Torjan.Agent

Status
Not open for further replies.

jmolina

Posts: 21   +0
Need Help with a client workstation. I keep catching a trojan.agent with malwarebytes and when rebooting and I scan again it comes up with trojan.agent again. Here are my logs for malwarebytes and hijack.
I have ran mcafee corporate editon;cc cleaner;malwarebytes; and super anti spyware. I am stil getting pop ups while browsing with firefox...

Thanks,:)
 

Attachments

  • mbam-log-2009-04-03 (14-23-13).txt
    949 bytes · Views: 5
trojan.agent removal

I offered poor suggestons the first time...
I should have simply referred jmolina to the Virus and Malware removal board,
especially the initial notes by Julio!
 
ok, Thanks I will try this out..

I deleted the files mentioned;I had already tried this but it keeps recreating a different dll and the scan will still come up with Trojan. agent on malwarebytes>>>
 
B00kWyrm, please refer to this: https://www.techspot.com/vb/topic120350.html

jmolina, please refrain from doing any Registry Edits.

If you followed the steps set up here: https://www.techspot.com/community/...lware-removal-preliminary-instructions.58138/
You will see that you are missing the SuperAntispyware log. But we'll go with what we have for now:

Remove bad HijackThis entries
• Run HijackThis
• Click on the System Scan Only button
• Put a check beside all of the items listed below (if present):
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ihub/
O4 - HKLM\..\Run: [Szagari] rundll32.exe "C:\WINDOWS\ucaxodem.dll",e
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\WINDOWS\System32\shdocvw.dll

They will need to verify if this is a company or work Domain: If it is leave the entries. If it is not, check for HijackThis to remove:
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = chi.crainit.com
O17 - HKLM\Software\..\Telephony: DomainName = chi.crainit.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = chi.crainit.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = crain.com
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = crain.com

• Close all open windows and browsers/email, etc...
• Click on the "Fix Checked" button
• When completed, close the application.


Uninstall, then reinstall Spybot Search & Destroy. Be sure Teatimer is disabled for now

Download and Install SDFix from HERE and save to your desktop.
* Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)

Boot into Safe Mode
* Restart your computer and start pressing the F8 key on your keyboard.
* Select the Safe Mode option when the Windows Advanced Options menu appears, and then press ENTER.

Run SDFix
* Open the extracted SDFix folder and double click RunThis.bat to start the script.
* Type Y to begin the cleanup process.
* It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.

* Press any Key and it will restart the PC.
* When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
* Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
* Attach Report.txt back here

Please update and run Superantispyware after SDFix and follow that with a new HijackThis scan. Attach all logs and report.
 
What Bobbye said...

It might be good for someone to delete my previous post.
That way it won't be an issue later for someone else stumbling across this thread.
If someone knows how to see that that happens...

1. Registry edits should not be attempted by the casual or novice user,
and should never be advised without adequate caveats...
no matter how certain I may have been that that edit would have done no harm.

2. The eight steps are certainly "Best Practice" strategy for dealing with an infection.

3. The Virus & Malware removal board rules should have governed my reply,
because that is exactly the topic of the question... even if not on that board.

My bad, on at least three counts.

So, jmolina, my sincere apologies, and I hope I did you no harm. :eek:
 
Torajan.Agent

Still getting the Trojan.Agent with malwareBytes after runnig 8step and the recommended scan here are all my logs.
 
Status
Not open for further replies.
Back