also @ TechSpot: Windows logo to get a Metro makeover in Windows 8
Welcome to the TechSpot OpenBoards. Please read the FAQ if you have any questions. Sign up or Login to participate.

Go Back   TechSpot OpenBoards > Tech Support > Windows BSOD, Freezing, Restarting Help

Collaborate in the cloud with Office, Exchange, SharePoint, and Lync

Torjan.Agent

Thread Tools Search this Thread
  #1  
Old 04-03-2009
Newcomer, in training
 
Member since: Aug 2007, 21 posts
Torjan.Agent

Need Help with a client workstation. I keep catching a trojan.agent with malwarebytes and when rebooting and i scan again it comes up with trojan.agent again. Here are my logs for malwarebytes and hijack.
I have ran mcafee corporate editon;cc cleaner;malwarebytes; and super anti spyware. I am stil getting pop ups while browsing with firefox...

Thanks,
Attached Files
File Type: log hijackthis.log (7.5 KB, 4 views)
File Type: txt mbam-log-2009-04-03 (14-23-13).txt (949 Bytes, 5 views)
  #2  
Old 04-03-2009
B00kWyrm's Avatar
TechSpot Paladin
 
Location: Maryland
Member since: Mar 2009, 1,452 posts
trojan.agent removal

I offered poor suggestons the first time...
I should have simply referred jmolina to the Virus and Malware removal board,
especially the initial notes by Julio!

Last edited by B00kWyrm; 04-03-2009 at 11:32 PM.. Reason: Retraction
  #3  
Old 04-03-2009
Newcomer, in training
 
Member since: Aug 2007, 21 posts
ok, Thanks I will try this out..

I deleted the files mentioned;I had already tried this but it keeps recreating a different dll and the scan will still come up with Trojan. agent on malwarebytes>>>
Attached Files
File Type: log hijackthis2.log (7.6 KB, 1 views)
File Type: txt mbam-log-2009-04-03 (17-12-43).txt (949 Bytes, 0 views)

Last edited by kimsland; 04-03-2009 at 11:27 PM.. Reason: merged recent posts
  #4  
Old 04-03-2009
Bobbye's Avatar
Helper on the Fringe
 
Location: Florida
Member since: Mar 2007, 15,050 posts
B00kWyrm, please refer to this: http://www.techspot.com/vb/topic120350.html

jmolina, please refrain from doing any Registry Edits.

If you followed the steps set up here: http://www.techspot.com/vb/topic58138.html
You will see that you are missing the SuperAntispyware log. But we'll go with what we have for now:

Remove bad HijackThis entries
• Run HijackThis
• Click on the System Scan Only button
• Put a check beside all of the items listed below (if present):
Quote:
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ihub/
O4 - HKLM\..\Run: [Szagari] rundll32.exe "C:\WINDOWS\ucaxodem.dll",e
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\WINDOWS\System32\shdocvw.dll
They will need to verify if this is a company or work Domain: If it is leave the entries. If it is not, check for HijackThis to remove:
Quote:
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = chi.crainit.com
O17 - HKLM\Software\..\Telephony: DomainName = chi.crainit.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = chi.crainit.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = crain.com
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = crain.com
• Close all open windows and browsers/email, etc...
• Click on the "Fix Checked" button
• When completed, close the application.


Uninstall, then reinstall Spybot Search & Destroy. Be sure Teatimer is disabled for now

Download and Install SDFix from HERE and save to your desktop.
* Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)

Boot into Safe Mode
* Restart your computer and start pressing the F8 key on your keyboard.
* Select the Safe Mode option when the Windows Advanced Options menu appears, and then press ENTER.

Run SDFix
Quote:
* Open the extracted SDFix folder and double click RunThis.bat to start the script.
* Type Y to begin the cleanup process.
* It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.

* Press any Key and it will restart the PC.
* When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
* Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
* Attach Report.txt back here
Please update and run Superantispyware after SDFix and follow that with a new HijackThis scan. Attach all logs and report.
  #5  
Old 04-03-2009
B00kWyrm's Avatar
TechSpot Paladin
 
Location: Maryland
Member since: Mar 2009, 1,452 posts
What Bobbye said...

It might be good for someone to delete my previous post.
That way it won't be an issue later for someone else stumbling across this thread.
If someone knows how to see that that happens...

1. Registry edits should not be attempted by the casual or novice user,
and should never be advised without adequate caveats...
no matter how certain I may have been that that edit would have done no harm.

2. The eight steps are certainly "Best Practice" strategy for dealing with an infection.

3. The Virus & Malware removal board rules should have governed my reply,
because that is exactly the topic of the question... even if not on that board.

My bad, on at least three counts.

So, jmolina, my sincere apologies, and I hope I did you no harm.
  #6  
Old 04-06-2009
Newcomer, in training
 
Member since: Aug 2007, 21 posts
Torajan.Agent

Still getting the Trojan.Agent with malwareBytes after runnig 8step and the recommended scan here are all my logs.
Attached Files
File Type: txt mbam-log-2009-04-06 (10-12-07).txt (976 Bytes, 1 views)
File Type: txt ReportSDfixlog.txt (3.2 KB, 0 views)
File Type: log SUPERAntiSpyware Scan Log - 04-03-2009 - 19-20-11.log (465 Bytes, 0 views)
File Type: log hijackthis3.log (7.5 KB, 0 views)
Closed Thread

Similar Topics
Topic Replies Forum
Help with annoying Trojan.Agent---Rootkit.Agent...etc 23 Virus and Malware Removal
JS downloader agent. How to get rid of it. 1 Virus and Malware Removal
Trojan.Agent.blc 21 Virus and Malware Removal
UD Agent 2 General Discussion
Help! How to remove Torjan Horse Generic2.KT? 8 Virus and Malware Removal

Thread Tools Search this Thread
Search this Thread:

Advanced Search
All times are GMT -4. The time now is 08:06 PM.