Welcome to SecurityForumz.com!
FAQFAQ      ProfileProfile    Private MessagesPrivate Messages   Log inLog in

Trojan Agent Winlogonhook

 
   Security Forums (Home) -> General Discussions RSS
Next:  FTC - fake e-mails  
Author Message
Gary Cramble

External


Since: Nov 04, 2007
Posts: 3



(Msg. 1) Posted: Sun Nov 04, 2007 10:44 am
Post subject: Trojan Agent Winlogonhook
Archived from groups: alt>comp>virus (more info?)

I keep seeing this little buggar pop up, even after spyware cleaners say it
has been removed. I ran Spysweeper and Ad AwareSE, both find it as a Trojan
in the hkey_local_machine part of the registry. yet, it keeps coming back
after removal/quarantine. norton doesn't even recognize it as anything which
makes me wonder if it's anything at all.

Any help, suggestions on how to get rid of this thing? also, since it's
arrival, windows installer keeps trying to install programs that already are
installed. very annoying. thanks in advance for any help.
gary

 >> Stay informed about: Trojan Agent Winlogonhook 
Back to top
Login to vote
joe black

External


Since: Oct 11, 2007
Posts: 4



(Msg. 2) Posted: Sun Nov 04, 2007 10:45 am
Post subject: Re: Trojan Agent Winlogonhook [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

"Gary Cramble" <gcramble DeleteThis @yahoo.net> wrote in message
news:13irq7fn3mech54@corp.supernews.com...
>I keep seeing this little buggar pop up, even after spyware cleaners say it
>has been removed. I ran Spysweeper and Ad AwareSE, both find it as a Trojan
>in the hkey_local_machine part of the registry. yet, it keeps coming back

What is the exact registry address and file name?

 >> Stay informed about: Trojan Agent Winlogonhook 
Back to top
Login to vote
Gary Cramble

External


Since: Nov 04, 2007
Posts: 3



(Msg. 3) Posted: Sun Nov 04, 2007 6:49 pm
Post subject: Re: Trojan Agent Winlogonhook [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

"joe black" <X-No-archive.DeleteThis@invalid.invalid> wrote in message ...


> "Gary Cramble" <gcramble.DeleteThis@yahoo.net> wrote in message
>>I keep seeing this little buggar pop up, even after spyware cleaners say
>>it has been removed. I ran Spysweeper and Ad AwareSE, both find it as a
>>Trojan in the hkey_local_machine part of the registry. yet, it keeps
>>coming back


> What is the exact registry address and file name?


hkey_local_machine\software\microsoft\mssmgr

then there are 5 more lines of the same file name/address that follow with a
different value added to the end of the string:

(value: Brnd)
(value: BSTV)
(value: SSTV)
(value: SCLIST)
(value: SSLIST
 >> Stay informed about: Trojan Agent Winlogonhook 
Back to top
Login to vote
pcbutts1

External


Since: Oct 14, 2007
Posts: 190



(Msg. 4) Posted: Sun Nov 04, 2007 6:49 pm
Post subject: Re: Trojan Agent Winlogonhook [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

Use Remove-it version 14, it's fast and free. It now has over 5000
signatures to remove All variants of Rogue scanners, Desktop/Homepage
Hijackers, Trojans, Codec's, and related Malware/Spyware. New Feature,
Remove-it will now update your hosts file. This tool is designed to
Specifically remove all variants. Scan time is about 2-10 minutes. Designed
for Windows 2000/XP only. Password is still required.
First read this page http://www.pcbutts1.com/downloads then use the email
link on the bottom of the page to receive the software.


--

Newsgroup Trolls. Read about mine here http://www.pcbutts1.com/downloads
The list grows. Leythos the stalker http://www.leythosthestalker.com, David
H. Lipman, Max M Wachtell III aka What's in a Name?, Fitz,
Rhonda Lea Kirk, Meat Plow, F Kwatu F, George Orwell



"Gary Cramble" <gcramble RemoveThis @yahoo.net> wrote in message
news:13ismkmi5toqjda@corp.supernews.com...
>
> "joe black" <X-No-archive RemoveThis @invalid.invalid> wrote in message ...
>
>
>> "Gary Cramble" <gcramble RemoveThis @yahoo.net> wrote in message
>>>I keep seeing this little buggar pop up, even after spyware cleaners say
>>>it has been removed. I ran Spysweeper and Ad AwareSE, both find it as a
>>>Trojan in the hkey_local_machine part of the registry. yet, it keeps
>>>coming back
>
>
>> What is the exact registry address and file name?
>
>
> hkey_local_machine\software\microsoft\mssmgr
>
> then there are 5 more lines of the same file name/address that follow with
> a different value added to the end of the string:
>
> (value: Brnd)
> (value: BSTV)
> (value: SSTV)
> (value: SCLIST)
> (value: SSLIST
>
 >> Stay informed about: Trojan Agent Winlogonhook 
Back to top
Login to vote
Leythos

External


Since: Jan 04, 2006
Posts: 201



(Msg. 5) Posted: Sun Nov 04, 2007 7:44 pm
Post subject: Re: Trojan Agent Winlogonhook [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

In article <fgloo9$q00$1@blackhelicopter.databasix.com>, pcbutts1
@leythosthestalker.com says...
> Remove-it will now update your hosts file.

It will block access to reputable malware fighting tools that are not
hosted on BUTTS Porno website.

--

Leythos - spam999free RemoveThis @rrohio.com (remove 999 to email me)

Fight exposing kids to porn, complain about sites like PCBUTTS 1.COM
that create filth and put it on the web for any kid to see: Just take a
look at some of the FILTH he's created and put on his website:
http://forums.speedguide.net/archive/index.php/t-223485.html all exposed
to children (the link I've include does not directly display his filth).
You can find the same information by googling for 'PCBUTTS1' and
'exposed to kids'.
 >> Stay informed about: Trojan Agent Winlogonhook 
Back to top
Login to vote
Kayman

External


Since: Nov 01, 2007
Posts: 22



(Msg. 6) Posted: Mon Nov 05, 2007 3:57 am
Post subject: Re: Trojan Agent Winlogonhook [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

On Sun, 4 Nov 2007 19:44:43 -0500, Leythos wrote:

> In article <fgloo9$q00$1@blackhelicopter.databasix.com>, pcbutts1
> @leythosthestalker.com says...
>> Remove-it will now update your hosts file.
>
> It will block access to reputable malware fighting tools that are not
> hosted on BUTTS Porno website.

Okay, and what advice should the OP follow to rectify his problem?
 >> Stay informed about: Trojan Agent Winlogonhook 
Back to top
Login to vote
Russg

External


Since: Jun 03, 2006
Posts: 117



(Msg. 7) Posted: Mon Nov 05, 2007 10:02 am
Post subject: Re: Trojan Agent Winlogonhook [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

"Gary Cramble" <> wrote in message news:
>I keep seeing this little buggar pop up, even after spyware cleaners say it
>has been removed. I ran Spysweeper and Ad AwareSE, both find it as a Trojan
>in the hkey_local_machine part of the registry. yet, it keeps coming back
>after removal/quarantine. norton doesn't even recognize it as anything
>which makes me wonder if it's anything at all.
>
> Any help, suggestions on how to get rid of this thing? also, since it's
> arrival, windows installer keeps trying to install programs that already
> are installed. very annoying. thanks in advance for any help.
> gary
Have you tried Ad-aware in safe mode, but first, turn off system restore
before booting in safe mode.
Then boot normally and see if it is still gone and turn restore back on.
You can find how to turn system restore off/on by a search of help for
system restore. You can also learn how to do a clean boot from links at:

http://www.claymania.com/removal-trojan-adware.html
 >> Stay informed about: Trojan Agent Winlogonhook 
Back to top
Login to vote
jen

External


Since: Aug 15, 2003
Posts: 112



(Msg. 8) Posted: Mon Nov 05, 2007 11:50 am
Post subject: Re: Trojan Agent Winlogonhook [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

"Gary Cramble" <gcramble.RemoveThis@yahoo.net> wrote in message
news:13irq7fn3mech54@corp.supernews.com...
>I keep seeing this little buggar pop up, even after spyware cleaners
>say it has been removed. I ran Spysweeper and Ad AwareSE, both find it
>as a Trojan in the hkey_local_machine part of the registry. yet, it
>keeps coming back after removal/quarantine. norton doesn't even
>recognize it as anything which makes me wonder if it's anything at all.
> Any help, suggestions on how to get rid of this thing? also, since
> it's arrival, windows installer keeps trying to install programs that
> already are installed. very annoying. thanks in advance for any help.

Download and scan with SUPERAntiSpyware Free
http://www.superantispyware.com/

* Double-click SUPERAntiSypware.exe and use the default settings for
installation.
* An icon will be created on your desktop. Double-click that icon to
launch the program.
* If asked to update the program definitions, click "Yes". If not,
update the definitions before scanning by selecting "Check for Updates".
(If you encounter any problems while downloading the updates, manually
download them from here and unzip into the program's folder.)
* Under "General and Startup", make sure "Start SUPERAntiSpyware when
Windows starts" box is unchecked.
* Under "Configuration and Preferences", click the Preferences button.
* Click the Scanning Control tab.
* Under Scanner Options make sure the following are checked (leave all
others unchecked):
o Close browsers before scanning.
o Scan for tracking cookies.
o Terminate memory threats before quarantining.
* Click the "Close" button to leave the control center screen and exit
the program.
* Do not run a scan just yet.

Reboot your computer in "SAFE MODE" using the F8 method. To do this,
restart your computer and after hearing your computer beep once during
startup (but before the Windows icon appears) press the F8 key
repeatedly. A menu will appear with several options. Use the arrow keys
to navigate and select the option to run Windows in "Safe Mode".

Scan with SUPERAntiSpyware as follows:

* Launch the program and back on the main screen, under "Scan for
Harmful Software" click Scan your computer.
* On the left, make sure you check C:\Fixed Drive.
* On the right, under "Complete Scan", choose Perform Complete Scan and
click "Next".
* After the scan is complete, a Scan Summary box will appear with
potentially harmful items that were detected. Click "OK".
* Make sure everything has a checkmark next to it and click "Next".
* A notification will appear that "Quarantine and Removal is Complete".
Click "OK" and then click the "Finish" button to return to the main
menu.
* If asked if you want to reboot, click "Yes" and reboot normally.
* To retrieve the removal information after reboot, launch
SUPERAntispyware again.
o Click Preferences, then click the Statistics/Logs tab.
o Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
o If there are several logs, click the current dated log and press View
log. A text file will open in your default text editor.
* Click Close to exit the program.

Here is a decription of your malware:
Trojan Agent Winlogonhook:
http://research.spysweeper.com/search.php?serialnumber=UY0Z74II

Since you may never be sure your system is entirely free of this type of
infestation, it is best to format and clean install your OS...

-jen
 >> Stay informed about: Trojan Agent Winlogonhook 
Back to top
Login to vote
jen

External


Since: Aug 15, 2003
Posts: 112



(Msg. 9) Posted: Mon Nov 05, 2007 12:02 pm
Post subject: Re: Trojan Agent Winlogonhook [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

"jen" <jen.RemoveThis@example.com> wrote in message
news:FRHXi.21534$u7.3909@bignews2.bellsouth.net...
> "Gary Cramble" <gcramble.RemoveThis@yahoo.net> wrote in message
> news:13irq7fn3mech54@corp.supernews.com...
>>I keep seeing this little buggar pop up, even after spyware cleaners
>>say it has been removed. I ran Spysweeper and Ad AwareSE, both find it
>>as a Trojan in the hkey_local_machine part of the registry. yet, it
>>keeps coming back after removal/quarantine. norton doesn't even
>>recognize it as anything which makes me wonder if it's anything at
>>all.
>> Any help, suggestions on how to get rid of this thing? also, since
>> it's arrival, windows installer keeps trying to install programs that
>> already are installed. very annoying. thanks in advance for any help.
>
> Download and scan with SUPERAntiSpyware Free
> http://www.superantispyware.com/
>
> * Double-click SUPERAntiSypware.exe and use the default settings for
> installation.
> * An icon will be created on your desktop. Double-click that icon to
> launch the program.
> * If asked to update the program definitions, click "Yes". If not,
> update the definitions before scanning by selecting "Check for
> Updates". (If you encounter any problems while downloading the
> updates, manually download them from here and unzip into the program's
> folder.)
> * Under "General and Startup", make sure "Start SUPERAntiSpyware when
> Windows starts" box is unchecked.
> * Under "Configuration and Preferences", click the Preferences button.
> * Click the Scanning Control tab.
> * Under Scanner Options make sure the following are checked (leave all
> others unchecked):
> o Close browsers before scanning.
> o Scan for tracking cookies.
> o Terminate memory threats before quarantining.
> * Click the "Close" button to leave the control center screen and exit
> the program.
> * Do not run a scan just yet.
>
> Reboot your computer in "SAFE MODE" using the F8 method. To do this,
> restart your computer and after hearing your computer beep once during
> startup (but before the Windows icon appears) press the F8 key
> repeatedly. A menu will appear with several options. Use the arrow
> keys to navigate and select the option to run Windows in "Safe Mode".
>
> Scan with SUPERAntiSpyware as follows:
>
> * Launch the program and back on the main screen, under "Scan for
> Harmful Software" click Scan your computer.
> * On the left, make sure you check C:\Fixed Drive.
> * On the right, under "Complete Scan", choose Perform Complete Scan
> and click "Next".
> * After the scan is complete, a Scan Summary box will appear with
> potentially harmful items that were detected. Click "OK".
> * Make sure everything has a checkmark next to it and click "Next".
> * A notification will appear that "Quarantine and Removal is
> Complete". Click "OK" and then click the "Finish" button to return to
> the main menu.
> * If asked if you want to reboot, click "Yes" and reboot normally.
> * To retrieve the removal information after reboot, launch
> SUPERAntispyware again.
> o Click Preferences, then click the Statistics/Logs tab.
> o Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
> o If there are several logs, click the current dated log and press
> View log. A text file will open in your default text editor.
> * Click Close to exit the program.
>
> Here is a decription of your malware:
> Trojan Agent Winlogonhook:
> http://research.spysweeper.com/search.php?serialnumber=UY0Z74II
>
> Since you may never be sure your system is entirely free of this type
> of infestation, it is best to format and clean install your OS...

ps.
If you encounter any problems while downloading the updates, manually
download them from here:
http://www.superantispyware.com/definitions.html

-jen
 >> Stay informed about: Trojan Agent Winlogonhook 
Back to top
Login to vote
kurt wismer

External


Since: Jul 04, 2003
Posts: 1562



(Msg. 10) Posted: Mon Nov 05, 2007 11:12 pm
Post subject: Re: Trojan Agent Winlogonhook [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

pcbutts1 wrote:
> Use Remove-it version 14, it's fast and free.

and greyware...

--
"it's not the right time to be sober
now the idiots have taken over
spreading like a social cancer,
is there an answer?"
 >> Stay informed about: Trojan Agent Winlogonhook 
Back to top
Login to vote
Gary Cramble

External


Since: Nov 04, 2007
Posts: 3



(Msg. 11) Posted: Thu Nov 08, 2007 10:39 pm
Post subject: Re: Trojan Agent Winlogonhook [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

sorry hun . . . i wasn't replying to your post directly, that's just where
it attached. i was raging back at some posters prior to yours. i did get it
resolved, and using some of your advice, thanks. but please know my blast at
the sales world wasn't directed to you : )


"jen" <jen.DeleteThis@example.com> wrote in message news:7bnYi.51269
>
> Superantispyware *is* free, and will clean the rest of the junk off your
> system as well as can be done... If you don't want to follow the
> proceedure I outlined for your *critical* infestation, then as I said do
> this:
>
> Since you may never be sure your system is entirely free of this type of
> infestation, it is best to format and clean install your OS...
>
> -jen
 >> Stay informed about: Trojan Agent Winlogonhook 
Back to top
Login to vote
Display posts from previous:   
Related Topics:
trojan Agent.EF - I can't find any reference via Google to the EF version. Is it new? It showed up on my pc in the file Dc2799.dll which I deleted by emptying the recycle bin. Leo

Trojan Agent.FK help needed - A friend running XP Home has had it slow down to crawl pace and I am trying to help from a distance(not easy to get to PC distance wise). She has Mcafee and Adaware &Spybot that show nothing. One of my suggestions was to run Trend Micro online sca...

Trojan.Win32.Agent - Hi Folks..... I discovered this trojan using a-Squared.....EZ Trust, Spybot and AdAware (among a few I ran) did not alert on it. A-Squared called it "Trojan.Win32.Autoit.b" I fired the infected files off to Virus Total and got the followin...

I need a help with two trojan AGENT.XJ e GROMP - please, I hope someone can help me somehow. Is there any way to remove theese viruses than are slowing down my PC? Sorry for english mistakes, but I'm not ienglish mother tounge. I tried to look for solution by searcing the net, and in this NG, but I..

Trojan horse Downloader.Agent.2.s - Hello, I'm a novice when it comes to viruses, and I have a couple questions. Hopefully, you will be able to help me out. I went to the following site: www.playstation2-cheats.co.uk/your_cheats.php/?13386 and a pop-up opened..
   Security Forums (Home) -> General Discussions All times are: Pacific Time (US & Canada) (change)
Page 1 of 1

 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum



[ Contact us | Terms of Service/Privacy Policy ]