Spy-Agent.n

Discussion in 'Malware Help (A Specialist Will Reply)' started by jfkruyer, Sep 17, 2006.

  1. jfkruyer

    jfkruyer Private E-2

    McAffe VirusScan tells me winlogon.exe is infected with the SpyAgent.n virus - - - cannot be cleaned, deleted blah, blah, blah. In safe mode I ran CCleaner, Ad-Adware SE, Spybot S&D, Trend Housecall, Ewido Anti-Malware. you guessed it! I still get the McAfee warning. Here are the results of my Hijack This log.

    EDIT: Removed incomplete and inlien HJT log

    Thanks in advance for your help. You folks are great!
     
    Last edited by a moderator: Sep 17, 2006
  2. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Hi and Welcome :)


    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Downloading, Installing, and Running HijackThis

    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.


    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
      • CounterSpy - ONLY IF you were not able to run Windows Defender
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • runkeys.txt - the log from GetRunKey.bat
      • newfiles.txt - the log from ShowNew.bat
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  3. jfkruyer

    jfkruyer Private E-2

    Okay now. I performed all the steps recommended inRead & Run Me First - - - and I still have issues with the Spy-Agent.n trojan.

    Ran Microsoft Windows Malicious Software Removal Tool - Full Scan - "No malicious software detected". Ran Spybot S&D - "Your computer is running normally."


    Here are the results of BitDefender, Panda and runkeys


    Thanks,

    Joe
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please attach all of the logs that Halo requested. Also you skipped step 0 of the READ ME. Viewpoint Manager should have been uninstalled in step 0.

    Is your copy of Ewido a paid or free trial version?

    You now need to run this: WareOut Removal and attach the requested log.
     
  5. jfkruyer

    jfkruyer Private E-2

    Okay - moving forward. I removed Viewpoint Media and Viewpoint Manager. Ewido is a trial version. Now as attachments: newfiles.txt and my HijackThis log.

    Thanks,

    J
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay but what about the log from the WareOut Removal procedure I asked you to run.

    You also need to follow the directions in step 7 of the READ ME from beginning to end. The version of HijackThis you are using has not been used in two years. Please follow the directions in step 7 and use the proper version and attach a new log.

    You also need to get your Sun Java version updated.


    First install the current version of Sun Java from: Sun Java Runtime Environment

    Then uninstall the below old versions of software:
    J2SE Runtime Environment 5.0
     
  7. jfkruyer

    jfkruyer Private E-2

    Okay, I believe I have completed everything as you asked.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Make sure viewing of hidden files is enabled (per the tutorial).

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O4 - HKLM\..\Run: [FinishOptions] C:\DOCUME~1\Joe\LOCALS~1\Temp\hpbinxst.exe
    O4 - HKLM\..\Run: [de288d13918] C:\WINDOWS\System32\de288d13918.exe
    O4 - HKCU\..\Run: [de288d13918] C:\WINDOWS\System32\de288d13918.exe

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\Documents and Settings\Joe\Local Settings\hpbinxst.exe
    C:\WINDOWS\System32\de288d13918.exe
    C:\WINDOWS\SYSTEM32\DMCPL.EXE

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST).

    Now reboot in normal mode

    Now delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp\
    C:\Documents and Settings\Joe\Local Settings\TEMP

    Now attach a the below new logs and tell me how the above steps went.

    1. GetRunKey
    2. ShowNew
    3. HJT
    Make sure you tell me how things are working now!
     
  9. jfkruyer

    jfkruyer Private E-2

    I fixed all the stuff you recommended on HJT.

    I did not delete this file - C:\Documents and Settings\Joe\Local Settings\hpbinxst.exe. I found it in another directory C:\Program Files\Hewlett-Packard\Desk Jet 6800\Installs\Installer. This is my printer.

    Could not find C:\WINDOWS\System32\de288d13918.exe. Even did a search with hidden files checked.

    Deleted as requested. C:\WINDOWS\SYSTEM32\DMCPL.EXE

    Deleted all files in Windows\Temp except a bunch sqlite.... which we todays date. And, similary Joe\Local Settings\Temp: ~DF31AM.tmp and ~DF2684.tmp, which had today's date.

    Here are the log files you requested.

    My brain hurts. I must go!
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes I know that hpbinxst.exe can be related to an HP printer, but it does not belong in the Local Settings folder as far as I'm concerned. In should be in a folder named for HP. Either it was not installed properly or this file is still of questionable origin. Or a third choice is that it was only required during installation and was never cleaned up properly after install. I doubt the file is needed. Do you even know what it is for?

    You did not tell me how things are working.
     
  11. jfkruyer

    jfkruyer Private E-2

    McAffee does not give the erro messages anymore. That's good and thanks for your help. The computer seems to boot up slower than it used to. I'm oing to clean up my software - especially uninstall ewido. Even though it is a trial version and I thought all it does is scan on demand, it seems to be running in the background. I know for sure that it goes out for virus updates every time I boot up. I'll have to go to Task Manager to see if it is running. That should work right?

    Again,

    Thanks for your patience and help.

    Joe
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Ewido installs some process that run as services. You cannot stop them via Task Manager. You should just uninstall Ewido since it is only the trial version and you do not want it running at the same time as Windows Defender because that would be a big waste of system resources and they will also conflict with each other.

    As far as PC performance is concerned, your biggest gain would be observed by uninstalling McAfee and using a couple tools from the How to protect thread (see below) in place of McAfee. What you are running is a massive resource hog.

    If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds