Jump to content


Recommended Posts

Hi, is Malwarebytes able to remove W32.Spybot.CF ? as it just showed TROJAN.AGENT. The trojan keep infected my PC even though I already update to the latest database and enable protection. Pls help !!

Head on over to our HijackThis forum and we will see what we can do for you .


Read the pinned threads and post your log there in a new thread .

If I have time tonight I might be able to collect samples from you and get this fixed .

BTW , Trojan.Agent is what you get on most generic detections so I would like to get something more specific into defs on this one .

Link to post
Share on other sites

Head on over to our HijackThis forum and we will see what we can do for you .


Read the pinned threads and post your log there in a new thread .

If I have time tonight I might be able to collect samples from you and get this fixed .

BTW , Trojan.Agent is what you get on most generic detections so I would like to get something more specific into defs on this one .

I suspected the protection works only on database : 1456 which came from version 1.31. It well protected (signed by popup windows with 3 buttons : disable, ignore, and terminate) until I do scheduled updated to newer one, and the Trojan attacked again. Then I had to uninstall and reinstall again back to the original database from version 1.31.

Malwarebytes' Anti-Malware 1.31

Database version: 1456

Windows 5.0.2195 Service Pack 4

12/6/2008 9:45:17 AM

mbam-log-2008-12-06 (09-45-17).txt

Scan type: Quick Scan

Objects scanned: 42653

Time elapsed: 6 minute(s), 18 second(s)

Memory Processes Infected: 0

Memory Modules Infected: 0

Registry Keys Infected: 3

Registry Values Infected: 0

Registry Data Items Infected: 0

Folders Infected: 0

Files Infected: 3

Memory Processes Infected:

(No malicious items detected)

Memory Modules Infected:

(No malicious items detected)

Registry Keys Infected:

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\winspoolsvc (Trojan.Agent) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\winspoolsvc (Trojan.Agent) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\winspoolsvc (Trojan.Agent) -> Quarantined and deleted successfully.

Registry Values Infected:

(No malicious items detected)

Registry Data Items Infected:

(No malicious items detected)

Folders Infected:

(No malicious items detected)

Files Infected:

C:\WINNT\system32\csrsc.exe (Trojan.Agent) -> Delete on reboot.

C:\RECYCLER\pagesyxxs.exe (Heuristics.Malware) -> Quarantined and deleted successfully.

C:\RECYCLER\pagewage.exe (Heuristics.Malware) -> Quarantined and deleted successfully.

Malwarebytes' Anti-Malware 1.31

Database version: 1479

Windows 5.0.2195 Service Pack 4

12/10/2008 2:05:13 PM

mbam-log-2008-12-10 (14-05-13).txt

Scan type: Quick Scan

Objects scanned: 42800

Time elapsed: 6 minute(s), 47 second(s)

Memory Processes Infected: 0

Memory Modules Infected: 0

Registry Keys Infected: 2

Registry Values Infected: 0

Registry Data Items Infected: 0

Folders Infected: 0

Files Infected: 1

Memory Processes Infected:

(No malicious items detected)

Memory Modules Infected:

(No malicious items detected)

Registry Keys Infected:

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\winspoolsvc (Trojan.Agent) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\winspoolsvc (Trojan.Agent) -> Quarantined and deleted successfully.

Registry Values Infected:

(No malicious items detected)

Registry Data Items Infected:

(No malicious items detected)

Folders Infected:

(No malicious items detected)

Files Infected:

C:\WINNT\system32\csrsc.exe (Trojan.Agent) -> Quarantined and deleted successfully.

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.