Trojan.Agent

FCUSA

New member
Local time
2:41 PM
Messages
19
Hi Everyone -

Cannot belive this! Just did a MBam quick scan and found a new item. Can anyone identify it?

I removed both items and the computer needed to reboot and now I am unsure how to retrieve the log for your review.

Thanks,
Sally
 

Attachments

  • MBAM123010.PNG
    MBAM123010.PNG
    42.4 KB · Views: 61
Last edited:

My Computer

Computer Manufacturer/Model Number
Toshiba Satellite L645D
OS
Windows 7 Home Premium 64bit
CPU
AMD Turion II P540 Dual-Core Processor 2.40 GHz
Memory
4GB RAM
Hi FCUSA,

Please go to these locations and get the latest log files, and upload them here.

C:\Users\<USERNAME>\AppData\Roaming\Malwarebytes\Malwarebytes' Anti-Malware\Logs
C:\ProgramData\Malwarebytes\Malwarebytes' Anti-Malware\Logs

Regards,
Golden
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Golden Mk. I.4
OS
Windows 10 Pro x64 ; Xubuntu x64
CPU
Intel i7 860 @ 2.80 GHz O/C'ed to 4.0GHz
Motherboard
Gigabyte P55A-UD3R Rev.1. Award BIOS F13
Memory
16GB Corsair Vengance DDR3 @ 661 MHz Dual Channel (9-9-9-24)
Graphics Card(s)
EVGA NVidia GTX 560 1024MB
Sound Card
Realtek Integrated
Monitor(s) Displays
Dual Samsung SyncMaster 2494HS
Screen Resolution
1920*1080 and 1920*1080
Hard Drives
1*Samsung 840 EVO 120GB SSD;
1*OCZ Vertex 2 60GB SSD;
2*Samsung F3 SpinPoint 1TB in RAID0;
1*Samsung F1 SpinPoint 1TB;
2*Western Digital 1TB External USB 3.0
1*Western Digital 500GB External USB 3.0
1*Seagate 500GB External USB 2.0
PSU
Thermaltake ToughPower QFan 750W
Case
Thermaltake Element S VK60001W2Z
Cooling
Corsair H60 Water Cooling, 2*230mm and 2*80mm case fans
Keyboard
Logitech G110
Mouse
Logitech MX518
Golden -

Thanks for that direction - I was looking at the file, but couldn't find it to upload
 

Attachments

My Computer

Computer Manufacturer/Model Number
Toshiba Satellite L645D
OS
Windows 7 Home Premium 64bit
CPU
AMD Turion II P540 Dual-Core Processor 2.40 GHz
Memory
4GB RAM
Hi,

OK. I've had a quick look. The second item PUM.HIJACK.STARTMENU could be either:

1. A consequence of the first item (the Trojan), or
2. A form of false positive (I say false positive because if you made changes to your Start menu, then MBAM sees this as a potential security issue).

At any rate, MBAM has cleaned up both items succesfully, so you don't have anything to worry about. For your own peace of mind, please use this site to perform an on-line scan of your PC Free ESET Online Antivirus Scanner

Do you use the paid version of MBAM? If so, have you got the protection module activated?

Regards,
Golden
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Golden Mk. I.4
OS
Windows 10 Pro x64 ; Xubuntu x64
CPU
Intel i7 860 @ 2.80 GHz O/C'ed to 4.0GHz
Motherboard
Gigabyte P55A-UD3R Rev.1. Award BIOS F13
Memory
16GB Corsair Vengance DDR3 @ 661 MHz Dual Channel (9-9-9-24)
Graphics Card(s)
EVGA NVidia GTX 560 1024MB
Sound Card
Realtek Integrated
Monitor(s) Displays
Dual Samsung SyncMaster 2494HS
Screen Resolution
1920*1080 and 1920*1080
Hard Drives
1*Samsung 840 EVO 120GB SSD;
1*OCZ Vertex 2 60GB SSD;
2*Samsung F3 SpinPoint 1TB in RAID0;
1*Samsung F1 SpinPoint 1TB;
2*Western Digital 1TB External USB 3.0
1*Western Digital 500GB External USB 3.0
1*Seagate 500GB External USB 2.0
PSU
Thermaltake ToughPower QFan 750W
Case
Thermaltake Element S VK60001W2Z
Cooling
Corsair H60 Water Cooling, 2*230mm and 2*80mm case fans
Keyboard
Logitech G110
Mouse
Logitech MX518
It won't hurt to run Mbam again just to make sure all is deleted. I would if it were mine. I'm paranoid though! LOL

From the log it appears it should be clean. Post new log if you run it again and want an extra set of eyes to take a look.

Goldens advice to use the ESET is a good idea also.;)

Mike
 

My Computer

Computer Manufacturer/Model Number
Hopalong/ Godzilla
OS
Windows7 Pro 64bit SP-1; Windows XP Pro 32bit
CPU
Intel Core i7-870 Lynnfield 2.93GHz LGA 1156 95W Quad-Core
Motherboard
ASUS P7P55D-E PRO
Memory
8GB@1400MHz Crucial Ballistix DDR3-1600 4x2GB
Graphics Card(s)
ASUS ENGTX460 DirectCU/2DI/1GD5 1GB 256-bit GDDR5
Sound Card
VIA Onboard
Monitor(s) Displays
Asus VS248H-P 24"; Samsung SyncMaster 941BW 19"ws
Screen Resolution
1920x1080; 1440x900
Hard Drives
Samsung 830 120GB SSD
Intel 320 120GB SSD
Western Digital Caviar Black WD7501AALS 750GB 7200 RPM SATA 3.0Gb/s
Western Digital Caviar Black WD6401AALS 640GB 7200 RPM SATA 3.0Gb/s
PSU
COOLER MASTER Silent Pro RS850-AMBAJ3-US 850W Modular
Case
COOLER MASTER HAF 932 RC-932-KKN5-GP Black
Cooling
Scythe "Mugen-2 Rev.B" (2 ScytheKaze-Jyuni PWM fans)
Keyboard
Logitech K-320
Mouse
Kensington
Antivirus
Avast Inernet Suite
Browser
IE 9 ; Chrome
Hello Golden -

I am currently not using the paid version - in fact until last week I did not even know what MBam was! Sadly my Vista was infected with backdoor.cycbot (I probably do not have that correct) - but very bad. The fine folks over at Vista have helped me nonstop with that; and so my business would not suffer, I purchased this alternate system. We did the first scan and came with the false positive, but when I came up with another problem just now - totally freaked.

Thank you so much for analyzing that and I will look into the on-line scan in the morning. Do you think it is necessary or preferred to do a full MBam scan?

Thank you so much for your quick assistance!

It won't hurt to run Mbam again just to make sure all is deleted. I would if it were mine. I'm paranoid though! LOL

From the log it appears it should be clean. Post new log if you run it again and want an extra set of eyes to take a look.

Goldens advice to use the ESET is a good idea also.
wink.gif


Mike

I guess you answered it before I wrote - I just love you wonderful here at both forums!!

I am paranoid - very paranoid (so you may be my new best friend!:)

Thanks to you both! I will rerun MBam and run the on-line scan in the AM!
 

My Computer

Computer Manufacturer/Model Number
Toshiba Satellite L645D
OS
Windows 7 Home Premium 64bit
CPU
AMD Turion II P540 Dual-Core Processor 2.40 GHz
Memory
4GB RAM
Hi,

If you use this computer for your business, and you have already been infected a few times, I would most definately consider a paid version of MBAM. That way you can turn on the protection module so it works in the background to catch all the nasties, without having to rely on you remembering to perform scans.

After you run the ESET scan, do a Full Scan with MBAM too.

For your own information, here is some background information on backdoor.cycbot : as you can see its potentially extremly damaging :

http://www.precisesecurity.com/trojan/backdoor-cycbot/

What other security systems do you have installed on your PC? Would you like me to help you review them and your security in general?

Regards,
Golden
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Golden Mk. I.4
OS
Windows 10 Pro x64 ; Xubuntu x64
CPU
Intel i7 860 @ 2.80 GHz O/C'ed to 4.0GHz
Motherboard
Gigabyte P55A-UD3R Rev.1. Award BIOS F13
Memory
16GB Corsair Vengance DDR3 @ 661 MHz Dual Channel (9-9-9-24)
Graphics Card(s)
EVGA NVidia GTX 560 1024MB
Sound Card
Realtek Integrated
Monitor(s) Displays
Dual Samsung SyncMaster 2494HS
Screen Resolution
1920*1080 and 1920*1080
Hard Drives
1*Samsung 840 EVO 120GB SSD;
1*OCZ Vertex 2 60GB SSD;
2*Samsung F3 SpinPoint 1TB in RAID0;
1*Samsung F1 SpinPoint 1TB;
2*Western Digital 1TB External USB 3.0
1*Western Digital 500GB External USB 3.0
1*Seagate 500GB External USB 2.0
PSU
Thermaltake ToughPower QFan 750W
Case
Thermaltake Element S VK60001W2Z
Cooling
Corsair H60 Water Cooling, 2*230mm and 2*80mm case fans
Keyboard
Logitech G110
Mouse
Logitech MX518
Good advice, Golden!

It certainly has performed spectacular.

PS These items are in Quarantine - should I delete them? or does it matter?
 

My Computer

Computer Manufacturer/Model Number
Toshiba Satellite L645D
OS
Windows 7 Home Premium 64bit
CPU
AMD Turion II P540 Dual-Core Processor 2.40 GHz
Memory
4GB RAM
Hi,

Empty the quarantine folder by deleting them.

Then do another scan, and see if they re-appear.

Regards,
Golden
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Golden Mk. I.4
OS
Windows 10 Pro x64 ; Xubuntu x64
CPU
Intel i7 860 @ 2.80 GHz O/C'ed to 4.0GHz
Motherboard
Gigabyte P55A-UD3R Rev.1. Award BIOS F13
Memory
16GB Corsair Vengance DDR3 @ 661 MHz Dual Channel (9-9-9-24)
Graphics Card(s)
EVGA NVidia GTX 560 1024MB
Sound Card
Realtek Integrated
Monitor(s) Displays
Dual Samsung SyncMaster 2494HS
Screen Resolution
1920*1080 and 1920*1080
Hard Drives
1*Samsung 840 EVO 120GB SSD;
1*OCZ Vertex 2 60GB SSD;
2*Samsung F3 SpinPoint 1TB in RAID0;
1*Samsung F1 SpinPoint 1TB;
2*Western Digital 1TB External USB 3.0
1*Western Digital 500GB External USB 3.0
1*Seagate 500GB External USB 2.0
PSU
Thermaltake ToughPower QFan 750W
Case
Thermaltake Element S VK60001W2Z
Cooling
Corsair H60 Water Cooling, 2*230mm and 2*80mm case fans
Keyboard
Logitech G110
Mouse
Logitech MX518
Empty the quarantine folder by deleting them.

Then do another scan, and see if they re-appear.

Regards,
Golden

I will do that - thank you.

For your own information, here is some background information on backdoor.cycbot : as you can see its potentially extremly damaging :

Backdoor.Cycbot - Virus Solution and Removal

What other security systems do you have installed on your PC? Would you like me to help you review them and your security in general?

I most definitely know. Just to clarify, that ocurred on the Vista and Jacee and many others assisted me with it and winding down - I hope to get a great report soon (fingers crossed)! So when this came up, well - no need to say more.

I plan on changing all the security software on both systems - but can only work with one at a time (just in the event trouble ensues with the removals, loading etc.) - I cannot afford to keep buying new machines each month! LOL

I will certainly look forward to your input on that subject!

Thank you again and I will run some of these now.
 

My Computer

Computer Manufacturer/Model Number
Toshiba Satellite L645D
OS
Windows 7 Home Premium 64bit
CPU
AMD Turion II P540 Dual-Core Processor 2.40 GHz
Memory
4GB RAM
Hi,

Ah if Jacee is helping you then you have expert help. I imagine she has already recommended both anti-virus (such as MSE) and anti-malware (such as MBAM) to you, in addition to having your Firewall turned on, so I can't really add more to that.

Get those scans done, and then post back here with the results.

Regards,
Golden
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Golden Mk. I.4
OS
Windows 10 Pro x64 ; Xubuntu x64
CPU
Intel i7 860 @ 2.80 GHz O/C'ed to 4.0GHz
Motherboard
Gigabyte P55A-UD3R Rev.1. Award BIOS F13
Memory
16GB Corsair Vengance DDR3 @ 661 MHz Dual Channel (9-9-9-24)
Graphics Card(s)
EVGA NVidia GTX 560 1024MB
Sound Card
Realtek Integrated
Monitor(s) Displays
Dual Samsung SyncMaster 2494HS
Screen Resolution
1920*1080 and 1920*1080
Hard Drives
1*Samsung 840 EVO 120GB SSD;
1*OCZ Vertex 2 60GB SSD;
2*Samsung F3 SpinPoint 1TB in RAID0;
1*Samsung F1 SpinPoint 1TB;
2*Western Digital 1TB External USB 3.0
1*Western Digital 500GB External USB 3.0
1*Seagate 500GB External USB 2.0
PSU
Thermaltake ToughPower QFan 750W
Case
Thermaltake Element S VK60001W2Z
Cooling
Corsair H60 Water Cooling, 2*230mm and 2*80mm case fans
Keyboard
Logitech G110
Mouse
Logitech MX518
Yes, that is exactly the road we are taking!

I just did a full MBam and all is well. Will do the other scans tomorrow.

Thank you again & best wishes for the New Year!!
 

My Computer

Computer Manufacturer/Model Number
Toshiba Satellite L645D
OS
Windows 7 Home Premium 64bit
CPU
AMD Turion II P540 Dual-Core Processor 2.40 GHz
Memory
4GB RAM
No worries - happy to help :cool:
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Golden Mk. I.4
OS
Windows 10 Pro x64 ; Xubuntu x64
CPU
Intel i7 860 @ 2.80 GHz O/C'ed to 4.0GHz
Motherboard
Gigabyte P55A-UD3R Rev.1. Award BIOS F13
Memory
16GB Corsair Vengance DDR3 @ 661 MHz Dual Channel (9-9-9-24)
Graphics Card(s)
EVGA NVidia GTX 560 1024MB
Sound Card
Realtek Integrated
Monitor(s) Displays
Dual Samsung SyncMaster 2494HS
Screen Resolution
1920*1080 and 1920*1080
Hard Drives
1*Samsung 840 EVO 120GB SSD;
1*OCZ Vertex 2 60GB SSD;
2*Samsung F3 SpinPoint 1TB in RAID0;
1*Samsung F1 SpinPoint 1TB;
2*Western Digital 1TB External USB 3.0
1*Western Digital 500GB External USB 3.0
1*Seagate 500GB External USB 2.0
PSU
Thermaltake ToughPower QFan 750W
Case
Thermaltake Element S VK60001W2Z
Cooling
Corsair H60 Water Cooling, 2*230mm and 2*80mm case fans
Keyboard
Logitech G110
Mouse
Logitech MX518
First, download TFC by Old Timer TFC - Temp File Cleaner by OldTimer - Geeks to Go Forums and save it to your desktop.

Save any unsaved work. TFC will close ALL open programs including your browser!

Double-click on TFC.exe to run it. If you are using Vista/Windows 7 right-click on the file and choose Run As Administrator.
Click the Start button to begin the cleaning process and let it run uninterrupted to completion.
***Important! If TFC prompts you to reboot, please do so immediately. If not prompted, manually reboot the machine anyway to ensure a complete clean.

Next, run a full MBam scan.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio
Golden -

Here is the log from last evening - I may be slow, but I try! BTW, your instructions getting to those logs were excellent, thanks!

Jacee -
I will get TFC done now - thank you so much!
 

Attachments

My Computer

Computer Manufacturer/Model Number
Toshiba Satellite L645D
OS
Windows 7 Home Premium 64bit
CPU
AMD Turion II P540 Dual-Core Processor 2.40 GHz
Memory
4GB RAM
No worries FCUSA.

I'll step back from this a bit now so that Jacee (who is far more experienced in this than me) can guide you through this cleanly, but I'd like to follow the thread if thats OK.

Jacee : thanks for posting the link to the PUM hit. I got this on a guaranteed clean XP system recently, but never made any changes to the Start menu. The effect seems innocous at any rate, if I understand Tony Klein's post correctly.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Golden Mk. I.4
OS
Windows 10 Pro x64 ; Xubuntu x64
CPU
Intel i7 860 @ 2.80 GHz O/C'ed to 4.0GHz
Motherboard
Gigabyte P55A-UD3R Rev.1. Award BIOS F13
Memory
16GB Corsair Vengance DDR3 @ 661 MHz Dual Channel (9-9-9-24)
Graphics Card(s)
EVGA NVidia GTX 560 1024MB
Sound Card
Realtek Integrated
Monitor(s) Displays
Dual Samsung SyncMaster 2494HS
Screen Resolution
1920*1080 and 1920*1080
Hard Drives
1*Samsung 840 EVO 120GB SSD;
1*OCZ Vertex 2 60GB SSD;
2*Samsung F3 SpinPoint 1TB in RAID0;
1*Samsung F1 SpinPoint 1TB;
2*Western Digital 1TB External USB 3.0
1*Western Digital 500GB External USB 3.0
1*Seagate 500GB External USB 2.0
PSU
Thermaltake ToughPower QFan 750W
Case
Thermaltake Element S VK60001W2Z
Cooling
Corsair H60 Water Cooling, 2*230mm and 2*80mm case fans
Keyboard
Logitech G110
Mouse
Logitech MX518
I cannot seem to ahead on all this. I had to restart computer because there was an update and now it shows the update failed. I am sure this belongs in another section but I have attached a snip anyway. Can I proceed with TFC etc without addressing this first?
 

Attachments

  • FailedInstall123110.PNG
    FailedInstall123110.PNG
    33.5 KB · Views: 8

My Computer

Computer Manufacturer/Model Number
Toshiba Satellite L645D
OS
Windows 7 Home Premium 64bit
CPU
AMD Turion II P540 Dual-Core Processor 2.40 GHz
Memory
4GB RAM
Yes.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Bruce ... somewhere in his 40's
OS
Windows 7 Ultimate 32bit SP1
CPU
Intel(R) Core(TM)2 Quad CPU @ 2.40GHz, 2400 MHz
Motherboard
INTEL/D975XBX2
Memory
4 GB
Graphics Card(s)
ATI Radeon HD 2600 Pro
Monitor(s) Displays
Samsung SyncMaster 914v
Screen Resolution
1280 x 1024
Hard Drives
2/500GB each ... ST3500630AS ATA Device.
One is not connected
PSU
Rocketfish 700 W
Case
G.Skill Gigabyte Chassis
Keyboard
Standard PS/2 Keyboard
Mouse
Microsoft PS/2 Mouse
Internet Speed
DSL
Antivirus
Avira Internet Security
Browser
IE 11
Other Info
ATI HDMI Audio

My Computer

Computer Manufacturer/Model Number
Toshiba Satellite L645D
OS
Windows 7 Home Premium 64bit
CPU
AMD Turion II P540 Dual-Core Processor 2.40 GHz
Memory
4GB RAM
Back
Top