SoftwareTipsandTricks Forum

Go Back   SoftwareTipsandTricks Forum > Operating Systems > Windows XP
User Name
Password


Backdoor Agobot ALI Trojan Please Help!!

Reply
 
Thread Tools Search this Thread Rate Thread Display Modes

  #1  
Old 05-30-2008, 01:45 PM
Gus209 Offline
Registered User
 
Join Date: Apr 2008
Posts: 25
Backdoor Agobot ALI Trojan Please Help!!

Alright just recently my computer started running very slow so I tried scanning for viruses but when I tried to load up my Anti-virus it would just pop out and dissapear so I went online and found a free scanner which is called XoftSpySE I did a scan and it said I have 2 Backdoor Agobot ALI Trojan and its a severe risk and its locations is at software\microsoft\windows\currentversion\run\micr osoft updates and the other one is at software\microsoft\windows\currentversion\runservi ces\microsoft updates
which I have no ideal where thats at so I went to trendmicro.com and made a free scan but all it picked up was cookies and stuff like that and now I don't know what to do or what if that XoftSpySE program just tells my I have a trojan so it could download the real version which cost money xD please someone help!!
Reply With Quote

  #2  
Old 05-30-2008, 05:47 PM
Monty007's Avatar
Monty007 Offline
Registered User
 
Join Date: Jan 2007
Location: Australia
Posts: 1,042
I wouldnt trust XoftSpy, go to this site down load, install and update http://www.superantispyware.com/download.html
Boot into safe mode (no networking) and run a full scan also run a full scan of your anti-virus in safe mode.
__________________
MCP
MCDST
Reply With Quote

  #3  
Old 05-30-2008, 05:58 PM
Gus209 Offline
Registered User
 
Join Date: Apr 2008
Posts: 25
well now that might be a problem because now it says I can't install stuff becuase something wrong with the servies or something like that and it tells me it might be in safe mode but I don't have it on safe mode oh and my computer is running normal speed now but am sure I have a virus but i can't load up my anti-virus
Reply With Quote

  #4  
Old 05-30-2008, 06:43 PM
Disk_Contented's Avatar
Disk_Contented Offline
Temporary Ban
 
Join Date: Sep 2002
Location: In a plasma conduit
Posts: 1,625
Wow! what a baddie!
Gains access via unpatched vulnerabilities. Keep your machine updated!
backdoor in the name means you don't go onto a network with this machine. It is under remote access.
Change all your passwords everywhere, immediately!
See here for what it does:
http://www.trendmicro.com/vinfo/viru...OT.ALI&VSect=T
Removal:
http://www.trendmicro.com/vinfo/viru...2EALI&VSect=Sn
__________________
Where there's a will, There's a way.
Pay developers, not Rapidshare!
I know nowt, but at least I'm trying.
Quality, not quantity.
Prevention is better than cure.

Last edited by Disk_Contented : 05-30-2008 at 06:45 PM.
Reply With Quote

  #5  
Old 05-30-2008, 09:35 PM
Gus209 Offline
Registered User
 
Join Date: Apr 2008
Posts: 25
alright it tells me to download latest pattern file and to do a scan with my trend micro anti-virus but I can't open up the anti-virus so then it tells me to use house call but I did that like 4 times already and it didnt detect anything but i did this before i downloaded the latest pattern file so if i download that does house call scan pick up the backdoor thingy? oh then I read i had to have System Restore off so i did that already and restarted and am about to do the House call scan and see if it picks up anything oh and it told me to do this
1. Open Registry Editor. Click Start>Run, type REGEDIT, then press Enter.
2. In the left panel, double-click the following:
HKEY_LOCAL_MACHINE>Software>Microsoft>
Windows>CurrentVersion>Run
3. In the right panel, locate and delete the entry:
msvps = "msvps.exe"
4. In the left panel, double-click the following:
HKEY_LOCAL_MACHINE>Software>Microsoft>
Windows>CurrentVersion>RunServices
5. In the right panel, locate and delete the entry:
msvps = "msvps.exe"
6. Close Registry Editor.
but i couldn't find the msvp file in any of thos two so idk but thanx alot for the help so far at least i understand this more
Reply With Quote

  #6  
Old 05-31-2008, 09:14 AM
Disk_Contented's Avatar
Disk_Contented Offline
Temporary Ban
 
Join Date: Sep 2002
Location: In a plasma conduit
Posts: 1,625
Quote:
Originally Posted by Monty007
I wouldnt trust XoftSpy, go to this site down load, install and update http://www.superantispyware.com/download.html
Boot into safe mode (no networking) and run a full scan also run a full scan of your anti-virus in safe mode.
It looks like Monty was right and xoftspy was listed as a rogue app at one time. I class it as untrustworthy. Try the app he suggested.

If you think It might be a false positive, Gus209. Remember your system is acting as though it will do anything to stop you scanning it. Beware!
__________________
Where there's a will, There's a way.
Pay developers, not Rapidshare!
I know nowt, but at least I'm trying.
Quality, not quantity.
Prevention is better than cure.
Reply With Quote

  #7  
Old 05-31-2008, 02:41 PM
Gus209 Offline
Registered User
 
Join Date: Apr 2008
Posts: 25
yes maybe xsofspy just listed that trojan so i could buy the real version but i knoe i have something in my pc that aint letting me scan and trend micros house call aint picking it up and i cant use this http://www.superantispyware.com/download.html because i can't install nothing in my computer =(
Reply With Quote

  #8  
Old 05-31-2008, 04:31 PM
Disk_Contented's Avatar
Disk_Contented Offline
Temporary Ban
 
Join Date: Sep 2002
Location: In a plasma conduit
Posts: 1,625
Try combofix: http://www.bleepingcomputer.com/comb...o-use-combofix
Doesn't need installing.
__________________
Where there's a will, There's a way.
Pay developers, not Rapidshare!
I know nowt, but at least I'm trying.
Quality, not quantity.
Prevention is better than cure.
Reply With Quote

  #9  
Old 05-31-2008, 04:59 PM
Gus209 Offline
Registered User
 
Join Date: Apr 2008
Posts: 25
OMFG it doesn't let me go that that site =( am getting really pissed now
Reply With Quote

  #10  
Old 05-31-2008, 05:01 PM
Disk_Contented's Avatar
Disk_Contented Offline
Temporary Ban
 
Join Date: Sep 2002
Location: In a plasma conduit
Posts: 1,625
Post a list of startup items or running processes, though If i were you I would start over.
__________________
Where there's a will, There's a way.
Pay developers, not Rapidshare!
I know nowt, but at least I'm trying.
Quality, not quantity.
Prevention is better than cure.
Reply With Quote

  #11  
Old 05-31-2008, 05:07 PM
Gus209 Offline
Registered User
 
Join Date: Apr 2008
Posts: 25
in task manger rite? am not a whole lot of smart in computers
Reply With Quote

  #12  
Old 05-31-2008, 05:18 PM
Disk_Contented's Avatar
Disk_Contented Offline
Temporary Ban
 
Join Date: Sep 2002
Location: In a plasma conduit
Posts: 1,625
Yes, it may need a screen grab
__________________
Where there's a will, There's a way.
Pay developers, not Rapidshare!
I know nowt, but at least I'm trying.
Quality, not quantity.
Prevention is better than cure.
Reply With Quote

  #13  
Old 05-31-2008, 05:34 PM
Gus209 Offline
Registered User
 
Join Date: Apr 2008
Posts: 25
well I don't know what a screen grab is lol but here is the list of the running processes
PnkBstrA.exe
mDNSResponder.exe
firefox.exe
wpabaln.exe
svchost.exe
svchost.exe
xfire.exe
svchost.exe
svchost.exe
lsass.exe
services.exe
winlogon.exe
csrss.exe
smss.exe
iPodService.exe
RocketDock.exe
ctfmon.exe
rundll32.exe
rundll32.exe
iTunesHelper.exe
explorer.exe
taskmgr.exe
System
System Idle Process

and here is the list of start up items
svehost
UfSeAgnt
qttask
iTunesHelper
trtgdfua
ccgcdqhy
ApcMain
ctfmon
RocketDock
Trend Micro Internet Security
Reply With Quote

  #14  
Old 05-31-2008, 05:50 PM
Disk_Contented's Avatar
Disk_Contented Offline
Temporary Ban
 
Join Date: Sep 2002
Location: In a plasma conduit
Posts: 1,625
trtgdfua
ccgcdqhy

Nonesense names. There to confuse you.

ApcMain Can you get to this site: http://www.securitystronghold.com/ga...restriker.html
__________________
Where there's a will, There's a way.
Pay developers, not Rapidshare!
I know nowt, but at least I'm trying.
Quality, not quantity.
Prevention is better than cure.
Reply With Quote

  #15  
Old 05-31-2008, 05:59 PM
Gus209 Offline
Registered User
 
Join Date: Apr 2008
Posts: 25
yeah i could get to that site
Reply With Quote
Reply




Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Trojan Detected! Please Help! rbhavsar29 Windows Vista 1 04-11-2008 05:12 PM
suspected trojan viurs Freakinoldguy Windows XP 6 06-26-2004 04:51 PM
Protection against the First Mac OS X Trojan Horse Azn_tweaker Chit Chat 1 04-10-2004 10:53 AM
trojan horse prankster Internet 3 12-19-2002 06:52 AM
Trojan advice needed! chrisinthesun20 Windows XP 3 12-01-2002 08:28 AM



All times are GMT -5. The time now is 01:05 AM.


Designed by eXtremepixels. Powered by vBulletin Version 3.5.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 2.3.2 © 2005, Crawlability, Inc.