also @ TechSpot: Tech Tip: Turn Off your Display Using a Windows Shortcut and More
Welcome to the TechSpot OpenBoards. Please read the FAQ if you have any questions. Login to participate.

Go Back   TechSpot OpenBoards > Operating Systems & Software > Virus & Malware removal

Trojan.downlaoder.win32.agent

Closed Thread
Page 1 of 2 1 2
Bookmark Thread Tools
  #1  
Old 11-19-2008
Newcomer, in training
 
Location: Seattle
Member since: Nov 2008, 18 posts
I finally got around to fixing my laptop, got wow all installed on it, downloaded some stuff, and now my avg scans are showing all sorts of crazy stuff... and when I open wow, it says I have a "trojan.downloader.Win32.Agent varient. Please help!

I attached the results from hijack this, superantipsyware, etc.
Attached Files
File Type: txt mbam-log-2008-11-19 (15-52-29).txt (4.4 KB, 2 views)
File Type: log SUPERAntiSpyware Scan Log - 11-19-2008 - 14-46-06.log (39.1 KB, 4 views)
File Type: log hijackthis.log (5.6 KB, 2 views)

Last edited by kimsland; 11-20-2008 at 02:33 AM.. Reason: Posts merged
  #2  
Old 11-20-2008
TechSpot Member
 
Member since: Aug 2008, 112 posts
in Mbam you did not do anything with the trojans
When scan is done look at the file list or report and then remove everything
did you remove everything in SAS?
tell me whats happening with your comp
To remove this ad, sign in. To register for a new account, click here.
  
  #3  
Old 11-20-2008
Newcomer, in training
 
Location: Seattle
Member since: Nov 2008, 18 posts
I deleted the quarantined items in mbam and sas. It seems like it's better now, I'm not getting the WoW warning and nothings showing up in scans.
  #4  
Old 11-20-2008
Newcomer, in training
 
Location: Seattle
Member since: Nov 2008, 18 posts
When I try to open either of my harddrives (E and C) from My Computer, I get a Windows Popup saying "E:\resycled\boot.com is not a valid Win32 Application." I know enough to know this is not good. I don't really want to reformat my laptop because I don't have all the disks where I'm living right now, I've moved around a lot the past year. Any help, again, is quite appreciated.
  #5  
Old 11-20-2008
TechSpot Member
 
Member since: Aug 2008, 112 posts
Ahh you need to delete Autorun.inf. Is Wow world of warcraft? i don't remember it giving pop ups

If you can fix your comp i hope you know how to delete files through CMD.
The autorun is just in the root of the drive.

i'm very sorry but i'm kinda bad at CMDS
Please post a new hijackthis log
  #6  
Old 11-20-2008
TechSpot Guru
 
Location: Lexington NC USA Eastern Time
Member since: Nov 2008, 2,788 posts
System specs
hell kipperoo15

When any cleaner is ran, it is possible that after one run that removes certain powerful Malware, then it exposes more that were not even seen on the first run.

The goal is to get these to come up clean or find something it can not handle.

So run both MBAM and SAS again and post the logs.

I can tell from the quantity and the quality of what they did find that you in fact have much more.

Good job so far.

Mike
  #7  
Old 11-21-2008
Newcomer, in training
 
Location: Seattle
Member since: Nov 2008, 18 posts
I ran both mbam and Sas, the mbam log is attached, but this time Sas didn't come up with anything.

Thanks for helping, this is a total life saver.
Attached Files
File Type: txt mbam-log-2008-11-20 (22-59-50).txt (2.3 KB, 4 views)
  #8  
Old 11-21-2008
TechSpot Guru
 
Location: Lexington NC USA Eastern Time
Member since: Nov 2008, 2,788 posts
System specs
Hi kipperoo15

Good job!

Run MBAM again until it comes up clean or finds something it can not remove if clean let me know, post log if it does find something it can not handle.

Then do the below

Download SD Fix to Desktop among other things Catchme to look for RootKits.

http://downloads.andymanchesta.com/R...ools/SDFix.exe

On Desktop run SDdFix It will run (install) then close.

Then reboot into Safe Mode

As the computer starts up, tap the F8 key several times.

On the Boot menu Choose Safe Mode.

Click thu all the prompts to get to desktop.

At Desktop
My Computer C: drive. Double-click to open.

Look for a folder called SD Fix. Double-click to enter SD Fix.

Double-clickto RunThis.bat. Type Y to begin.

SD Fix does its job.

When prompted hit the enter key to restart the computer

Your computer will reboot.

On normal restart the Fixtool will run again and complete the removal process then say Finished,
Hit the Enter key to end the script and load your desktop icons.

Once the desktop is up, the SDFix report will open on screen and also be saved to the SDFix folder as Report.txt.

Copy and paste the Report.txt file to your next post.

Mike
  #9  
Old 11-21-2008
Newcomer, in training
 
Location: Seattle
Member since: Nov 2008, 18 posts
I ram mbam a few more times, logs are attached. It keeps coming up with 4 results.
Attached Files
File Type: txt mbam-log-2008-11-21 (15-48-27).txt (1.6 KB, 1 views)
File Type: txt mbam-log-2008-11-21 (16-56-25).txt (1.6 KB, 1 views)
File Type: txt mbam-log-2008-11-21 (18-09-09).txt (1.6 KB, 2 views)
To remove this ad, sign in. To register for a new account, click here.
  
  #10  
Old 11-21-2008
TechSpot Guru
 
Location: Lexington NC USA Eastern Time
Member since: Nov 2008, 2,788 posts
System specs
Ok Kipper

Sorry you took the time to run the third time. After these issues are fixed you should run these programs every 2 weeks or so, but if they come up twice with exactly the same thing no need to run it more.

OK now do the SDFix above to get these we may need to run another tool to finish up.

So do the SDFix it does not take nearly as long as the others.

Mike

Last edited by mflynn; 11-21-2008 at 10:29 PM..
  #11  
Old 11-21-2008
Newcomer, in training
 
Location: Seattle
Member since: Nov 2008, 18 posts
Log Attached
Attached Files
File Type: txt report.txt (2.5 KB, 5 views)

Last edited by kipperoo15; 11-21-2008 at 11:12 PM..
  #12  
Old 11-21-2008
TechSpot Guru
 
Location: Lexington NC USA Eastern Time
Member since: Nov 2008, 2,788 posts
System specs
OK good that was clear.

Again this one doesn't take long either it should find and fix DNSCHanger.

ComboFix

NOTE: If you have had ComboFix more than a few days old delete and re-download.

Get it here: http://download.bleepingcomputer.com/sUBs/ComboFix.exe
Or here: http://subs.geekstogo.com/ComboFix.exe

Double click combofix.exe follow the prompts.

When finished, it will open a log.
Attach the log and a new HJT log in your next reply.

Note: Do not click combofix's window while its running. That may cause it to stall

Mike

Don't forget to Attach instead of pasting to the thread.
  #13  
Old 11-21-2008
Newcomer, in training
 
Location: Seattle
Member since: Nov 2008, 18 posts
Quote:
Originally Posted by mflynn View Post

Copy and paste the Report.txt file to your next post.

Mike
I'm going to run Combofix right now. Thanks for your help
-Katie
  #14  
Old 11-21-2008
TechSpot Guru
 
Location: Lexington NC USA Eastern Time
Member since: Nov 2008, 2,788 posts
System specs
You are right sorry I must be tired!

Thanks
Mike
  #15  
Old 11-21-2008
Newcomer, in training
 
Location: Seattle
Member since: Nov 2008, 18 posts
Hehe I'm just trying to follow directions as clearly as possible :P

Log attached.
Attached Files
File Type: txt log.txt (21.4 KB, 2 views)
  #16  
Old 11-21-2008
TechSpot Guru
 
Location: Lexington NC USA Eastern Time
Member since: Nov 2008, 2,788 posts
System specs
And you are doing a fabulous job.

Run SAS it had much found and removed but we need to see it clean then MBAM should finish all the rest.

If they are clear then no need to post them but do get me a final HJT log.

I hope we are close to finished I think so!

Mike
  #17  
Old 11-22-2008
Newcomer, in training
 
Location: Seattle
Member since: Nov 2008, 18 posts
sas log is attached, it had some stuff on it. I'm running mbam now.
Attached Files
File Type: log SUPERAntiSpyware Scan Log - 11-21-2008 - 19-57-28.log (841 Bytes, 2 views)
  #18  
Old 11-22-2008
TechSpot Guru
 
Location: Lexington NC USA Eastern Time
Member since: Nov 2008, 2,788 posts
System specs
OK Kipper

We found one that needs special handling.


Drag mouse copy each line one at a time
Code:
%System%\drivers\winsys.sys
%System%\wincom.exe
Then

Open MBAM click and update it (new update today)

Then More Tools-Run Tool

In the File name: paste it click ok chose delete on boot an the paste the second line same way.

Reboot to remove file run SAS again to confirm it gone!

Mike

Last edited by mflynn; 11-22-2008 at 12:54 AM..
  #19  
Old 11-22-2008
Newcomer, in training
 
Location: Seattle
Member since: Nov 2008, 18 posts
I can't get the first line to work, it gives an error that says
%System%\drivers\winsys.sys
Path Does not exist
Please verify the correct path was given.

Thanks
  #20  
Old 11-22-2008
TechSpot Guru
 
Location: Lexington NC USA Eastern Time
Member since: Nov 2008, 2,788 posts
System specs
That just means the file is not there that is good.

What about the 2nd?

Mike
Closed Thread
Page 1 of 2 1 2

Tip: Download Advanced SystemCare 3 Freeware - 1 Click A Day to Clean, Repair, Protect & Optimize your PC.

Thread Tools


Similar Topics
Topic Category Replies Last Post
Win32.dl.agent.vei / Trojan Virus & Malware removal 1 12-03-2007 12:12 PM
Trojan.Win32.Agent.bxj Virus & Malware removal 19 10-28-2007 01:13 PM
Trojan-Downloader.Win32.Agent Virus & Malware removal 16 09-11-2007 11:19 AM
Trojan-Downloader.Win32.agent Virus & Malware removal 7 03-29-2007 04:04 PM
Trojan-Downloader.Win32.Agent Virus & Malware removal 2 03-08-2007 01:47 AM


All times are GMT -4. The time now is 03:49 PM.