Trojan Horse Agent_r.XJ

Discussion in 'Malware Help (A Specialist Will Reply)' started by misskm, Apr 21, 2011.

  1. misskm

    misskm Private E-2

    Hi - I know there are a lot of posts for this particular virus but so far I can't find a response for my particular situation. I got the agent_r.XJ virus a couple of days ago and have tried almost everything to get rid of it, without a lot of success.

    AVG Free can see the problems (3 pairs: wuauclt.exe, svchost.exe and explorer.exe) - but can't erase them. I have run SuperAntiSpyware and it seems to get rid of one pair. Malwarebytes gets rid of another pair, but I can't seem to get rid of the explorer.exe pair. I tried running Avast and it blocks attempts to affect svchost.exe but can't find anything when I do a scan (I get a 'threat has been detected' about 3 times in a row every 20 minutes).

    I've run Spybot and CCleaner which found other issues, but didn't solve the problem.

    I downloaded TDSSKiller and it stalled at 80% initialization - even when I ran it in safe mode and as administrator. I also tried re-naming it and running it and the same thing happened. I have tried other rootkit removers and they have either crashed or not found anything.

    The computer is very slow and often gets a blue screen. Any idea what I could do? Thank you in advance for any help.
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  3. misskm

    misskm Private E-2

    Thank you for looking at my post... I have been working on this issue now for about three days straight (I'm usually fairly good at getting rid viruses and malware for friends - I don't usually get them on my machine)... I spent all day today following the instructions in the guide exactly as they specified.

    The results:

    - Uninstalled all but one virus program - left Avast on as it blocks the dangerous URLs (got rid of AVG)
    - Did all the housecleaning steps
    - Superantispyware and Malwarebytes found nothing (have run both of these multiple times in the last couple of days - and have updated them both).
    - Combofix causes a computer crash with a blue screen
    - MGtools gets most of the way through and then crashes with a blue screen.
    - RootRepeal does part of a scan and also crashes with a blue screen - it did show a few temp files before it happened.

    The blue screen also appears when I try to reboot or shut down the computer. There are multiple svchost.exe files in my processes - some with huge numbers beside them.

    What can I do? I don't mind formatting but I don't have a Vista boot disc... I may have made some a few years ago, but they've gone missing in the multiple house moves I've done...
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You need to post in the software forum regarding your BSOD's. Right click My Computer / properties / Advanced settings / Startup and Recovery and uncheck the box to restart on errors. You will then get the error messages with each BSOD. Post that info in the thread you start in software. We have to have a stable system in order to carry out the malware cleaning.

    You could try creating one of these discs on another computer and then boot to it with the infected machine:

     
  5. misskm

    misskm Private E-2

    Thanks so much :) I've seen your postings on here to everyone and you're so helpful and patient... do you get paid for this?

    I really appreciate your time. Hopefully I can sort out the issues soon - I'll look at your suggestions... I got a new laptop the other day and the problem is on the old one... was going to give it to my partner but might get him to try and fix it!
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome. I hope you can get it sorted out. We are all volunteers on this site, we all are just trying to "give it back" for others. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds