also @ TechSpot: Top PC Games for this Holiday Season and Beyond
Welcome to the TechSpot OpenBoards. Please read the FAQ if you have any questions. Login to participate.

Go Back   TechSpot OpenBoards > Operating Systems & Software > Virus & Malware removal

Trojan-Downloader.Win32.agent

Closed Thread
Bookmark Thread Tools
  #1  
Old 03-28-2007
Newcomer, in training
 
Member since: Mar 2007, 4 posts
Trojan-Downloader.Win32.agent

yup i have this trojan thing too, and yup i cant, well i can but its not advisable, play wow, which is what notified me of this issue

now im up to step 11 of preliminary removal, so far nothing has actually found anything

before i go onto 12 and 13 thought id leave here the results of rootkit, if it means anything

c:\WINDOWS\system32\dmast.exe - Hidden File

c:\WINDOWS\system32\csnnx.exe - Hidden File

ill be back in a bit with all the info from steps 12 and 13

thanks for your time
  #2  
Old 03-28-2007
chamillitarysk8's Avatar
TechSpot Member
 
Member since: Jan 2007, 168 posts
go to lavasoft.com and download and run Win32_Pipeline_Remover
To remove this ad, sign in. To register for a new account, click here.
  
  #3  
Old 03-28-2007
Newcomer, in training
 
Member since: Mar 2007, 4 posts
ok ill try that

im back from steps 12 and 13, ill post al lthe info just incase

*edit* tool posted in above message found nothing?
Attached Files
File Type: txt Report-Scan-20070328-231541.txt (1.2 KB, 2 views)
File Type: log hijackthis.log (6.8 KB, 2 views)
File Type: txt VBG.TXT (1.4 KB, 1 views)

Last edited by dayz; 03-28-2007 at 07:28 PM..
  #4  
Old 03-29-2007
Banned
 
Member since: Aug 2004, 25,945 posts
[B]Hello and welcome to Techspot.[/B]

Your system has some very nasty infections.

Run AVG Antirootkit and have it fix these entries.

c:\WINDOWS\system32\dmast.exe - Hidden File

c:\WINDOWS\system32\csnnx.exe - Hidden File

Please download FixWareout from one of these sites:
[url]http://downloads.subratam.org/Fixwareout.exe[/url]
[url]http://www.bleepingcomputer.com/files/lonny/Fixwareout.exe[/url]

Save it to your desktop and run it. Click Next, then Install, make sure "Run fixit" is checked and click Finish.
The fix will begin; follow the prompts. You will be asked to reboot your computer; please do so. Your system may take longer than usual to load; this is normal.

Rename HJT as per the instructions [URL="http://www.techspot.com/vb/topic19133.html"]HERE[/URL].

Post a fresh HJT log as well as a Combofix log and the C:\fixwareout\report.txt .

Regards Howard

[color=red][b]This thread is for the use of[/color] dayz [color=red]only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our [URL="http://www.techspot.com/vb/menu28.html"]security and the web forum[/URL].[/color][/b]
  #5  
Old 03-29-2007
Newcomer, in training
 
Member since: Mar 2007, 4 posts
as per your intructions

your time is much appreciated
Attached Files
File Type: txt ComboFix.txt (29.1 KB, 1 views)
File Type: txt hijackthis2.txt (6.6 KB, 1 views)
File Type: txt report.txt (2.2 KB, 1 views)
  #6  
Old 03-29-2007
Banned
 
Member since: Aug 2004, 25,945 posts
Your didn`t attach an AVG Antispyware log as requested. Please do so in your next reply.

Run HJT with no other programmes open(except notepad). Click the scan button. Have HJT fix the following, by placing a tick in the little box next to(if there).

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O17 - HKLM\System\CCS\Services\Tcpip\..\{9CAAFCAC-B13B-48C9-87D4-D95B0AC2E968}: NameServer = 85.255.115.2,85.255.112.6

O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.115.2 85.255.112.6

O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.115.2 85.255.112.6

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.115.2 85.255.112.6

Click on the fix checked button.

Close HJT and reboot your system.

Post a fresh HJT log and an AVG Antispyware log.

Regards Howard

[color=red][b]This thread is for the use of[/color] dayz [color=red]only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our [URL="http://www.techspot.com/vb/menu28.html"]security and the web forum[/URL].[/color][/b]
  #7  
Old 03-29-2007
Newcomer, in training
 
Member since: Mar 2007, 4 posts
sorry about the AVG, must of forgot about it, followed above steps, result:
Attached Files
File Type: txt hijackthis3.txt (6.2 KB, 1 views)
File Type: txt Report-Scan-20070329-193632.txt (3.3 KB, 1 views)
  #8  
Old 03-29-2007
Banned
 
Member since: Aug 2004, 25,945 posts
Your HJT log is now clean.

Run the ccleaner programme as per the instructions in step9 of this thread [URL="http://www.techspot.com/vb/topic58138.html"]HERE[/URL].

[b]Turn off system restore.(XP/ME only)[/b] See how [URL="http://www.bleepingcomputer.com/forums/tutorial56.html"]HERE[/URL].

Now, turn system restore back on. This will have deleted all your old restore points and any nasties that are in them. It will also have created a new, clean restore point.

If you have any further virus/spyware problems, please post in this thread.

Regards Howard

[color=red][b]This thread is for the use of[/color] dayz [color=red]only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our [URL="http://www.techspot.com/vb/menu28.html"]security and the web forum[/URL].[/color][/b]
Closed Thread

Tip: Download Advanced SystemCare 3 Freeware - 1 Click A Day to Clean, Repair, Protect & Optimize your PC.

Thread Tools


Similar Topics
Topic Category Replies Last Post
Trojan-Downloader.Win32.Agent Virus & Malware removal 16 09-11-2007 11:19 AM
Trojan-Downloader.Win32.Agent Virus & Malware removal 2 03-08-2007 01:47 AM
my pc infected by downloader.agent.awf Virus & Malware removal 7 02-11-2007 03:49 PM
How to remove Trojan-Clicker.Win32.Agent.bu Virus & Malware removal 2 10-04-2005 09:18 PM
Trojan.Agent and Downloader.BI Virus & Malware removal 2 05-23-2005 12:45 PM


All times are GMT -4. The time now is 11:06 PM.