what was posted in message # 12 of the below thread and see if you can get this CD to run. If you still need special drivers to access your drive, you will need to post in the Software Forum on how to do this.

    whistler/black internet@mbr again!
     
  5. docdan

    docdan Private E-2

    Hi

    I got HirensbootCd to run fine - I did it from a USB at first - got the menus fine, installed a standard MBR as directed and rebooted XP without problems, but once again TDSSKiller fails at 80% and agent_r.XJ appears on my avg scan. I scanned the USB - clear - and tried to run it again, but oddly it failed to load.

    So I repeated with a CDR version of Hirens. Again loads fine, installed a standard MBR but no joy - TDSS fails at 80% and the Trojan is still here.

    Further advice would be greatly appreciated.

    docdan
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    This is a download of an .iso file of just the Recovery Console for XP.
    Burn to CD with Nero or other 'disc image' capable tool and boot.

    XP Recovery Console.

    Now move TDSSKiller directly to your C:\ folder. So you should have C:\TDSSKiller.exe

    Once you have created the disc, boot to the bios and change the boot order to CD/DVD as first boot device.

    Now boot to the disc and go into the Recovery console. At the prompt, change the directory to the C: prompt and then type:
    C:\TDSSKiller.exe and hit enter.

    Reboot and Please also download MBRCheck to your desktop

    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...
    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message.
     
    Last edited by a moderator: Apr 28, 2011
  7. docdan

    docdan Private E-2

    Hi

    I followed your instuctions but could not get to TDSSKiller from the C: prompt after booting from the RC disk as "The command is not recognised". Typing the Dir command gets me: "An error occurred during directory enumeration".

    I appear to be able to run fixmbr from the C:\ prompt:

    **Caution**
    This computer appears to have a non-standard or invalid master boot record. etc. etc. etc.

    but I cancelled for now - should I go ahead and do it?

    Thanks again

    Docdan


    Daniel
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    tdsskiller.exe would have to have been moved to your root folder so that you have c:\tdsskiller.exe and that is how you would try to run it too. If you did not move it there, then you will not be able to find it since the Desktop cannot be accessed from the Recovery Console.

    You will likely be better off just running fixmbr from the Recovery Console command prompt. Yes you likely have a non-standard MBR but you don't really have any choice here. You need to do this to remove the infection. Your other choice would be to repartition, format, and reinstall. If you want to be safe, you should backup your important data, before running fixmbr. In most cases ( 99 % ) there are no problems, but when removing malware there is always the chance that the disk may not boot after the repair since something could go wrong.

    After you fix the MBR, reboot and run TDSSkiller and attach the log. It should run properly, if the fix of the MBR was successful. You don't need to run MBRcheck as it would not tell you anything useful. It does not detect this infection.
     
  9. docdan

    docdan Private E-2

    TDSSKiller was in the root directory already, but I was unable to access it from the RC C: prompt - likewise any of the hard drive.

    However, fixmbr ran from the RC C: prompt and it worked :-D:-D

    TDSSKiller ran fine and gave clear result - log attached. A full AVG scan was clear, logs attached.

    Thanks very much for all your guidance. You guys are tremendous!!:clap:clap:clap

    My wife is talking to me again:-o

    docdan
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Tell me what malware issues you are still having, if any.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:


    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0

    Help Support MajorGeeks
    Buy Discounted Software @ Majorgeeks Store. Giveaways Too!

    Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies

    MajorGeeks on FaceBook
     
  11. docdan

    docdan Private E-2

    Everything is working fine now thanks:-D

    :wave

    docdan
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good to know. Safe surfing! :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds