Troj_agent.lik found

Discussion in 'Malware Help (A Specialist Will Reply)' started by CrazyPhucker, Apr 29, 2005.

  1. CrazyPhucker

    CrazyPhucker Private E-2

    Hello. I was running Trend Micro's and it found Troj_agent.lik in two spots. I deleted and ran in safe mode and it cam up clean. I then did all the reccomended scans. Also, I was in my add/remove panel and I noticed something called IE host which I have no idea what it is.
    I was just wondering if anyone else has seen this and if I need to do anything else to get this stuff off my computer.

    Thank you for any help.
    Sincerely,
    C.P.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  3. CrazyPhucker

    CrazyPhucker Private E-2

    Thank you for your respone Chaslang. Here is the log file.

    Thanks again for your help.
    Sincerely,
    C.P.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please remember to exit browsers before you run HijackThis.

    If you still have IEhost in Add/Remove programs, see if it will uninstall.

    You do not really have any major issues that show in your log. Only a few minor problems.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: (no name) - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - (no file)
    O2 - BHO: (no name) - {BDF3E430-B101-42AD-A544-FADC6B084872} - (no file)
    O16 - DPF: {CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA} -
    O16 - DPF: {CAFEEFAC-0014-0002-0004-ABCDEFFEDCBA} -
    O16 - DPF: {CAFEEFAC-0014-0002-0005-ABCDEFFEDCBA} -

    After clicking Fix, exit HJT.
     
  5. CrazyPhucker

    CrazyPhucker Private E-2

    Good Morning Chaslang. Thanks again for your help.
    I tried to uninstall that IE Host program in add/remove programs and it stated "please wait while we download the uninstaller." That got me nervous, so I canceled the download. It just didnt seem right.

    I fixed the selections that you gave me in HJT. I have a new log file. I will wait till you ask to see it.

    Thanks again for your time.
    Sincerely,
    C.P.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please download, install, and update: Spy Sweeper

    Then run a full scan with Spy Sweeper and fix what it finds. Post the log from Spy Sweeper as an attachment.

    I'm hoping it will take care of IEHost.
     
  7. CrazyPhucker

    CrazyPhucker Private E-2

    Good Moning Chaslang.
    Ok, I did the scan and it did find some objects. I am really concerned about that Spy Agent. Attached is a log file from the Spy Sweeper and a new HJT.

    IE Host is still in Add/Remove programs though.

    Thanks again for your time and effort.

    Sincerely,
    C.P.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! SpySweeper found and cleaned a bunch of things (including Spy Agent you mentioned).

    It would be a good idea for you to disable Spybot's Teatimer as it could be blocking some changes we are trying to make and in addition it can be a resource hog at times. Also running it plus Spy Sweeper plus MS Antispyware at the same time can slow things down dramatically.

    To disable TeaTimer, run Spybot and click Mode and select Advanced Mode. Then click Tools and select Resident. Now in the right window pane, uncheck TeaTimer.
    Also while this is open, in the left column now select IE Tweaks and then in the right pane make sure all the Miscellaneous locks are unchecked.
    Now quit Spybot!

    Now have HijackThis fix the below lines:

    O16 - DPF: {CAFEEFAC-0014-0002-0004-ABCDEFFEDCBA} -
    O16 - DPF: {CAFEEFAC-0014-0002-0005-ABCDEFFEDCBA} -


    Try this for the IEhost program:

    Copy the contents of the Quote Box below to Notepad. Then click File and then Save As. Change the Save as Type to All Files. Name the file fixieh.reg and then click save. (make sure you save it somewhere you can find it. Saving it to your Desktop may make that easy.) Double-click on the fixieh.reg file on your desktop (or locate it with Windows Explorer and double click on it if not saved to the Desktop) and when it prompts to add to the registry say yes.
    And look for the below two files and delete them if found (also look in c:\windows\system32 ):
    c:\windows\clbcatq5.exe
    c:\windows\commdlg5.exe
     
  9. CrazyPhucker

    CrazyPhucker Private E-2

    Good Morning Chaslang.

    I disabled TeaTimer and fixed the two issues with HJT and everything went fine.

    I tried to add the registry key but it gave me an error of “The specified file is not a registry script. You can only import binary registry files from within the registry editor.”

    I also looked for the two .exe files in both places and did not find a thing.

    I know you are a very busy person, thank you so much for all your help.

    Sincerely,
    C.P.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That was my fault (your right - I'm very busy and I left something out that is needed. Try the below.


    Copy the contents of the Quote Box below to Notepad. Then click File and then Save As. Change the Save as Type to All Files. Name the file fixieh.reg and then click save. (make sure you save it somewhere you can find it. Saving it to your Desktop may make that easy.) Double-click on the fixieh.reg file on your desktop (or locate it with Windows Explorer and double click on it if not saved to the Desktop) and when it prompts to add to the registry say yes.

    Then let me know how things are looking.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds