DssAgent found by Ad-Aware

Discussion in 'Malware Help (A Specialist Will Reply)' started by suzieQQ, Jan 26, 2006.

  1. suzieQQ

    suzieQQ Private E-2

    I haven't yet went through the removal steps posted by Chaslang ~ not sure if this is a virus or spyware.

    I ran Ad-aware and found "Dss Agent - 1 object total ~ Tac rating of 8
    Ad-Aware didn't remove this. Spybot and Avast didn't detect it.

    What is this?

    I am going to start the steps posted by chaslang now....
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  3. suzieQQ

    suzieQQ Private E-2


    I'm not sure. If I have any software from Borderbund I'm not aware of it. I ran Ad-Aware 3 times before posting here and the Dss-Agent was there each time. When I was following the "READ ME" steps the Dss-Agent didn't show up in Ad-Aware.

    The 2 online scans both found problems ~ all of the other scans came up clean. I will attach the logs from the last 2 scans and the HJT log.

    Thanks!!
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Maybe you misread what Ad-aware was reporting. I do not see Dss Agent but I do see the below from Dell:

    C:\Program Files\Dell Support\DSAgnt.exe

    You HJT log does not show any major problems. There are just a few minor things I would do as stated below. And then there are also some infected email files that you must delete.

    Make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell4me.com/myway
    O16 - DPF: {A7EA8AD2-287F-11D3-B120-006008C39542} (CBSTIEPrint Class) - http://offers.e-centives.com/cif/download/bin/actxcab.cab
    O16 - DPF: {A922B6AB-3B87-11D3-B3C2-0008C7DA6CB9} (InetDownload Class) - https://media.pineconeresearch.com/ActiveX/downloadcontrol.cab

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete
    :
    C:\WINDOWS\cpbrkpie.ocx
    C:\Documents and Settings\Cora Barrett\Application Data\Thunderbird\Profiles\db9ez90g.default\Mail\mail.bellsouth.net\Inbox[price.cpl]
    C:\Documents and Settings\Cora Barrett\Application Data\Thunderbird\Profiles\db9ez90g.default\Mail\mail.bellsouth.net\Inbox[DFC00213.exe]
    C:\WINDOWS\SYSTEM32\DRIVERS\ETC\hosts.20050416-194053.backup

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST).


    Now we need to Reset Web Settings:
    1) If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2) Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3) If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
  5. suzieQQ

    suzieQQ Private E-2

    I am poitive that it was DSSAgent that Ad-Aware found ~ I wrote it down. I did remove the Yahoo toolbar before I did the READ ME steps. Could it have been in that maybe? I have never downloaded the Yahoo toolbar I don't know where it keeps coming from. I have had to delete it twice.

    After I posted my logs I decided to cleanup my computer. I ran the disc cleanup and the disc defragmenter. Could this be the reason I can't find the files (see below) to delete.




    I am unable to find these files to delete. I follow the path all the way to "bellsouth.net" and then find inbox.sbd ~ this is the only inbox folder there. Indise this folder I find these 2 files and one folder ~ the folder is empty.

    saved ebay mail
    saved ebay mail.msf
    saved ebay mail.sbd



    This is the next file I am unable to find.

    C:\WINDOWS\SYSTEM32\DRIVERS\ETC\hosts.20050416-194053.backup

    I get to the ETC folder and there are 5 files there. One of the files does say hosts but does not have the "20050416-194053.backup" attached to it.

    I am going to post another HJT log so you can see if maybe the files were moved during my disc cleanup.

    I won't be trying to "fix" anything else until I have all of this solved.

    Thank you!!
     

    Attached Files:

  6. suzieQQ

    suzieQQ Private E-2

    Just reread my post ~ I wasn't very clear about the files....


    I had no problem finding and deleting this file ~
    C:\WINDOWS\cpbrkpie.ocx

    These are the 3 I am unable to locate ~
    C:\Documents and Settings\Cora Barrett\Application Data\Thunderbird\Profiles\db9ez90g.default\Mail\mail.bellsouth.net\Inbox[price.cpl]
    C:\Documents and Settings\Cora Barrett\Application Data\Thunderbird\Profiles\db9ez90g.default\Mail\mail.bellsouth.net\Inbox[DFC00213.exe]
    C:\WINDOWS\SYSTEM32\DRIVERS\ETC\hosts.20050416-194053.backup
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Bitdefender probably was successful in removing the hosts.20050416-194053.backup file.
    The two email items may have to be deleted while running your email program. The are probably part of a large email file. You could just run Panda again and see if it still detects these. If so, try cleaning them out of your email.
     
  8. suzieQQ

    suzieQQ Private E-2

    Here is the log from the most recent Panda scan and HJT.

    My computer is running much faster now :)

    Thanks!
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Looks pretty good other than the minor detection by Panda on Adware/Coupons. Too bad Panda does not give exactly what it is finding so we could look for it an remove it.

    If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I have an idea to try though for the Coupons thing.

    Download the Registry Search Tool

    Unzip to your Desktop and double click on regsrch.vbs
    (if you have script protection, please allow this to run)

    In the dialog that opens enter the following:

    cpbrkpie.ocx

    Press 'OK'

    The search will run for a while then alert you when it is finished. Press 'OK' and copy the contents of the WordPad window and post in this thread. If it is very long, an attachment would be better.
     
  11. suzieQQ

    suzieQQ Private E-2

    This is what the search pulled up ~


    REGEDIT4
    ; RegSrch.vbs © Bill James

    ; Registry search results for string "cpbrkpie.ocx " 1/28/2006 8:41:37 PM

    ; NOTE: This file will be deleted when you close WordPad.
    ; You must manually save this file to a new location if you want to refer to it again later.
    ; (If you save the file with a .reg extension, you can use it to restore any Registry changes you make to these values.)


    [HKEY_USERS\S-1-5-21-3631196625-3173001342-3775498431-1007\Software\Microsoft\Search Assistant\ACMru\5603]
    "000"="cpbrkpie.ocx "


    I did a search through the start menu and found cpbrkpie control in downloaded program files. It shows under status that it's damamged.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Can you delete this control?

    Let's do a couple more things.

    Run the steps inUsing GetRunKey and attach the log!

    Copy the contents of the below Quote Box to Notepad. Then click File and then Save As. Change the Save as Type to All Files. Name the file fixme.reg and then click save. (make sure you save it somewhere you can find it. Saving it to your Desktop may make that easy.) Then double-click on the fixme.reg file on your desktop (or locate it with Windows Explorer and double click on it if not saved to the Desktop) and when it prompts to Add in to the registry, say yes.
     
  13. suzieQQ

    suzieQQ Private E-2

    I was able to delete the file. The log is attached. I followed the steps in the order you had them listed.


    Thanks!!
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That log is clean! So is everything working OK now? If so, start completing what I gave you in message # 9 if you have not done it already.
     
  15. suzieQQ

    suzieQQ Private E-2

    Thanks!!

    I have only one small problem. When the Microsoft anti spyware does a scan it finds ~ C\windows system 32 \activescan\PSkavs.dll

    I clicked on the "take no action" button because I am thinking this is not a real virus but some files in Panda that should be there for whatever reason. When this happens it does stop the scan (runs in the middle of the night) so I have to take the proper steps and get it going again. Should I do anything about this?

    Thanks!!
     
  16. suzieQQ

    suzieQQ Private E-2

    Other than the small problem I mentioned everything is running great ~ much faster than before!!

    Thanks!
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    pskavs.dll is part of the software from PandaActiveScan and is normally found under the directory "ActiveScan". This is not malware. Just tell MS AS to ignore it and always ignore it.
     
  18. suzieQQ

    suzieQQ Private E-2

    I have followed all of your instructions and everything is working great!

    I am tyring to install a real firewall now but keep getting an error message ~ "not a valid win32 application"

    I am going over to the software forum and see if I can get any answers.

    Thanks so much for all of your help Chaslang!!
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome! Surf safely!

    Make sure you give them the complete error message - not just a piece of it. Also indicate which firewall you were attempting to install.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds