services.exe (Trojan.Agent)...

Discussion in 'Malware Help (A Specialist Will Reply)' started by Mogwai, Jun 29, 2010.

  1. Mogwai

    Mogwai Private E-2

    Okay since I got back from uni my laptop has gone crazy with a virus. Please please would someone give me a hand?

    The problem manifests itself by turning the volume to silent, playing horrible adverts in the background...I often here this little jingle: "washing machines live longer with Calgon" If I'm watching something on Iplayer then it minimises the screen, and clicks in the background and then turns the sound settings to silent.

    So I've tried the complete list of recommendations of downloading all the programs and spending the day scanning and rescanning with them. It does find the trojan but can't seem to deactivate it to delete it.
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Could you please also attach the last requested log? C:\Mglogs.zip into your next reply, so that I can give you a complete fix.
     
  3. Mogwai

    Mogwai Private E-2

    For some reason I can't find that one. When it was scanning it kept saying that it couldn't write to c:\mglogs.zip

    Should the file just be in c:?
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes it should be. If you cannot locate it or it does not exist then I need you to rerun C:\MGTools.exe and see if we can generate a log. If you have difficulties running it, try renaming it to 123.com, try safe mode if normal mode is not possible for the running of it.
     
  5. Mogwai

    Mogwai Private E-2

    Running it now with it renamed. The message it throws up while running is:

    "zip error: Could not create output file <c:/mglogs.zip>"

    Followed by lots of "Access denied" messages.

    I think I'll have to give it a go in safe mode

    Thanks for such a quick reply by the way, it's much appreciated.
     
  6. Mogwai

    Mogwai Private E-2

    Okay, it worked fine in safe mode, thanks. Here's the final log.
     

    Attached Files:

  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You have a Master Boot Record (MBR) infection as shown by the below to files seen running in your process list:
    Please complete the below in normal mode.

    We need to see the below log before creating a fix.
    • Download bootkit_remover.rar
    • Click the underlined DOWNLOAD text to download the file and save it to your Desktop.
    • You then need to extract the remover.exe file from the RAR using a program capable of extracing RAR compressed files. If you don't have an extraction program, you can use 7-Zip
    • After extracing remover.exe to your Desktop, double click the remover.exe file to run the program.
    • Attach or post inline here, the output from remover.exe
     
  8. Mogwai

    Mogwai Private E-2

    Is this the info you needed?
     

    Attached Files:

  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Thus for example with remover.exe on the Desktop and assuming the physicaldrive0

    • Click Start, Run and copy and paste the below into the Run box and click OK.

    • Now reboot your PC and after reboot continue with the below instructions.
    • Run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  10. Mogwai

    Mogwai Private E-2

    Okay, so the remover.exe gave an error message but I continued with your instructions anyway. I'll include the error message along with the MGLogs.zip file.

    At the moment I'm not noticing any interference from the infection, but a quick scan from malwarebytes finds 5 objects infected and if I run avast then it immediately finds threats.

    Thank you very much for the continued support.
     

    Attached Files:

  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    MGTools wasn't run properly.

    Attach logs showing this, from mbam and let me know where avast is finding threats.

    Please run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  12. Mogwai

    Mogwai Private E-2

    When running getlogs.bat it gives a very quick error message, something about:

    'The system cannot execute the specified program. The process cannot access the file because it's being used by another process'

    It therefore does not update the MGlogs.zip file.

    I've attached the mbam log and included a picture of the avast log as I can't find the file on my computer.

    (avast is unable to move to chest, repair or delete the problems)
     

    Attached Files:

  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Now - please do the following:

    • Click Start, Run then copy and paste the below into the Run box and click OK.
    • Now reboot your PC and after reboot continue with the below instructions.
    • Disable System Restore on all drives.
    • Look for the below folder and if if it sill exists, delete it.
    • o C:\System Volume Information\Microsoft
    • Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\MGlogs.zip

    Make sure you tell me how things are working now.
     
  14. Mogwai

    Mogwai Private E-2

    Clicking on 'C:\System Volume Information' gives the message: 'C:\System Volume Information is not accessible. Access denied.'

    I hovered the cursor over the icon though and it said that the folder was empty.

    Clicking on getlogs.bat does exactly the same thing as before and does not update mglogs.zip
     
  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Then try just double clicking C:\MGTools.exe and see if that generates an updated log.
     
  16. Mogwai

    Mogwai Private E-2

    Running "%userprofile%\Desktop\remover.exe" fix \\.\PhysicalDrive0 produces an error message and mgtools seems unable to write to the zip file. I've included pics of the two windows they throw up.
     

    Attached Files:

  17. Mogwai

    Mogwai Private E-2

    Okay well it got to the end of what it was doing, but I'm not sure if it managed to work properly. This is the zip file after using mgtools.exe.

    I've also included a picture of the info it throws up while running.

    Thanks Kestrel.
     

    Attached Files:

  18. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Those logs are very incomplete :(

    Let me have you do this whilst I consult with colleagues.

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only and save a log file)

    Attach this log into your next reply.

    Please click Start, Run, and enter cmd and click OK. This will open a command prompt window. Enter the below commands at the command prompt each followed by the enter key. The bold black are commands. The purple is merely informational.

    cd \MGtools <-- this changes to the MGtools folder and the prompt should change to C:\MGtools>
    ShowNew <-- this will try to run all another scan from MGtools. Tell me what error messages, if any, you see.
    GetRunKey <-- this will try to run all one scan from MGtools. Tell me what error messages, if any, you see.

    Attach logs.
     
  19. Mogwai

    Mogwai Private E-2

    Thanks. Just a thought, but might completely uninstalling avast and comodo firewall help? At the moment the firewall starts on bootup and I have to manually stop it and avast has a process running in the background despite not actively running. Just wondering whether either of those might be blocking mgtools in the background maybe?


    hijackthis log attached.

    cd \mgtools followed by shownew produced this message: 'the system cannon execute the specified program. The process cannot access the file because it is being used by another process.'

    And 'getrunkey' produces the same error message as above :confused
     

    Attached Files:

  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Now download The Avenger by Swandog469, and save it to your Desktop.

    * Extract+ avenger.exe from the Zip file and save it to your desktop

    Now boot into safe mode.

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Now - please do the following:

    • Click Start, Run then copy and paste the below into the Run box and click OK.

    "%userprofile%\Desktop\remover.exe" fix \\.\PhysicalDrive0
    Now reboot your PC and after reboot continue with the below instructions.
    Disable System Restore on all drives.
    Look for the below folder and if if it sill exists, delete it.

    • C:\System Volume Information\Microsoft
    If it does:
    Boot back into normal mode, disabling your AV software and:
    * Run avenger.exe by double-clicking on it.
    * -Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\Avenger.txt
    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
    Last edited: Jul 3, 2010
  21. Mogwai

    Mogwai Private E-2

    Okay, so I can find system volume information folder, but can't open it and when I hover cursor over it says it is empty.

    When you say: "Now - please do the following:
    Click Start, Run then copy and paste the below into the Run box and click OK.

    "%userprofile%\Desktop\remover.exe" fix \\.\PhysicalDrive0
    Now reboot your PC and after reboot continue with the below instructions.
    Disable System Restore on all drives.
    Look for the below folder and if if it sill exists, delete it.
    C:\System Volume Information\Microsoft"


    Should it be a safe reboot after doing the '"%userprofile%\Desktop\remover.exe" fix \\.\PhysicalDrive0' bit?

    And what should I do if there is no 'microsoft' file or folder in the 'system volume information folder'?
     
  22. Mogwai

    Mogwai Private E-2

    By jove, I think you've cracked it! :yum

    Just doing a quick scan with malwarebytes and it has found nothing.

    Logs attached.

    Thank you Kestrel and Tim so much for your time and hard work. It's very much appreciated.

    Are there any free firewall's and AV software you'd particularly recommend? At the moment I've got Avast and Comodo but I think Avast is only for a 30 day trial period.

    Once again, thank you very much. You guys do a great job.
     

    Attached Files:

  23. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Avast is freeware. Once we are sure you are clean, we will link you to a thread on how to protect yourself from malware.

    In the meantime, you did not allow MGTools to run to completion. Please:
    Run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\MGlogs.zip
     
  24. Mogwai

    Mogwai Private E-2

    I've been asked to double click on getlogs.bat a number of times and it has never worked each time I've done it. Window comes up, then closes super quick with the error message previously stated. Not sure how to make it work.
     
  25. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please run the C:\MGTools\analyse.exe and attach the HJT log. I just want to make sure that the bad files/folder are gone and that you are now clean.
     
  26. Mogwai

    Mogwai Private E-2

    Ah okay, I think that one worked. I've attached the log.
     

    Attached Files:

  27. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good, that is no longer showing the infection. Are you still having any malware issues?

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:

     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds