Trojan Horse Downloader.Agent.6.I

Discussion in 'Malware Help (A Specialist Will Reply)' started by sharpxl521, Jan 5, 2005.

  1. sharpxl521

    sharpxl521 Private E-2

    Ok, i've followed the sticky threads and removed all the problems i could find(irritating toolbars). But upon restart, AVG still picks up the title trojan and deletes it. C:\WINDOWS\SYSTEM32\MSWX.DLL was the most recent file, but these seem to change name after a reboot (yes system restore is turned off). I think my HJT log is clean but i'd appreciate it if someone could doublecheck it. Any suggestions on how to remove Downloader.Agent.6.I?. Thanks ;)
     

    Attached Files:

    Last edited: Jan 5, 2005
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The online scanners in the READ ME thread are not optional. They must be run. Did you skip anything else?

    Have you manually gone in yourself in safe mode and looked for the files (like C:\WINDOWS\SYSTEM32\MSWX.DLL ) and look to see if still present and delete them.
     
  3. sharpxl521

    sharpxl521 Private E-2

    Thanks for the quick reply ;)

    Yes, i've been into safe mode and tried removing the infected files, but they just keep coming back. AVG's obviously not picking up the root of the problem.

    I haven't run the online scanners because i can't get online in safemode with networking. Ports 1 and 2 are available, but not port 3.....which is where my modems situated. Is there anyway to enable this in safemode, so i can get online and do a scan?. Thanks :)
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The READ ME tells you:

    You need to run them in normal boot mode and you should have reported that you had a problem trying to run them in safe mode so you ran them in normal mode.

    Complete the scans and report back!
     
  5. sharpxl521

    sharpxl521 Private E-2

    Ok, i ran the scans in normal mode and they turned up nothing. I also used the free online trojan scanner and that also failed to find anything. AVG's still finding Downloader.Agent.6.I in the SYSTEM32 folder, on restart. The latest one being mslm.dll. I've removed the files manually as well as letting AVG delete them, but nothing seems to work. They just come back over and over. Any suggestions on what to try next. Thanks :) .
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What is your complete version number of AVG?
    And have you run a full scan with AVG in safe mode?
     
  7. sharpxl521

    sharpxl521 Private E-2

    AVG Free Editon
    Program version 7.0.300
    Virus Base 265.6.9 release date 1/6/2005
    Basically as up to date as it can be.
    I've already done a full scan with AVG in safe mode. It again picks up the infected file or files (infected with Agent.6.I) removes them, only for them to come back on reboot. A reformat and reinstall is looking ever nearer, but i appreciate all the help your a giving me and want to stick at it a little longer. Any other ideas?. Thanks :)
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If it is always changing names, something else must be spawing the DLLs.
    Besides C:\WINDOWS\SYSTEM32\MSWX.DLL what other names have you seen?
    Is it still called C:\WINDOWS\SYSTEM32\MSWX.DLL?

    Please download Pocket KillBox do not run yet.
    Here are the files that we need to delete using PocketKillbox.

    C:\WINDOWS\SYSTEM32\iecust.exe
    C:\WINDOWS\SYSTEM32\openconf.exe
    C:\WINDOWS\SYSTEM32\pentxpl.exe
    C:\WINDOWS\SYSTEM32\qappsrvc32.exe
    C:\WINDOWS\SYSTEM32\taskopen.exe
    C:\WINDOWS\SYSTEM32\unlodctl.exe
    C:\WINDOWS\SYSTEM32\FNTCACHE.DAT
    C:\WINDOWS\SYSTEM32\msqr.dll
    C:\WINDOWS\SYSTEM32\iecust.dll
    C:\WINDOWS\SYSTEM32\dnsauth.dll
    C:\WINDOWS\SYSTEM32\dx9vbc.dll
    C:\WINDOWS\SYSTEM32\msuv.dll
    C:\WINDOWS\SYSTEM32\mswx.dll
    C:\WINDOWS\SYSTEM32\msvw.dll
    C:\WINDOWS\SYSTEM32\menu.txt
    C:\WINDOWS\SYSTEM32\msno.dll
    C:\WINDOWS\SYSTEM32\msab.dll
    C:\WINDOWS\SYSTEM32\hdon.dll
    C:\WINDOWS\SYSTEM32\msxy.dll
    C:\WINDOWS\system32\msfg.dll
    C:\WINDOWS\system32\mstu.dll
    C:\WINDOWS\system32\mslm.dll

    and C:\WINDOWS\system32\mswx.dll


    Here is the procedure to use to delete them. Run Pocket Killbox. Select the option to Replace on Reboot.

    Now you are going to repeat the below steps for every file except C:\WINDOWS\system32\mswx.dll (we will add it separately at the end). Replace the the word fullpathfile with the actual full file name path from above (one file at a time). For example, the first time you paste in C:\WINDOWS\SYSTEM32\iecust.exe



    1) Now, Copy and Paste fullpathfile into the box
    2) Check the option to Use Dummy.
    3) Now, Click the Red X and Yes to the confirmation message.
    4) A message will ask if you want to reboot now – Click NO.
    5) Repeat for all files except the last one

    For the last file, we will be rebooting when prompted. Here is the final step of the file deletions:

    Now, Copy and Paste C:\WINDOWS\system32\mswx.dll into the box. Check the option to Use Dummy and Click the Red X and Yes to the confirmation message. A message will ask if you want to reboot now – Click YES and allow your machine to reboot but boot into Safe Mode and run a full scan with AVG and let's see what happens. Write down any files that it finds.

    If you still have the problem, download the below file to your computer where you can find it.

    RemV3.Zip

    Extract all the files to a folder (make it a folder for only these tools).
    Then boot into safe mode and run the remv3.bat file.

    Now reboot in normal mode and try running AVG.
     
    Last edited: Jan 8, 2005
  9. sharpxl521

    sharpxl521 Private E-2

    So far the infected files have been C:\WINDOWS\SYSTEM32\msab.dll, msbc.dll,msde.dll, msij.dll, msqr.dll, msst.dll, msuv.dll, msvw.dll, msxy.dll, msyz.dll, msz{.dll.

    I followed your Killbox instructions to the word, rebooted into safemode and AVG picked up infections in C:\WINDOWS\SYSTEM32\msbc.dll and msyz.dll. AVG proceeded to delete these files.

    While still in safemode, i installed and ran remv3.bat .
    Files Found.................
    ----------------------------------------
    unlodctl.exe
    qappsrvc32.exe
    taskopen.exe

    Files Not deleted.................
    ----------------------------------------

    Merging registry entries
    -----------------------------------------------------------------
    The Registry Entries Found...
    -----------------------------------------------------------------


    Other bad files to be Manually deleted.. Please note that this might also list legit Files, be careful while deleting
    -----------------------------------------------------------------
    hdts.dll
    msi.dll
    msxy.dll
    Finished

    I manually deleted all 3 exe's and 2 dll's. msi.dll would not delete "full write protected or in use".

    I finally booted back into normal mode and windows reported qappsrvc32.exe
    as missing (was that a system file?) . I ran AVG and no infections were found.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well at least we now have a clean AVG scan! ;)
    qappsrvc32.exe is not a system file. It is part of the infection we were trying to clean. Something is trying to load it. Please post a HijackThis log attachment.
     
  11. sharpxl521

    sharpxl521 Private E-2

    Yep, the clean AVG scan is much appreciated!! :) .
    I've rebooted a couple of times since and there were no other warning messages about qappsrvc32.exe being missing. It's nowhere to be found on my HDD either, but i've attached my HJT log anyway.

    Is the fact i couldn't delete msi.dll important? Thanks ;)
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Yes! msi.dll is needed. See this: http://www.liutilities.com/products/wintaskspro/dlllibrary/msi/

    You have some new stuff in your log to fix. One of them is a trojan. Also stop using HSremove unless you have an HSA hijack.

    If you are using WinXP or WinMe, make sure you have system restore disabled (per the tutorial).
    For all OS types, make sure viewing of hidden files is enabled (per the tutorial).


    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    O2 - BHO: (no name) - {A5366673-E8CA-11D3-9CD9-0090271D075B} - (no file)
    O4 - HKLM\..\Run: [taskopen.exe] taskopen.exe
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll (file missing)
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll (file missing)
    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\system32\taskopen.exe

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.

    Now you really need to perform the steps here: How to Protect yourself from malware!
     
    Last edited: Jan 9, 2005
  13. sharpxl521

    sharpxl521 Private E-2

    I fixed the files with HJT with no problem, but when i booted into safemode to remove taskopen.exe, it was nowhere to be found (show hidden files is enabled) . So did HJT remove it?.
    AVG is still showing a clean scan :) . Is my HJT log clean?. Thanks ;)
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    No HJT does not delete files. It only fixes (removes) registry entries.

    At any rate, your log is clean now.
     
  15. sharpxl521

    sharpxl521 Private E-2

    Great!!!. I really appreciate all the help, chaslang :) . Everything appears clean and i'll keep a close eye on things and report back any finds. I've also followed all measures in the "protect yourself from malware" thread, so hopefully i'll not have any more problems. Thanks once again ;)
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. The How to protect will help prevent problems but nothing can stop them completely.
     
  17. sharpxl521

    sharpxl521 Private E-2

    I spoke too soon :rolleyes: . The following line has returned in my latest HJT log.

    O2 - BHO: (no name) - {A5366673-E8CA-11D3-9CD9-0090271D075B} - (no file)

    I've tried getting it to fix, but it just comes back again. sorry to be a pain in the a$$, but any suggestions?. Thanks ;)
     

    Attached Files:

  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That BHO is part of FlashGet. I'm not sure why it says no file if you still have FlashGet installed. There should be a file associated with it. Do you use FlashGet? You could try uninstalling FlashGet and rebooting and then re-installing it and see if the file now shows up.

    I believe the file should be jccatch.dll

    I had you remove the O2 - BHO line earlier because there was no file, but since they keep putting it back you may need to re-install to get the file back.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds