This is a read-only archive of malwareremoval.com. No new posts or registrations. Privacy Page
Malware Removal Forums

Trojan.Agent

55 min read

This thread's last reply is from August 4, 2012, 1:13 AM UTC. Software, malware, and removal-tool advice below may be out of date — treat specific steps and download links with caution.

I did it and MBAM still found a trojan:

Trojan.Agent
Registry value
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run|61703

MBAM log:Malwarebytes Anti-Malware 1.62.0.1300
www.malwarebytes.org

Database version: v2012.07.29.09

Windows Vista Service Pack 2 x64 NTFS
Internet Explorer 9.0.8112.16421
Foung-Yang Family :: FOUNG-YANG-PC [administrator]

Protection: Enabled

30/07/2012 7:35:42 PM
mbam-log-2012-07-30 (19-35-42).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 190498
Time elapsed: 2 minute(s), 36 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run|61703 (Trojan.Agent) -> Data: C:\PROGRA~3\LOCALS~1\Temp\mstvfixe.cmd -> Delete on reboot.

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

(end)
marlene,
I think that's just a leftover registry entry. Let's see.
---------------------------------------------
Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1 (64-bit)
Download Mirror #2 (64-bit)


  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:

    :reg
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run /sub

    :filefind
    mstvfixe.cmd
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.

Note: The results log can also be found on your Desktop, entitled SystemLook.txt

askey127
SystemLook 30.07.11 by jpshortstuff
Log created at 19:49 on 31/07/2012 by Foung-Yang Family
Administrator - Elevation successful

========== reg ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
"61703"="C:\PROGRA~3\LOCALS~1\Temp\mstvfixe.cmd"


========== filefind ==========

Searching for "mstvfixe.cmd"
No files found.

-= EOF =-
marlene,
That is just an "orphaned" registry entry. The file it's trying to run doesn't exist any more.
Let's get rid of it so MBAM won't detect it .
----------------------------------------------
Perform a Custom Fix with OTL
Run OTL (Right click and choose "Run as administrator" in Vista/Win7)
  • In the Custom Scans/Fixes box at the bottom, paste in the following lines from the Code box (Do not include the word "Code"):

    :Commands
    [CREATERESTOREPOINT]

    :Reg
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
    "61703"=-

    :Commands
    [EMPTYTEMP]
  • Then click the Run Fix button at the top.
  • Let the program run unhindered and reboot the PC when it is done.
  • Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.


askey127
All processes killed
========== COMMANDS ==========
Restore point Set: OTL Restore Point
========== REGISTRY ==========
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\\61703 deleted successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Foung-Yang Family
->Temp folder emptied: 2154259 bytes
->Temporary Internet Files folder emptied: 344509975 bytes
->Java cache emptied: 0 bytes
->Apple Safari cache emptied: 0 bytes
->Opera cache emptied: 0 bytes
->Flash cache emptied: 2475 bytes

User: Public

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 6430399 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 842433337 bytes

Total Files Cleaned = 1,140.00 mb


OTL by OldTimer - Version 3.2.55.0 log created on 08012012_211002

Files\Folders moved on Reboot...
C:\Users\Foung-Yang Family\AppData\Local\Temp\VGX698B.tmp moved successfully.

PendingFileRenameOperations files...
File C:\Users\Foung-Yang Family\AppData\Local\Temp\VGX698B.tmp not found!

Registry entries deleted on Reboot...
marlene,
Looks like we got it this time.
Let me know if MBAM finds anything. (It could possibly find something in the C:_OTL\ folder but that's a harmless quarantine location).

Should be clean now.

askey127
Thank you for your help and for your time:)