ARK/Agent.IQ keylogger?

Discussion in 'Malware Help (A Specialist Will Reply)' started by col_pogo, Jul 31, 2008.

  1. col_pogo

    col_pogo Private E-2

    My daily Antivir scans (logs of two recent ones are attached in logs.zip) started picking up some files with a "recognition pattern of a probably damaged CC/Agent.IQ sample" in the past week or so. I can't find the files referred to in my system, and only about 4/10 of the past week's scans (I ran a few on my own) have turned up these files.

    Infected files are:
    C:\ARK10E2.tmp
    C:\ARK10DB.tmp
    C:\SwSetup\ESPtools\Disk1\System32\IfxWlxEN.dll
    C:\System Volume Information\_restore{A80475B6-CF6D-4B3A-BD21-B16C67DB5304}\RP350\A0053231.dll

    An Antivir information page (which I can no longer find) suggested that Agent.IQ is keylogging malware, but I can't find references to it anywhere online.

    I did all steps in the forum Readme--logs are attached--and apart from some tracking cookies (killed by Spybot) and altered registry keys (picked up and corrected by Malwarebytes) everything looks clean to me.

    Another Antivir scan I ran after all the spyware scans came up clean--but I don't think this is a reliable indicator.

    Any suggestions on how to make sure I'm clean? I'd like to catch up on my internet banking but don't want to do so if there's a keylogger sitting on my system?

    Other info you might want: I ran all scans from Administrator (except Antivir), but usually run as markg, a restricted user. I usually use Firefox 3.01, but have been known to lapse and use IE--won't be doing that again.
     

    Attached Files:

  2. col_pogo

    col_pogo Private E-2

    Oh, and my regular user profile has now disappeared. I was using it until I ran all the scans, now I get a note that the user profile is "corrupt" or missing and Windows won't let me log in. All my files still seem to be in order, however. Do you get this problem with your malware removal tools often?
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    This has nothing to do with running the READ & RUN ME. Very little was removed from your PC since there was no real malware to be concerned with. It sounds to me like the registry for this user account was corrupted. You may want to post about that in the Software Forum. Someone may be able to help you with creating a new user account and copying as much over from the old account as possible.

    Are you actually having any real malware problems? I'm not referring to that silly useless message in the log from AntiVir. That may not even be a valid problem.

    What is the below folder for/from? Is it something for an HP Printer?
    C:\SwSetup\ESPtools\Disk 1


    Please run this Running GMER to detect rootkits and attach the log. I just want to make sure no rootkits are found.
     
  4. col_pogo

    col_pogo Private E-2

    After a couple of reboots, user profiles all seem to be back in order. No idea what caused that problem.

    I ran GMER--logs are attached.

    C:\SwSetup\ESPtools\Disk 1 is HP Embedded Security, something which I don't think I have enabled that came with my computer.

    I don't have any malware problems that I know of (I have occasional slowdowns, but nothing that seems alarming) apart from these Antivir reports. Is Antivir known for producing lots of false positives? Is there an easy way to tell which reports should be ignored?

    Thanks for helping out.
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It is also clean.

    Not as bad as some other programs but they all do have some issues with FPs.

    Not that I know of and it would be difficult here since the TMP file names are random. Seems like something you are running creates them and then removes them before the file can even be deleted by AntiVir.


    Now we need to cleanup some items from running ComboFix.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    If you are not having any other malware problems, it is time to do our final steps:
    1. You can uninstall SUPERAntiSpyware now.
    2. We recommed you keep Malwarebytes Anti-Malware as a scanner. It uses no resources except a little disk space until you run a scan.
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combo-fix" /u
        • Notes: The space between the combo-fix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combo-fix folder from combofix.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  6. col_pogo

    col_pogo Private E-2

    Thanks, Chaslang!

    That all seems to have worked perfectly. In future I'll do your Read & Run process and only post if that throws up issues.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds