Troj_agnet.csv

Discussion in 'Malware Help (A Specialist Will Reply)' started by wachtwoord, Aug 13, 2006.

  1. wachtwoord

    wachtwoord Private E-2

    hi,

    (I'm using win XP pro SP1)
    My anti virus software found the abovementioned virus inside the C:\windows\system32\winzwr32.dll
    I cannot remove the file, also not logged in as administrator or in safe mode. I tried the solution offered at trend micro's virus list (http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ_AGENT.CSV)
    but that didn't help either. Does anyone have an idea how to solve this?

    Thanks in advance
     
  2. wachtwoord

    wachtwoord Private E-2

    sorry there is no edit button. I forgot to metion that winlogon.exe has a lock on the file (and winlogon can't be killed)
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Majorgeeks!

    You have to unhook the DLL from both winlogon.exe and maybe explorer.exe and then you need to remove the registry keys (Winlogon>Notify) where this file has hooked itself into loading itself at reboot. Then you need to boot into safe mode and delete the file and possibly some other files in your %TEMP% folder. Now if you don't no how to do all of that, you will need to run the below steps which are highly recommended anyway because this infection often arrives with other problems (like Virtumonde).


    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Downloading, Installing, and Running HijackThis

    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.



    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:

      • [*]runkeys.txt - the log from GetRunKey.bat
        [*]newfiles.txt - the log from ShowNew.bat
      • CounterSpy - ONLY IF you were not able to run Windows Defender
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  4. wachtwoord

    wachtwoord Private E-2

    Thank you.

    I did the scans, however I was unable to do the online virus scans in safe mode (I did them in normal boot).
     

    Attached Files:

  5. wachtwoord

    wachtwoord Private E-2

    I zipped counterspy and newfiles because they were too large (> 250 kb).
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Is the below ProxyServer something you setup?
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 130.37.198.243:3124

    The below things are the source of many of your problems. You need to stop downloading stuff like this.
    E:\bu\CloneCD.v5.0.0.0\Keygen.exe
    G:\my documents\Teach YOU how to crack (hack) files

    Look in Add/Remove Prorams for ToolBar888 and uninstall if found (CounterSpy may have deleted already).
    Did you install Maya 6.5? If so, what is it. If not, then uninstall it.

    Make sure viewing of hidden files is enabled (per the tutorial).
    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O20 - Winlogon Notify: winzwr32 - winzwr32.dll (file missing)

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    G:\my documents\Teach YOU how to crack (hack) files <--- the whole folder
    C:\Program Files\Common Files\{BCC94447-096B-1033-0517-051110200001} <--- the whole folder
    C:\Program Files\alias <--- the whole folder
    C:\Program Files\DAEMON Tools\SetupDTSB.exe

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST).

    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\Kevin1\Local Settings\TEMP

    Now reboot into normal mode.

    Now attach a new HJT log and tell me how the steps went.

    Also attach a new log from ShowNew and a new log from GetRunKey.

    Make sure you tell me how things are working now.
     
    Last edited: Aug 14, 2006
  7. wachtwoord

    wachtwoord Private E-2

    The proxy is something I used a long time ago it's filled in but not activated in IE I probably never removed it because I use FF mostly now.

    Maya is a 3d modelling software package: http://en.wikipedia.org/wiki/Maya_(software)

    Toolbar888 is not in my add/remove programs list, maya, however is. But the remove program option isn't working probaly because counterspy removed some or all of the components (I don't even have a C:\program files\alias dir anymore). So I should only edit the registry to make it reflect in the add/remove programs list? (I haven't done so I'm only doing as instructed).

    Then I let HJT fix O20, after which i booted into safe mode.

    I removed the folders and files without problems (other then C:\Program Files\alias did not exist and C:\WINDOWS\Temp and C:\Documents and Settings\Kevin1\Local Settings\TEMP where already empty
    (Ccleaner?)

    And how it's running? I don't see any *.tmp.exe applications running anymore in taskmanager and before I did your read me first I got a window with caption dialer and text: "connessione impossible! Il programma sara' terminato" but that was already gone after running through the read me first (I think counterspy got that).

    Attached are the requested logs. Thanks for your help and time :)
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    But do you need it when you use IE? If not, you can just have HJT fix that line.

    Then it looks like CouterSpy s falsely associated this with what it calls Screenmates. See the below link. It was the Alias folder the probably triggered them.

    http://research.sunbelt-software.com/threatdisplay.aspx?name=ScreenMates&threatid=44395

    I would say this is something you can reinstall if you use it. Note that it is not completely uninstalled right now. A service is still showing for Maya.

    Let's include it in the below steps to remove it! You still have a few things hanging around from Virtumonde and Winlogonhook infections.

    Please download and install Registrar Lite Make sure you select a Majorgeeks download link and not the Authors!

    Run Registrar Lite navigate to the following key and take ownership of it (explained further down):

    HKEY_LOCAL_MACHINE\software\microsoft\mssmgr

    To take ownership of the key do the following:
    • Copy & Paste the registry key from above into the address bar of Registrar Lite and hit the enter key. This will bring you to the registry key.
    • Click-on Security in the Menu
    • Select Take Ownership
    • Now leave RegistrarLite running and continue
    • Now run the NEW REGISTRY PATCH below in this message.
    • Tell me the results. Any error messages?
    • Now in RegistrarLite click View and then Refresh
    • Now navigate to HKEY_LOCAL_MACHINE\software\microsoft\mssmgr
    • Does the above mssmgr key still exist! If so, right click on it and select Delete.
    Here is the Registry Patch

    Now Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    [/quote]REGEDIT4


    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run]
    "{BCC94447-096B-1033-0517-051110200001}"=-

    [-HKEY_LOCAL_MACHINE\software\microsoft\mssmgr]

    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ToolBar888]
    [/quote]


    After completing ALL of the above instructions, continue here!

    Now Double check to make sure the below folder has been deleted. If you find it, delete it.
    C:\Program Files\Common Files\{BCC94447-096B-1033-0517-051110200001}

    Now attach a new log from GetRunKey!
     
  9. wachtwoord

    wachtwoord Private E-2

    I don't use the proxy, in IE the option "use a proxy for your LAN" isn't turned on, I just never removed the actual filled in fields (which it remembered). I'll remove it anyway.

    The patch gave no errors (it just said it merged into the registry)It also deleted the mssmgr key, I did not have to manually delete it.

    The C:\Program Files\Common Files\{BCC94447-096B-1033-0517-051110200001} folder also was no longer there.

    Attached is the new runkeys.txt

    BTW: what should I do about the half-delted maya install? I don't really use it anymore anyway and can reinstall it when I want to use it again, what registry keys do I need to remove for that?
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What we need to remove is the below service:
    O23 - Service: Maya 6.5 Documentation Server (maya65docserver) - Unknown owner - C:\Program Files\Alias\Maya6.5\docs\wrapper.exe" -s "C:\Program Files\Alias\Maya6.5\docs\Wrapper.conf (file missing)

    Here is how we remove it

    Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'. On the page that opens, scroll down to Maya 6.5 Documentation Server ... then right click the entry, select 'Properties' and press 'Stop Service'. When it shows that it is stopped, next please set the 'Start-up Type' to 'Disabled'. Press 'OK' until you get back to Windows.

    Next, run HJT, but instead of scanning, click on the "None of the above, just start the program" button at the bottom of the choices. At the lower right, click on the 'Config" button, and then the Misc tools' button ... select 'Delete an NT Service" ... copy/paste the following into the box that opens, and press "OK":

    maya65docserver

    If you receive any error messages just ignore them and continue.

    Now exit HJT and reboot when it tells you it needs to.

    After reboot just verify the above 023 line is gone! Also delete the below folder if it exists:
    C:\Program Files\Alias
     
  11. wachtwoord

    wachtwoord Private E-2

    ok done, it's gone from the list.

    About the programs that caused the infection, they're both from a long time back (from my previous pc, I moved the HD) and one of them was never actually executed on this system. (the other was).

    The windows install on my old pc must be infected too. Doesn't matter I never use the windows install on that pc anymore (just the ubuntu install it's a dual boot).

    But to close of: Again, thanks a lot for your time and effort.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. If you are not having any other malware problems, it is time to go back to step 1 of the READ & RUN ME to Disable System Restore which will flush your Restore Points. Then reboot and enable System Restore to create a new clean Restore Point.

    After that, you should work thru the below link:

    How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds