W32/Agobot-S virus

Discussion in 'Malware Help (A Specialist Will Reply)' started by bjgarrick, Jan 12, 2005.

  1. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Hey chaslang, I have a question about this worm/trojan. My wife got on my computer and apparently got my pc infected with whats called the W32/Agobot-S virus. I have never heard of this particular worm/trojan, are you familiar with it?
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  3. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Hey chaslang, thanks for the information. I looked for the keys in the registry and did NOT find them, ran there removal tool and found nothing. Also ran Trend, TrojanHunter and SpySweeper, nothing as well. I know it was infected because my wife said she clicked a file she downloaded and it said something about "scvhost.exe" well I looked for it but cant find it anywhere so I dont know if im still infected or not. Also in normal mode CPU Usage is 100% but nothing suspicious is running that I see and computer seems to run fine, Any advice?
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Does a process show in HJT? Have you run a full blown antivirus app from safe mode and performed a full system scan?

    Does CPU usage remain at 100% even when not actively doing anything but watching it?
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Also did you look at the registry keys they mentioned?
     
  6. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Not of the "scvhost.exe"

    SpySweeper, TrojanHunter, NAV 2005

    Yes!

    Yes, they did not exist.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Which process is using all the CPU time?
     
  8. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    iexplore.exe [1]
    taskmgr.exe [3]
    System Idle Process [96]

    Thats all TaskManager shows
     
  9. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Also I want to mention, when I ran TrojanHunter and TrojanRemover I recieved the following:

    "regfile = "regedit.exe" "%1"

    "txtfile = %SystemRoot%\system32\NOTEPAD.EXE %1


    Isnt this a Trojan doing this?
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! So no process is using all your CPU time. I don't see a problem.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What are these referring to? I assume they are point out registry keys and the file associations for a .reg and a .txt file.

    These would appear to be normal. Which registry keys were they pointing out.
     
  12. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    ok, thanks chaslang

    If you want a look heres a HGT log, I dont see anything that looks malicious, I dont know what happened to the scvhost.exe but anyway thanks again!


    Not sure which keys, thats all it said. Detected that and said this could possible be a trojan.
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Other than the below, your log is okay! My opinion is nothing should go in the trusted zone nor should it need to be.
    O15 - Trusted Zone: messenger.hotmail.com
    O15 - Trusted Zone: http://g.msn.com
    O15 - Trusted Zone: http://www.msn.com
    O15 - Trusted Zone: loginnet.passport.com
    O15 - Trusted Zone: login.passport.net
    O15 - Trusted Zone: memberservicesnet.passport.net
     
  14. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Ok, thanks chaslang

    Those were put into trusted due to a windows messenger problem not wanting to connect per microsoft, didnt think that would fix it but anyway that was a while back.

    Thanks again!
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Trusted Zone entries fit into one of my pet peeves areas. I just believe they can do more harm then good.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds