Subscribe to How-To Geek

Welcome to the How-To Geek Forums

We encourage you to register on our forums and post any questions you might have. The How-To Geeks monitor this forum and will respond to your question quickly.

How-To Geek Forums » Windows XP

(Solved) - i cant get rid of a trojan.agent

(29 posts)
  • Started 1 month ago by sloth
  • Latest reply from sloth
  • Topic Viewed 573 times

  • Remove Solved Status

sloth
Posts: 11

i downloaded a anti virus software called malwarebytes and i did a full scan about 8 times and it comes up with the same trojan.agent virus everytime. it says it removes it successfully but everytime i run another scan it continues to show up.

any help is appreciated.

Posted 1 month ago #
Top
 
LH
LH
Posts: 7492

Try scanning with MBAM, with the computer in Safe Mode.
Also make sure you update MBAM, and always run the deep scan

Please post the name of the virus here.

Posted 1 month ago #
Top
 
mfletch
mfletch
Posts: 185

Plus can you tell us the location of the Trojan/Virus

Posted 1 month ago #
Top
 
keithd
Posts: 2

MBAM is specific to malware, spyware and those lightweights. You need a good Antivirus solution such as McAfee or better. You could get a little more technical and download sysinternals tools and and there is one which you can run that will show you all the dlls associated with that trojan. You can write them down, reboot in safe mode and delete them. Then search the registry for the mention of them and delete them. Can you actually look and see the executable in windows explorer? If not, go into safe mode and open a dos prompt, and change directories to the location and then type dir to see if it shows up.

Posted 1 month ago #
Top
 
sloth
Posts: 11

here is the log from the last scan of malwarebytes.

Malwarebytes' Anti-Malware 1.41
Database version: 3015
Windows 5.1.2600 Service Pack 2

10/23/2009 8:12:37 PM
mbam-log-2009-10-23 (20-12-37).txt

Scan type: Full Scan (C:\|D:\|E:\|)
Objects scanned: 159167
Time elapsed: 19 minute(s), 58 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\xml10 (Trojan.Agent) -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

also, i got this from the quarantine list with the program:
RUNDLL32.exe C:\window\system32\xml_incdll,i

im assuming thats the location of it. so is it just easy enough to boot up in safe mode and go into that file and delete it?

i also have run my anitvirus program (mcafee) a couple of times and it cant even detect the Trojan at all.

Posted 1 month ago #
Top
 
mickeyblue
mickeyblue
Posts: 405

does this RunnDLL error prompt when you start your PC?
do you have a program called autoruns? well if not then download it, something similar happened to me, its probably a left over from a deleted virus, run autoruns and see if its in the start up tab, if it is then turn it off, then save, restart and see if the system runs normally for a few hours without this, if so then go back into autoruns and delete the entry.

Posted 1 month ago #
Top
 
sloth
Posts: 11

my computer doesnt run slow and i dont get any pop ups or error messages. i just ran this malware program to make sure everything was clear and this was the only thing i cant get rid of. other than it not being able to delete the infection everything is normal.

do you have a link for this autorun thing, and what exaclty does it do?

Posted 1 month ago #
Top
 
mickeyblue
mickeyblue
Posts: 405

autoruns is a program that shows you exactly whats running on your PC on startup and idle and everything else. very useful actually. no need to install it works right from the .exe

you can download it from here its a very small app only 581kb

Posted 1 month ago #
Top
 
sloth
Posts: 11

im still unsure why autoruns would help me in this situation as i am not getting any error messages when i boot or at all.

i have located the file on my C: drive, but i am afraid to just try to delete it because i know there are sensitive files in the system32 folder.

when i highlight this file that i suspect is the infection it says that the company is "inte". and every other file that i highlight in the system32 folder's company name is "microsoft coporation"

Posted 1 month ago #
Top
 
LH
LH
Posts: 7492

Definitely use Autoruns to look for anything unusual. In fact it's a good idea to do it on a regular basis.
What is the exact name of the file you suspect is the infection ?
(some 3rd party programs do put things in the system32 folder too)

Posted 1 month ago #
Top
 
sloth
Posts: 11

RUNDLL32.exe C:\window\system32\xml_incdll,i

this is what i suspect as the location of the infected file.

i can find the xml_incdll file in my systyem32 folder, but i just feel like right click>delete would not do the trick.

Posted 1 month ago #
Top
 
LH
LH
Posts: 7492

It does look suspicious, and a new one. I should send a bug report to MBAM.
Copy the file to a cd, take out the cd out. Delete it in system32. Reboot. Keep an eye open for it appearing again. (might not appear for a few days)

Posted 1 month ago #
Top
 
ruthackermann
Posts: 5

you can go to the process library and look these up, if they don;t have the information they will find it for you, go to the home page type in the the search bar,I have rundill32.exe running also in small letters the process library is looking them up for me,
here is the link, free to use.. http://www.processlibrary.com/

Posted 4 weeks ago #
Top
 
sloth
Posts: 11

i ran a registry scan and it came up with a bunch of errors, but it wont get rid of all of them without me buying something which im not. the actually file in the system32 folder that i am talking about is xml_inc.dll

i put that into that process library and it didnt come up with anything.

i am looking into the cd idea but i dont have a blank one at the moment. so i copy the xml_inc.dll file onto a cd. then take the cd out and delete the file from the system32 folder?

Posted 4 weeks ago #
Top
 
LH
LH
Posts: 7492

Don't pay for anything like that. I hope you didn't run a scan with something that actually infects you. Please tell us what you used.
And yes. Do the CD and delete thing I mentioned earlier.

Posted 4 weeks ago #
Top
 
sloth
Posts: 11

i got a cd and copied the file over. when i tried to delete the file it would not let me and gave me an error message, something about the file may be in use or something. i can get the exact error if i need to. would booting up in safe mode allow me to delete the file?

Posted 4 weeks ago #
Top
 
podie
Posts: 14

Mcafee site adviser does not give autorun a good report.

Posted 4 weeks ago #
Top
 
Odeho19
Odeho19
Posts: 258

I agree with podie. Go to the 9th item down on this link to Major Geeks, where I just got help to get rid of a VERY bad virus infection on my machine from them. You'll see that on that page they want you to disable AutoRuns. This article was written by the Co-owner of the site, and he personally helps alot of people rid their machines of Viruses, and the like. The article is about how NOT to get Malware in the 1st place. It's pretty helpful.

Here
is a link to show how they helped me get rid of the bug that was in my machine.

Good Luck......

Posted 4 weeks ago #
Top
 
BobJam
BobJam
Posts: 878

If you think you have malware, you should run a HijackThis log and post it on one of the forums I've listed below.

To download HijackThis go to the following link:
http://free.antivirus.com/hijackthis/

1. Click on the "Installer" link next to the icon of the guy with the spyglass.

2. Save HJTInstall.exe to your desktop.

3. Doubleclick on the HJTInstall.exe icon on your desktop. You may get the "open file - security warning" window asking you if you want to run the file. If so, just click "Run".

4. Click "Install". By default it will install HJT to C:\Program Files\Trend Micro\HijackThis and create a HJT icon on your desktop and launch HJT.

5. Click on the "Do a system scan and save a log file" button. It will scan and then save the log to Notepad.

6. Close HJT by clicking on the "X".

7. At the top of the Notepad HJT log screen, hit Edit then Select All then click Edit and then click Copy (doing that copies the text to the clipboard, you won't see it yet....)

8. Go to any of the the Malware Removal forums listed below and Paste the log in a new thread. (To paste - if you use IE as your browser - just click on the "Edit" menu selection, and then "Paste" in the drop down menu)

DO NOT have HijackThis fix anything yet. Most of what it finds will be harmless or even required. WAIT until a security expert AT ONE OF THE SITES LISTED BELOW looks at your log and interprets it and posts a reply.

Aumha forum: http://forum.aumha.org/viewfor.....7782f68c4c

Bleeping Computer: http://www.bleepingcomputer.co.....rum22.html

Geeks to Go: http://www.geekstogo.com/forum.....l-f37.html

Major Geeks: http://forums.majorgeeks.com/forumdisplay.php?f=35

Malware removal: http://malwareremoval.com/foru.....66edf36e99

Spyware Info: http://www.spywareinfoforum.co.....owforum=18

Tech Support Guy: http://forums.techguy.org/54-m.....this-logs/

What the Tech (formerly Tom Coyote forum): http://forums.whatthetech.com/.....l_f27.html

Be sure to read all the sticky announcements/instructions at the top of each malware forum!

You will probably have to register to post.

(BTW, the reason I've listed so many malware removal forums is so that you can post your HJT long on each one . . . some respond faster than others, so if you post on each one you are likely to get an answer within 24 hours from one of them . . . sort of like a shotgun approach.)

Posted 4 weeks ago #
Top
 
Odeho19
Odeho19
Posts: 258

Great post Bobjam, I would add at the end though, about the part about posting to several sites, re: your HJT log. Once you've started getting help from one of these helpers, STICK WITH THAT ONE! If you start mixing help from one site to the next, a) you might screw something up horribly bad, and b) some of these guys are VERY proprietary about helping people, (which they attribute to reason "a"). So just a heads up. Don't mix and match advice once you've decided on one of these helpers........

Posted 4 weeks ago #
Top
 

RSS feed for this topic

Reply »

You must log in to post.

Our Friends
Getting Started


About How-To Geek
What Is That Process?
svchost.exe
jusched.exe
dwm.exe
ctfmon.exe
wmpnetwk.exe
mDNSResponder.exe
wmpnscfg.exe
rundll32.exe
wfcrun32.exe
Ipoint.exe
Itype.exe
Wfica32.exe
Mobsync.exe
conhost.exe
Dpupdchk.exe Adobe_Updater.exe

Copyright © 2006-2009 HowToGeek.com. All Rights Reserved.