Can't remove MagicControl.Agent-ADW_SLAGENT.A

Discussion in 'Malware Help (A Specialist Will Reply)' started by Roger_Duke, Jan 4, 2006.

  1. Roger_Duke

    Roger_Duke Private E-2

    Spybot S&D reports that I have MagicControl.Agent spyware. PC-cillin is reporting it as ADW_SLAGENT.A -- I understand these are the same thing.

    After apparently removing the problem it reappears without rebooting.

    I can find and delete the registry keys indicated by Spybot -
    [HKEY_USERS\S-1-5-21-790525478-1343024091-268654771-1004\Software\LanConfig]
    "LAN"="UP"
    and
    [HKEY_CURRENT_USER\Software\LanConfig]
    "LAN"="UP"

    but the keys reappear, again before I reboot.

    I have gone through all the steps in " READ & RUN ME FIRST Before Asking for Support" and have attached the logs.

    I booted into Safe Mode with no Internet connection and ran the following:

    Ccleaner - did not report any problems.

    Windows Malicious Software Removal Tool - did not detect anything.

    Ad-Aware - did not report any problems.

    Spybot Search & Destroy - found MagicControl.Agent. I told S&D to fix it and did another run, it was still showing clean.

    Microsoft Antispyware did not report any problems.

    I booted into Safe Mode with Network Support and ran the following-

    Bitdefender - log saved

    Panda ActiveScan – ran but couldn't access the button to save the log.
    I ran it again in normal boot mode and saved the log.

    After rebooting into normal mode I re-ran Spybot S&D and it again found MagicControl.Agent
    Re-ran PC-cillin and it found ADW_SLAGENT.A.

    I ran Hijack This and saved the log.

    I would be grateful for any advice on how to permanently remove MagicControl.Agent (ADW_SLAGENT.A).
    Also the logs show other unresolved problem about which I would appreciate any advice.

    Attached logs: Hijack This, ActiveScan, BitDefender.

    Thank you
    Roger
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do you have a program named Mailskinner on your PC? If so, Magic Control Agent more than likely came along with it. Uninstall Mailskinner.
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Why do you have both Trend Micro and Norton firewalls running? Do you also still have the WinXP SP2 firewall enabled? You must use only one firewall and not the one in WinXP.

    Do you know what the below is for:

    O4 - HKLM\..\Run: [Sidi] C:\ProgramFilesAllUsers\Sidi\Sidi.exe


    Are you using a script to create a restore point each time you boot?
    O4 - HKCU\..\Run: [!Shortcut to RestorePoint.vbs] C:\WINDOWS\RestorePoint.vbs

    The below NetMeter is known as malware did you install this?
    O4 - HKCU\..\Run: [C:\Program Files\NetMeter\NetMeter.exe] C:\Program Files\NetMeter\NetMeter.exe

    See: http://www.bleepingcomputer.com/startups/NetMeter.exe-3644.html
     
    Last edited: Jan 4, 2006
  4. Roger_Duke

    Roger_Duke Private E-2

    As far as I know I do not have a program named Mailskinner and I have never heard of it. I have searched for it and can't find it. It is not in the Add or Remove Programs list.

    I uninstalled my Norton firewall when I installed Trend Micro (PC-cillin) firewall. The WinXP SP2 firewall is not enabled.

    HKLM\..\Run: [Sidi] C:\ProgramFilesAllUsers\Sidi\Sidi.exe is a program that locks my CD and DVD trays - it prevents junior from trying to destroy them.

    >Are you using a script to create a restore point each time you boot?
    >O4 - HKCU\..\Run: [!Shortcut to RestorePoint.vbs] >C:\WINDOWS\RestorePoint.vbs
    Yes - I have used it for a year or more with no apparent ill effects.

    Yes I installed NetMeter when my ISP imposed a monthly usage cap. Following your advice I will remove it.

    Thanks for the advice. However the above do not seem to relate to MagicControl.Agent - ADW_SLAGENT.A spyware.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No they are not related to Magic Control but let's fix the fact that Symantec/Norton is still showing in your Services.
    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
    O23 - Service: Norton Personal Firewall Proxy Service (SymProxySvc) - Unknown owner - C:\Program Files\Norton Personal Firewall\SymProxySvc.exe (file missing)

    Are you sure all Symantec/Norton stuff is uninstalled? Try running the below to clean them up:

    Removing your Norton program using SymNRT


    If that does not work we will do it manually.

    For MagicControl Agent. Try this:

    Copy the contents of the below Quote Box to Notepad. Then click File and then Save As. Change the Save as Type to All Files. Name the file fixMCA.reg and then click save. (make sure you save it somewhere you can find it. Saving it to your Desktop may make that easy.) Then double-click on the fixMCA.reg file on your desktop (or locate it with Windows Explorer and double click on it if not saved to the Desktop) and when it prompts to Add in to the registry, say yes.
    Now do a new Spybot scan and attach the log from Spybot (and also TrendMicro) so I can see what they are reporting.

    Also let's get an installed programs list from HijackThis.
    Run HijackThis, click Open the Misc Tools section
    Click "Open Uninstall Manager"
    Click "Save List" (generates uninstall_list.txt)
    Click Save, to save it to a file where you can find it.
    Upload this file as an attachment too.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  7. Roger_Duke

    Roger_Duke Private E-2

    Symantec/Norton
    I tried to find and remove the remnants of Symantec/Norton stuff but without success. I can't use SymNRT because it doesn't apply to my versions – Norton AntiVirus 2002 and Norton Personal Firewall 2002. So I followed the procedure on the same link – "Remove programs that cannot be removed with SymNRT" – specifically "Step 3: Use the Windows Installer CleanUp utility". However when I ran it the only Symantec item I could only see in the Windows Installer Clean-Up dialog box was Symantec Network Drivers Update, which I left untouched.

    MagicControl Agent
    I copied your Quote Box and made the fixMCA.reg file. It seemed to run OK.
    I then did another Spybot scan which still showed MagicControl Agent. I ran a TrendMicro scan and again saw ADW_SLAGENT.A. I will attach both logs, but I can't see any reference to MagicControl Agent in Spybot's log. I screen-captured what Spybot flashed up and pasted it into a Word doc, it said MagicControlAgent ---- HKEY_USERS\S-1-5-21-790525478-1343024091-268654771-1004\Software\LanConfig (still there) and HKEY_USERS\S-1-5-21-790525478-1343024091-268654771-1004\Software\mc\SA (can't now locate).

    I ran Hijack this and got an installed programs list which I'll attach.

    As I was still getting the same reports from Trend and Spybot I ran http://www.trendmicro.com/vinfo/gray..._SLAGENT.A as you suggested.

    It says that ADW_SLAGENT.A creates a folder where it drops 2_ MSLAGENT.DLL, MSLAGENT.EXE and UNINSTALL.EXE. I could find either of the first two in Windows folders, though later I found them in the Registry.
    I opened the Registry editor, as instructed, but didn't find mslagent.exe in HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run . However I found it in [HKEY_CURRENT_USER\Software\Microsoft\Search Assistant\ACMru\5603] and in [HKEY_USERS\S-1-5-21-790525478-1343024091-268654771-1004\Software\Microsoft\Search Assistant\ACMru\5603].
    I also found 2_mslagent.dll and uninstall.exe in the same places. I exported the keys and then deleted them.

    Afterwards I re-ran TrendMicro and Spybot with the same result – i.e. the same problem is still there and if I remove the problem it re-appears.

    Thank you for your continuing help.
    Roger
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You should go to Add/Remove programs and uninstall NetMeter.exe. This is malware and I mentioned this earlier but you did not fix it. Please uninstall this now before continuing.

    I need a Spybot log that shows the malware that it detects. That is not what you posted.

    You need to follow the directions in the READ & RUN ME. We ask you to check against ALL versions and make sure you are using the proper program versions and updated definitions. This is in your installed programs list:

    Spybot - Search & Destroy 1.3

    This is not current. Please go back to the READ & RUN ME and verify you have the proper versions for ALL programs. You must click the links and make sure you have the same versions. Also get all updates. Then re-run Spybot S & D 1.4 with ALL updates and see if you still have a problem fixing Magic Control Agent. If so, attach the log that shows what it detects as malware.

    Note: while not part of the READ ME, SpywareBlaster v3.4 is not current either.

    Where you saying in you last message you looked for the below registry keys but could not find them:
    HKEY_USERS\S-1-5-21-790525478-1343024091-268654771-1004\Software\LanConfig
    HKEY_USERS\S-1-5-21-790525478-1343024091-268654771-1004\Software\mc\SA
     
    Last edited: Jan 5, 2006
  9. Roger_Duke

    Roger_Duke Private E-2

    NetMeter.exe – I did previously uninstall this using Add/Remove programs and it no longer appears in the Add/Remove list. It isn't in my Program Files folder and I can't find any netmeter files (except my saved download) using Windows Search. However it does appear more than once in some Registry keys – shall I delete these?

    My Spybot Search & Destroy is now version 1.4 +updates. Once again it reports MagicControl.Agent. It also reported Winfixer tracking cookie. Tried fixing both and re-ran Spybot. Winfixer did not re-appear but MagicControl.Agent did and is still there.

    I will attach the log from the first run, when I selected Fix - SpybotSD.Report-Jan6_6.29p.txt, and from the later run - SpybotSD.Report-Jan6_6.50p.txt – when MagicControl has reappeared though Winfixer has not reappeared.

    Regarding the Registry keys, I did find HKEY_USERS\S-1-5-21-790525478-1343024091-268654771-1004\Software\LanConfig
    but I couldn't find
    HKEY_USERS\S-1-5-21-790525478-1343024091-268654771-1004\Software\mc\SA

    I have looked again and found [HKEY_CURRENT_USER\Software\LanConfig]
    "LAN"="UP"
    and [HKEY_USERS\S-1-5-21-790525478-1343024091-268654771-1004\Software\LanConfig]
    "LAN"="UP"

    I saved and then deleted them but they re-appeared when I re-ran the registry editor.

    I still can't find
    HKEY_USERS\S-1-5-21-790525478-1343024091-268654771-1004\Software\mc\SA – this was flagged up previously by S&D as part of the problem but this is not happening now.

    Roger
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please do not save full logs with Spybot. When you complete the scan and have fixed the items it shows, just right click in the window and select Save results to file and then save the file so you can upload it here. If the log is very small you could just right click and select Copy results to clipboard and then paste them here into your message.

    Please download Silent Runner's
    • Save it to the desktop.
    • Run Silent Runner's by doubleclicking the "Silent Runners" icon on your desktop.
    • You will see a text file appear on the desktop - it's not done, let it run (it won't appear to be doing anything!)
    • Once you receive the prompt All Done!, open the text file on the desktop, copy that entire log, and attach it to your next message.
    NOTE: If you receive any warning messages from your antivirus or antispyware programs about a script trying to be run , please choose to allow the script to run.

    Also do the below. I want to see if it also helps delect a hidden process that I suspect.

    Copy the below quoted text into a new notepad document.
    Click File> Save as... and change Save as type to all files, set the File name to runhjt.bat and save it to your Desktop.
    Now execute runhjt.bat by double clicking on it. A new HJT log will come up. The file is already save in the folder where HJT is run from. This should be C:\Program Files\HJT if you followed our directions for installing HJT. Attach this new log. I'm suspecting it will reveal another hidden executable process which is the cause for MCA coming back. HJT is also still running minimized. You can close it.
     
    Last edited: Feb 3, 2006
  11. Roger_Duke

    Roger_Duke Private E-2

    Silent Runners - ran and log Startup Programs (ROGER-0XVI49MES) 2006-01-07 10.57.10.txt attached.

    I notice it has an entry "wolhqexrni" = "c:\windows\system32\wolhqexrni.exe wolhqexrni" [null data]
    I think I remember seeing some recent warnings about this from Microsoft AntiSpyware – should I delete it from the Registry?

    runhjt.bat – ran and log attached.

    Roger
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Use runhjt.bat to run HJT again. Just close the notepad log window when it comes up. Then click on the hijackthis process showing minimized in your system tray. Now you will see the HJT window. Click on the Config button on the lower right. Then click Misc Tools. Then select "Open process manager" on the left-hand side. Look for the following process and kill it by selecting it and then clicking "Kill process". Then click yes.
    C:\windows\system32\wolhqexrni.exe

    Now on the Far lower right of the Window click the Back button (do not click the back button next to the Run button). Now you should be back at the scan screen where we can select the check boxes to fix items. Select each of the below lines and then click Fix checked (make sure no browsers are running before you click Fix):
    R3 - Default URLSearchHook is missing
    O4 - HKLM\..\Run: [wolhqexrni] c:\windows\system32\wolhqexrni.exe wolhqexrni
    O4 - HKCU\..\Run: [C:\Program Files\NetMeter\NetMeter.exe] C:\Program Files\NetMeter\NetMeter.exe

    Then Exit HJT and continue.

    Now Click Start, Run, and enter cmd and click OK. This will open a command prompt window. At the command prompt enter the below commands each followed by the enter key. Take note of any messages you get from the below and tell me later what it says if anything.
    C:\windows\system32\wolhqexrni.exe -uninstall
    exit

    Now use Windows Explorer to look for the below and delete them (tell me what you find):
    c:\windows\system32\wolhqexrni.exe
    c:\windows\system32\wolhqexrni.dat
    c:\windows\system32\msclock32.dll
    c:\windows\system32\msplock32.dll
    C:\Program Files\NetMeter <--- the whole folder

    If you find the above files but any of them will not delete, reboot into safe mode and try to delete them again.

    At anyrate whether in safe mode or still in normal boot, run the fixMCA.reg registry patch that I gave you in message number 5.

    Now reboot again into normal boot mode and attach a new HJT log. Also check a Spybot scan and let me know the results. If it finds anything, fix them and run another scan to see if clean.

    Also let me know how all the above steps went and answer my questions about the uninstall and what files were found.
     
  13. Roger_Duke

    Roger_Duke Private E-2

    Ran runhjt.bat and opened Process Manager. Cannot find C:\windows\system32\wolhqexrni.exe Will attach text file of list. wolhqexrni.exe not found in Windows search.

    Found in Registry –
    HKEY_CURRENT_USER\Software\Microsoft\Search Assistant\ACMru\5603\wolhqexrni.exe
    HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam\MUICache\wolhqexrni
    and as above in
    HKEY_USERS\S-1-5-21-790525478-1343024091-268654771-1004\Software\Microsoft\Search Assistant\ACMru\5603
    HKEY_USERS\S-1-5-21-790525478-1343024091-268654771-1004\Software\Microsoft\Windows\ShellNoRoam\MUICache
    HKEY_USERS\S-1-5-21-790525478-1343024091-268654771-1005\Software\Microsoft\Windows\ShellNoRoam\MUICache

    Got back to HJT scan screen and checked
    R3 - Default URLSearchHook is missing
    O4 - HKLM\..\Run: [wolhqexrni] c:\windows\system32\wolhqexrni.exe wolhqexrni
    O4 - HKCU\..\Run: [C:\Program Files\NetMeter\NetMeter.exe] C:\Program Files\NetMeter\NetMeter.exe
    Then clicked Fix Check.

    Shortly afterwards I saw a System Tray pop-up from MS AntiSpyware that said "An Internet Explorer URL Search Hook ({CFBFAE00-17A6-11D0-99CB-00C04FD64497}) has been added to Internet Explorer and has been automatically allowed. Microsoft AntiSpyware has determined this program to be free of known spyware".

    I opened a command prompt window and typed C:\windows\system32\wolhqexrni.exe –uninstall <enter>
    Response was "Did you really want to uninstall?" [Yes]
    Response was "wolhqexrni has been removed"
    Exited command prompt window.

    Used Windows Explorer to look for --

    c:\windows\system32\wolhqexrni.exe
    c:\windows\system32\wolhqexrni.dat
    c:\windows\system32\msclock32.dll
    c:\windows\system32\msplock32.dll
    C:\Program Files\NetMeter <--- the whole folder

    None of the above found.

    I ran the fixMCA.reg registry patch, then I rebooted into normal boot mode and ran HJT. I will attach the log.

    I ran Spybot and it found
    MagicControl.Agent: User settings (Registry key, fixed)
    HKEY_USERS\S-1-5-21-790525478-1343024091-268654771-1004\Software\LanConfig

    I ran another scan which this time said no threats found.
    I rebooted and ran another scan – still said no threats found.

    It's starting to look if MagicControl.Agent has been removed, though I'm not sure how.

    Attached: HijackThisProcessList21.19-Jan07-06.txt – re first item in message; hijackthis.log – towards end of message.

    Roger
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    By running the steps I gave you. That's how.
    This process c:\windows\system32\wolhqexrni.exe was behind it reinstalling itself. And even though you said you did not see it running, it was running and it was there. It it were not the c:\windows\system32\wolhqexrni.exe -uninstall would have given you an error message.

    Some of the additional steps I had are backups to make sure we got it. I now see the below in your HJT log. Have HJT fix it and make sure it does not come back after a reboot. Let me know:
    O4 - HKLM\..\Run: [wolhqexrni] c:\windows\system32\wolhqexrni.exe wolhqexrni

    If things remain clean and the O4 line is gone for good and you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     
  15. Roger_Duke

    Roger_Duke Private E-2

    Ran HJT and fixed
    O4 - HKLM\..\Run: [wolhqexrni] c:\windows\system32\wolhqexrni.exe wolhqexrni

    Rebooted and ran HJT – the above did not return.

    I have run Spybot and Trend Micro PC-cillin again and they do not report any malware.

    I disabled System Restore then rebooted and enabled System Restore.

    I have worked through "How to Protect yourself from malware!"

    Many thanks for your help and advice.

    Roger
    Hertfordshire UK
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome! Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds