Jump to content

Malware Issue? / MSIL/PSW.Agent.NGD trojan


Recommended Posts

Older versions of Java pose a security risk. Uninstall Java 7 Update 13

And if you do not need Java for the programs that you use, keep Java off your system .

How to disable Java in various browsers : http://blog.eset.com/2012/08/29/disabling-java-a-safer-way-to-browse

Also see No, Seriously, Just Disable Java in Your Browser Right Now

Windows does not need Java for the o.s. to work or to run. Only selected 3rd-party programs require Java runtime.

If and only if a installed application really need it, then, see also Corrine's Security Blog post http://securitygarden.blogspot.com/2013/02/critical-oracle-java-security-update.html

You will want to print out or copy these instructions to Notepad for offline reference!

Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools

For directions on how, see How To Temporarily Disable Your Anti-virus, Firewall And Anti-malware Programs

Do NOT turn off the firewall

Close all open browsers at this point.

Start Internet Explorer (fresh) by pressing Start >> Internet Explorer >> Right-Click and select Run As Administrator.

Using Internet Explorer browser only, go to ESET Online Scanner website:

http://www.eset.com/onlinescan/

  • Accept the Terms of Use and press Start button;
  • Approve the install of the required ActiveX Control, then follow on-screen instructions;
  • Enable (check) the Remove found threats option, and run the scan.
  • After the scan completes, the Details tab in the Results window will display what was found and removed.
    • A logfile is created and located at C:\Program Files (x86)\Eset\EsetOnlineScanner\log.txt.

    Look at contents of this file using Notepad.

    The Frequently Asked Questions for ESET Online Scanner can be viewed here

    http://go.eset.com/us/online-scanner/faq

    • It is emphasized to temporarily disable any pc-resident {active} antivirus program prior to any on-line scan by any on-line scanner.
      (And the prompt re-enabling when finished.)
    • If you use Firefox, you have to install IETab, an add-on. This is to enable ActiveX support.
    • Do not use the system while the scan is running. Once the full scan is underway, go take a long break popcorn.gifpepsi.gif

Re-enable the antivirus program.

Reply with copy of the Eset scan log

Link to post
Share on other sites

  • Replies 54
  • Created
  • Last Reply

Top Posters In This Topic

ESET log below. The Win32/Bagle worm is on the XP partition and the Lotoor is on the E-drive (this has to do with my Android phone I assume).

Nothing found on the Win 7 partition.

Brian

D:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinDNSChangeraxi.zip Win32/Bagle.gen.zip worm cleaned by deleting - quarantined

E:\Downloads\Samsung\SuperOneClickv2.3.3-ShortFuse\Exploits\psneuter Android/Exploit.Lotoor.AK trojan cleaned by deleting - quarantined

Link to post
Share on other sites

We can wrap this up now. I see that you are clear of your original issues.

If you have a problem with these steps, or something does not quite work here, do let me know.

The following few steps will remove tools we used. Advise me after you have completed the cleanups.

We have to remove Combofix and all its associated folders. By whichever name you named it, ( you had named it ComboFix icon_exclaim.gif),

put that name in the RUN box stated just below.

The "/uninstall" in the Run line below is to start Combofix for it's cleanup & removal function.

Note the space before the slash mark.

The utility must be removed to prevent any un-intentional or accidental usage, PLUS, to free up much space on your hard disk.

  • Highlight the line in this CODEBOX.
    Select & Copy the entire line within this codebox (so that it is in Windows clipboard memory)
    c:\users\BMO-WIN-7\Desktop\ComboFix.exe /uninstall


  • Start >> type in cmd >> press the Ctrl+Shift+Enter keyboard combination and cmd.exe will be launched as if you selected Run as Administrator. You will then see a User Account Control prompt asking if you would like to allow the Command Prompt to be able to make changes on your computer. Click on the Yes button and you will now be at the Elevated Command Prompt.
    Do a Right click within the command prompt window and select Paste. This must show the line from Codebox above.
    Then tap Enter

IF in the case Combofix un-install has an issue, skip that step.

NEXT

  • Download OTC to your desktop and run it
  • Click Yes to beginning the Cleanup process and remove these components, including this application.
  • You will be asked to reboot the machine to finish the Cleanup process. Choose Yes.

ERUNT you should keep and use periodically to backup Windows registry.

Delete the following if still present:

securitycheck.exe

RKILL

roguekiller.exe

MBAR

Tdsskiller.exe

DrWeb Cure-It

Listparts.exe

You may use Control Panel >> Programs and Features and uninstall ESET Online scan.

Safer practices & malware prevention

We are finished here. Best regards. cool.gif

Link to post
Share on other sites

Maurice,

I have done what you suggested above. Hopefully, I am now ok, however, that is what I thought on Friday before having the original issue reappear. Maybe removing all registry items for ccleaner and Windows-Audio-HD had an affect, particularly the items in the "run" section. I will feel better when I have gone a week or so without the problem re-occuring. If that happens, I will have to bite the bullet and restore the Win 7 partition from the image I made on 2/9/13.

Thanks for you help,

Brian

Link to post
Share on other sites

Ccleaner is not a malware and not a threat.

If your computer plays audio sounds ok and you do ok, then fine.

Since I cannot see any malware left, it is all up to you if you decide to wipe/erase and install Windows fresh.

You are welcome. I wish you well. I am closing this topic.

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.

Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.