1. ## Need Help, My Gaming Rig got infected by EpicNet/CloudNet, Glupteba, Csrrs

Need solution, My PC got infected with EpicNet.inc/CloudNet/glupteba/or whatever, they keep coming after rebooting, I need your help to get rid of these pesky malware, step by step guide will be appreciated.
2. ## Help, i cannot remove this folder (windows/rss, epicnet.inc)

so apparently, malwarebytes and adwcleaner recognize this pup and trojan agent as a folder, i tried to remove it from malwarebytes and the folder stil reappear when i rebooted my computer can somebody help me with this?

4. ## Unusually high RAM usage at times

Hi. I have high ram usage at times, I mean 70-90% and I think it's connected to malware and Malwarebytes can't pick it up, but when my windows has been up and running for few hours, it shows 2 malware threats are detected, but even if I quarantine them and delete them, nothing works, they just keep coming back. I have also tried to use ADW cleaner multiple times without any luck too since it's all come back a few minutes after windows has loaded. One thing to note is that Chrome is only using 4-5 GB of ram which is okay, but the task manager shows over 70% even at sometimes 90% so there might be something running in the background which is hidden. I really hope we can fix this since this really destroys my PC experience and I can't wait to get down to bussines. Thank you. FRST.txt Addition.txt

6. ## Quarantining Trojan.Agent and Trojan.Yelloader Failure

Hi, MBAM has failed to quarantine/remove three identified trojan viruses several times today. I checked some sources and saw that it was recommended that I try MBAM Anti-Rootkit Beta to solve this, so I installed and ran it. It located the files and I selected to clean them and restarted my laptop, but if I run Anti-Rootkit or MBAM again it still detects the same files and MBAM still fails to quarantine them. I also tried running the scans and quarantining from Safe Mode, but that did not change the results. Any suggestions? Addition.txt FRST.txt Threat Scan Log.txt

8. ## Need Help Removing Malware

Recently one of my windows server 2008 R2 had been infected with malwares. I have no idea on how it got infected but i installed MalwareBytes Malware removal tool and it found few malwares including one bitcoin miner and quarantined it. After rebooting it worked without any issue but it keeps on restarting in 1-1.5 hours with below error in Event Viewer A critical system process, C:\Windows\system32\lsass.exe, failed with status code 00000000. The machine must now be restarted. Also it finds malware in C:\1.exe with type of Trojan.Agent and quarantines it. I am using latest version. It seems that malware is not getting removed completely after scan and it gets activated again and crashes OS after some time. Any help here would be highly appreciated.
9. ## Trojan.BHO, Trojan.Agent, Security.Hijack found

Found 1 file with Trojan.BHO and four registry malware items. How can I tell if the threats are completely removed? Webroot did not pick these items up on it's scan.

11. ## Fonts (.ttf/.otf) contain Trojan.Agent?

This is odd, I've never had a report like this before. Fonts are being considered as Trojan.Agent. As far as I know TTF or OTF files simply can't contain any malware. No? Here's the screenshot: I've been using these fonts for a while now. I'm sure those are false positives but why?
12. ## Bladabindi.gen Trojan keeps coming back, even after Malwarebytes Removal

I recently built a new pc, and have not even had it running for a month, and already I have a trojan... I have Windows Defender and Malwarebytes installed. After booting computer, either Malwarebytes or Windows Defender will quarantine the Win32/Bladabindi.gen Trojan, which is found in C:\ProgramData\smss.exe. I have tried deleting it many times using both of these programs, and have run full scans that show it to be gone afterwards. However, usually when I next restart, a notification will pop up immediately saying that Malwarebytes or Windows Defender has found this very same trojan in the very same location again! As you can imagine, this is very annoying for me, and I want to completely get rid of this program. Perhaps I should mention that I am using HackTool:MSIL/Gendows for my Microsoft Office Activation, and HackTool:Win32/AutoKMS for my Windows 8.1 activation, and that I have allowed both of those items in Windows Defender, although they came up as medium level threats. The threat level of Win32/Bladabindi.gen is stated as SEVERE in Windows Defender, so I am very worried! Please respond with instructions on what action I should take. Thanks so much for the time and consideration. -Jes3monkey
13. ## msconfig.ini

Hello, with each search the file \\ users \ % username% \ AppData \ Roaming \ msconfig.ini found and identified as Trojan.Agent and placed in Quarantäne. After a reboot the file is infected again. What can I do ? regards Tom OS Windows 8.1 Tool (Premium) 2.0.2.1012

20. ## Malwarebytes can't locate infection

My online Armor says that i my removable disk has a trojan.agent virus or shortcut virus. I use malwarebytes to remove it but it failed to locate it saying "no infection". Any help?
21. ## Trojan.Agent in COMMAND.COM - false positive?

Hello Malwarebytes, I updated Anti-Malware to the latest database version (913042702) and ran a full scan today. Here's what I got after running the same scan in developer mode: Files Infected: C:\Windows\System32\COMMAND.COM (Trojan.Agent) -> No action taken. [27517B842938D5006908C61D87F3AB7C] This never happened before. I'll be pleased if you guys could check this one whether it's a false positive or not. I've zipped everything and attached it in this post. The zip file includes the following files: COMMAND.COM -> the file reported as "infected" COMMAND.md5 -> MD5 checksum of the file for verification mbam-log-2013-04-27 (13-41-29).txt -> the detailed log of my scan in developer mode Regards, viruskiller mbam-false-positive-2013-04-27.zip
22. ## Yet another false positive?

Thank you for your help in the past. I think I've found yet another one. A scan of the computer turns up this result. " ...\FAT-Engine SDK + demos v1.22 BETA - fat.zip (Trojan.Agent.NR) -> No action taken. [19028d807fed5ed82d4ff02cae53738d] ...\FAT-Engine SDK + demos v1.22 BETA - fat.zip (Trojan.Agent.NR) -> No action taken. [04177a93224a330384f82af2649dad53] " FAT-Engine, is a generic Raycasting Engine for the TI-89, TI-89T, TI-92+ and TI-V200 (collectively known as TI-68k) calculators. < http://tict.ticalc.o...ref_other_games > I suspect this one is another false positive since scans of the file in question with AVG and Spybot Search & Destroy both come up clean. Note: Both files listed in the log provided by this post are just copies of the same file. Thank you. -Files and log attached. MBAM-log-2013-05-10 (01-09-50).txt FAT-Engine SDK + demos v1.22 BETA - fat.zip Please help. Thanks.

24. ## Trojan.Agent - svchost.exe not deleting/constantly quarantined

Hi, I'm new to this forum so I am sorry if this is posted in the wrong category. I was recently infected with the Trojan.Agent that runs out of the svchost.exe (winrscmde). It uses up a large amount of the CPU along with hijacking passwords, etc. My Norton Security wasn't able to detect it so I downloaded malwarebytes to resolve the issue. I ran malwarebytes and it found the Trojan.Agent with little problem. It was quarantined and I restarted my computer. I then deleted the threats listed in the quarantine box. The Trojan.Agent still keeps reappearing in the quarantine box with more Trojan.Agents being created every minute.They are no longer affecting my CPU since it only ranges 3%-10% compared to 50% before it was quarantined. The symptoms are no longer present, but the virus keeps trying to recreate itself to no avail though. I have tried restarting my computer but the virus persists. All of the recreations are quarantined, but they have not stopped being created. I am wondering if my computer is safe right now and if there is anything I can do to prevent these recreations. Thank You
25. ## trojan.agent quarentined, but can't seem to remove - help!

