Content Top
DAL Computer Help » Internet Security Help » Spyware, Adware, Viruses and HijackThis Logs » Trojan.Agent.BI & Trojan.Downloaders.Agent.BQ Etc.

Recommended Fix

Click here to fix Windows Errors and Optimize Windows Performance

Need Computer Help?
Register Now for FREE

Trojan.Agent.BI & Trojan.Downloaders.Agent.BQ Etc.

Reply
Thread Tools
Spyware, Adware, Viruses and HijackThis Logs
  #1 (permalink)  
Old 24-11-2005, 10:30 AM
Newbie
D-A-L Newbie
 
Join Date: Nov 2005
Posts: 5
ThaArtist Is a beginner here at D-A-L
Trojan.Agent.BI & Trojan.Downloaders.Agent.BQ Etc.

Hey everyone. I'm new here, my names Joe...

Well I've taken on the task of fixing a relatives old gateway computer... Of course, they didn't use a firewall or anti-virus, anti-spyware... They had their friend reformat the hard drive and then just started browsing the net!!! So here I am... I already fixed alot of there stuff but I got these two nasty ones that keep poppin up. I have updated their windows XP Home with SP1 & SP2 along with all the other updates... I've ran anti-virus and anti-spyware and nothing seems to get rid of these...

Programs in use (now) are:

Microsoft Anti-Spyware (latest version with latest updates)
Bit Defender Professional Plus 9 (with latest updates)
CCleaner (newest version)

Heres the HiJackThis log..

Logfile of HijackThis v1.99.1
Scan saved at 5:24:34 AM, on 11/23/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\GWMDMMSG.exe
C:\WINDOWS\system32\d3rw.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\PROGRA~1\Softwin\BITDEF~1\bdmcon.exe
C:\WINDOWS\atlcd32.exe
C:\PROGRA~1\Softwin\BITDEF~1\bdnagent.exe
C:\PROGRA~1\Softwin\BITDEF~1\bdswitch.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_A10IC 2.EXE
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe
C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe
C:\Program Files\Common Files\Softwin\BitDefender Update Service\livesrv.exe
C:\Program Files\Softwin\BitDefender9\vsserv.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\admin\Desktop\HijackThis.exe
C:\WINDOWS\SoftwareDistribution\Download\S-1-5-18\837ee431df87226c3788bde39d0fd5c6\update\update. exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\ucgyj.dll/sp.html#69589
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\ucgyj.dll/sp.html#69589
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\ucgyj.dll/sp.html#69589
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\ucgyj.dll/sp.html#69589
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\ucgyj.dll/sp.html#69589
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\ucgyj.dll/sp.html#69589
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyServer = proxy.milwaukee.k12.wi.us:8080
R3 - Default URLSearchHook is missing
O2 - BHO: Class - {196066D6-4FB2-A00C-7E08-A151674E1789} - C:\WINDOWS\system32\addmm32.dll (file missing)
O2 - BHO: Class - {2CDE1514-2193-6763-C430-05413232D3E7} - C:\WINDOWS\system32\mspi32.dll
O2 - BHO: Class - {9B7B8469-5DD6-2CC3-6510-338DE167588F} - C:\WINDOWS\appud32.dll
O2 - BHO: Class - {B11BCDC9-1DD6-8BB6-933F-3824A67B8492} - C:\WINDOWS\apphk32.dll (file missing)
O2 - BHO: Class - {C47F26FB-2717-FEB3-9E41-FD54EB783896} - C:\WINDOWS\netld.dll
O2 - BHO: Class - {EB56A74D-84CE-7822-6816-C95DF458D0FD} - C:\WINDOWS\mfcsa32.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [GWMDMMSG] GWMDMMSG.exe
O4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKLM\..\Run: [d3rw.exe] C:\WINDOWS\system32\d3rw.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [BDMCon] C:\PROGRA~1\Softwin\BITDEF~1\bdmcon.exe
O4 - HKLM\..\Run: [BDNewsAgent] "C:\PROGRA~1\Softwin\BITDEF~1\bdnagent.exe"
O4 - HKLM\..\Run: [BDSwitchAgent] "C:\PROGRA~1\Softwin\BITDEF~1\bdswitch.exe"
O4 - HKCU\..\Run: [EPSON Stylus C40 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_A10IC 2.EXE /P23 "EPSON Stylus C40 Series" /O6 "USB001" /M"

Stylus C40"
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .mid: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin2.dll
O12 - Plugin for .mpeg: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin3.dll
O12 - Plugin for .mpg: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin3.dll
O12 - Plugin for .wav: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?Link...04&clcid=0x409
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -

http://update.microsoft.com/windowsu...?1120169495217
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = milwaukee.12.wi.us
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = milwaukee.12.wi.us
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: SearchList = milwaukee.12.wi.us
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = milwaukee.12.wi.us
O23 - Service: Remote Procedure Call (RPC) Helper ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\atlcd32.exe" /s (file missing)
O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe" /service (file missing)
O23 - Service: BitDefender Desktop Update Service (LIVESRV) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Update Service\livesrv.exe" /service

(file missing)
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: PictureTaker - LANovation - C:\WINDOWS\System32\PCTKRNT.SYS
O23 - Service: BitDefender Virus Shield (VSSERV) - Unknown owner - C:\Program Files\Softwin\BitDefender9\vsserv.exe" /service (file missing)
O23 - Service: BitDefender Communicator (XCOMM) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe" /service (file

missing)
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #2 (permalink)  
Old 24-11-2005, 03:37 PM
VopThis's Avatar
Senior Member (Canada)
 
Join Date: Nov 2005
Posts: 3,439
VopThis is a D-A-L Rockstar!VopThis is a D-A-L Rockstar!VopThis is a D-A-L Rockstar!VopThis is a D-A-L Rockstar!VopThis is a D-A-L Rockstar!VopThis is a D-A-L Rockstar!VopThis is a D-A-L Rockstar!VopThis is a D-A-L Rockstar!VopThis is a D-A-L Rockstar!VopThis is a D-A-L Rockstar!VopThis is a D-A-L Rockstar!
Re: Trojan.Agent.BI & Trojan.Downloaders.Agent.BQ Etc.

Dedicated HIJACKTHIS FOLDER NEEDED: – very important
You need to set up a dedicated HijackThis folder to ensure that available recovery features of the tool are possible should they be needed. Create a folder HJT such as C:\HJT or C:\Program Files\HJT. Copy or drag-and-drop the HijackThis program to the newly created folder. Then make or alter the shortcut to the HJT program.




You have a nasty About:Blank infection. Fixing this requires several cleanup tools to be downloaded for later use.

Download the following tools:




Download the latest version of CWSHredder to your desktop from here:
http://cwshredder.net/bin/CWShredder.exe

We will use this application a little later on in the process.
Initially, run it ONLY to check for updates.



Download About:Buster from one of these links:

http://majorgeeks.com/download4289.html

Unzip it to your desktop.
Initially, run AboutBuster 5.0 and press ‘Update’ to make sure you have the latest reference file version.
Do not run the actual scan/fix until instructed below.


You will run About:Buster while you are in Safe Mode.
It will create a log in addition to cleaning your system. Post that log into your next reply in this thread.



DISCONNECT FROM THE INTERNET
During the fix do NOT connect to the Internet (turn your modem off or disconnect your internet connection wire).
Unless you can memorize these instructions, it would be a good idea to print them out or save these instructions to a file on your desktop (NOTEPAD).




SELECT HijackThis FIX ITEMS: Scan with HijackThis and place a check next to these items:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\ucgyj.dll/sp.html#69589
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\ucgyj.dll/sp.html#69589
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\ucgyj.dll/sp.html#69589
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\ucgyj.dll/sp.html#69589
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\ucgyj.dll/sp.html#69589
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\ucgyj.dll/sp.html#69589
R3 - Default URLSearchHook is missing

O2 - BHO: Class - {196066D6-4FB2-A00C-7E08-A151674E1789} - C:\WINDOWS\system32\addmm32.dll (file missing)
O2 - BHO: Class - {2CDE1514-2193-6763-C430-05413232D3E7} - C:\WINDOWS\system32\mspi32.dll
O2 - BHO: Class - {9B7B8469-5DD6-2CC3-6510-338DE167588F} - C:\WINDOWS\appud32.dll
O2 - BHO: Class - {B11BCDC9-1DD6-8BB6-933F-3824A67B8492} - C:\WINDOWS\apphk32.dll (file missing)
O2 - BHO: Class - {C47F26FB-2717-FEB3-9E41-FD54EB783896} - C:\WINDOWS\netld.dll
O2 - BHO: Class - {EB56A74D-84CE-7822-6816-C95DF458D0FD} - C:\WINDOWS\mfcsa32.dll


Make sure that all browser windows and internet links are closed, even this one!
CLICK ’FIX CHECKED’ with HijackThis.



HIDDEN FILES: To make sure you can see all hidden files, please follow the directions here

SAFEMODE: Boot into safe mode by tapping the F8 key at restart and choosing 'safe mode' menu option (explained here if needed).




Now, run AboutBuster and select ’Begin Removal’. Continue running the scan until it shows clean.

Post a copy of the scan results, which will appear in the AboutBuster folder.



Next, run CWShredder
-Click on the: ‘Fix’ button
-Follow the prompts, and press OK


Go to Start > Run and type: CLEANMGR.EXE and hit enter.
When prompted select the C: drive and click ok.
Check the boxes for:
Temporary Internet Files
Downloaded Program Files
Recycle Bin
Temporary Files
Click OK or Enter


Check that none of the DLL files still exist on your PC from HJT items removed.

POST A REVISED HIJACKTHIS LOG for review:
Reboot and post a new HijackThis log with any feedback as appropriate - how things are now behaving: any new or remaining apparent issues.
__________________
Vincent P

MALWARE: READ FIRST Procedures:
|_ SpyBot V1.5 _|_ HijackThis LOG __V2.0.2 _|


__
ASAP: promoting a high standard and quality of security support no matter where you seek help.

Quote:
SAFER SURFING TOOLS (IE/FF **FREE** browser addons):
Linkscanner + WOT (Web of Trust) + SiteAdvisor (suggest at least two but not necessarily all)
Quote:
Tell me and I forget; show me and I remember; involve me and I understand.
There are no foolish questions, the only thing foolish is not asking if you're unsure of something.
Never ASSUME any detail because it can make an ASS out of U and ME... (ASS/U/ME ).
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #3 (permalink)  
Old 25-11-2005, 07:59 AM
Newbie
D-A-L Newbie
 
Join Date: Nov 2005
Posts: 5
ThaArtist Is a beginner here at D-A-L
Re: Trojan.Agent.BI & Trojan.Downloaders.Agent.BQ Etc.

Hey, Thanks for your help...

Well I followed your directions exactly... Once I restarted windows I still got some anti-virus alerts... I only stuck around to see 2 errors but there might have been more... Usually there are tons of files effected from GenPack:Trojan.Agent.BI

Anyway... the ones I recieved were:

Files infected:
C:\windows\crnh.exe
C:\windows\system32\syskr.exe

Infected with:
GenPack:Trojan.Agent.BI

Anyway... the computer I'm working on only has 128mb of SD Ram with a Pent 4 2.5ghz ... So needless to say its very slow just because it has barely any ram and the spyware, viruses, etc. So I'm thinking I will just stick in their windows disk and reinstall windows and reformat the hard drive....

Otherwise I'd have to keep burning discs back and forth to transfer log files from hijack this. Not to mention unplugging the keyboard, mouse, and monitor from this pc and into that one, and back and forth... (which is hard the way this pc is setup) Oh and hijack this didnt show any of the things that you had me delete when i ran it again... I don't have the new log file tho, sorry. (i know thats not much help)

IE won't even run on that computer when I have my cable modem hooked up to it... (although i didnt try after removal instructions)

So reinstalling windows will do the trick right? That way i dont even have to mess wit all this stuff... I already spent like 10 hours on this pc just trying to install updates, etc. ITS THAT SLOW!!!

Let me know your thoughts please.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #4 (permalink)  
Old 25-11-2005, 03:54 PM
VopThis's Avatar
Senior Member (Canada)
 
Join Date: Nov 2005
Posts: 3,439
VopThis is a D-A-L Rockstar!VopThis is a D-A-L Rockstar!VopThis is a D-A-L Rockstar!VopThis is a D-A-L Rockstar!VopThis is a D-A-L Rockstar!VopThis is a D-A-L Rockstar!VopThis is a D-A-L Rockstar!VopThis is a D-A-L Rockstar!VopThis is a D-A-L Rockstar!VopThis is a D-A-L Rockstar!VopThis is a D-A-L Rockstar!
Re: Trojan.Agent.BI & Trojan.Downloaders.Agent.BQ Etc.

Quote:
So reinstalling windows will do the trick right? That way i dont even have to mess wit all this stuff... I already spent like 10 hours on this pc just trying to install updates, etc. ITS THAT SLOW!!!
You definitely need more memory just to ensure that such a PC has a fighting chance (critical updates and download tools) to get and stay healthy.

I wouldn't want to be the one reinstalling that one with less than 256MB (preferably 512MB) of RAM. Those circumstances will continue to make your association with that PC most frustrating and generally unproductive.
__________________
Vincent P

MALWARE: READ FIRST Procedures:
|_ SpyBot V1.5 _|_ HijackThis LOG __V2.0.2 _|


__
ASAP: promoting a high standard and quality of security support no matter where you seek help.

Quote:
SAFER SURFING TOOLS (IE/FF **FREE** browser addons):
Linkscanner + WOT (Web of Trust) + SiteAdvisor (suggest at least two but not necessarily all)
Quote:
Tell me and I forget; show me and I remember; involve me and I understand.
There are no foolish questions, the only thing foolish is not asking if you're unsure of something.
Never ASSUME any detail because it can make an ASS out of U and ME... (ASS/U/ME ).
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #5 (permalink)  
Old 26-11-2005, 03:53 AM
Newbie
D-A-L Newbie
 
Join Date: Nov 2005
Posts: 5
ThaArtist Is a beginner here at D-A-L
Re: Trojan.Agent.BI & Trojan.Downloaders.Agent.BQ Etc.

Yeah, I'm not gonna do anything until I get more ram for it.

I'm checked gateway and their computer can hold 3 512mb sticks so I'm gonna have her upgrade to 2 512 sticks and keep one of the lousy 64mb sticks she has... So as soon as them get here the computer should be alot faster....

Thanks again... I'm sorry if I wasted your time VopThis... You were very helpful... I just don't have the energy to play around with this computer. I've already spent like 10 hours on it and I'm not sure if shes even gonna give me any money for all this... grrr...

Thanks again.

Joe
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply


Thread Tools

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Trojan Horse Agent 2.GUF Dippa Spyware, Adware, Viruses and HijackThis Logs 1 18-05-2009 11:15 PM
trojan.agent.afi sukiemem Spyware, Adware, Viruses and HijackThis Logs 1 06-07-2007 01:22 PM
trojan.agent.afi sukiemem Windows XP Help 2 05-07-2007 11:59 AM
win32 ad-agent(adw) ian2494 Spyware, Adware, Viruses and HijackThis Logs 0 15-04-2005 09:06 PM
(3) Trojan downloaders - STUBBY.C, INTEXP.A, AGENT.AS (HiJackThis log) DAVIDEV Spyware, Adware, Viruses and HijackThis Logs 2 01-11-2004 09:43 PM


All times are GMT +1. The time now is 11:56 AM.

Bottom Corner