This is a read-only archive of malwareremoval.com. No new posts or registrations. Privacy Page
Malware Removal Forums

Trojan.Agent

7 min read

✨ The volunteers who helped with this thread aren't active anymore, but you can still get a personalized answer — click Ask AI below.

This thread's last reply is from August 4, 2012, 1:13 AM UTC. Software, malware, and removal-tool advice below may be out of date — treat specific steps and download links with caution.

marlenefoung
I did it and MBAM still found a trojan:

Trojan.Agent
Registry value
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run|61703

MBAM log:Malwarebytes Anti-Malware 1.62.0.1300
www.malwarebytes.org

Database version: v2012.07.29.09

Windows Vista Service Pack 2 x64 NTFS
Internet Explorer 9.0.8112.16421
[redacted] :: FOUNG-YANG-PC [administrator]

Protection: Enabled

30/07/2012 7:35:42 PM
mbam-log-2012-07-30 (19-35-42).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 190498
Time elapsed: 2 minute(s), 36 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run|61703 (Trojan.Agent) -> Data: C:\PROGRA~3\LOCALS~1\Temp\mstvfixe.cmd -> Delete on reboot.

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

(end)
askey127 Admin/Teacher
marlene,
I think that's just a leftover registry entry. Let's see.
---------------------------------------------
Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1 (64-bit)
Download Mirror #2 (64-bit)


  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:

    :reg
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run /sub

    :filefind
    mstvfixe.cmd
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.

Note: The results log can also be found on your Desktop, entitled SystemLook.txt

askey127
marlenefoung
SystemLook 30.07.11 by jpshortstuff
Log created at 19:49 on 31/07/2012 by [redacted]
Administrator - Elevation successful

========== reg ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
"61703"="C:\PROGRA~3\LOCALS~1\Temp\mstvfixe.cmd"


========== filefind ==========

Searching for "mstvfixe.cmd"
No files found.

-= EOF =-
askey127 Admin/Teacher
marlene,
That is just an "orphaned" registry entry. The file it's trying to run doesn't exist any more.
Let's get rid of it so MBAM won't detect it .
----------------------------------------------
Perform a Custom Fix with OTL
Run OTL (Right click and choose "Run as administrator" in Vista/Win7)
  • In the Custom Scans/Fixes box at the bottom, paste in the following lines from the Code box (Do not include the word "Code"):

    :Commands
    [CREATERESTOREPOINT]

    :Reg
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
    "61703"=-

    :Commands
    [EMPTYTEMP]
  • Then click the Run Fix button at the top.
  • Let the program run unhindered and reboot the PC when it is done.
  • Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.


askey127
marlenefoung
All processes killed
========== COMMANDS ==========
Restore point Set: OTL Restore Point
========== REGISTRY ==========
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\\61703 deleted successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: [redacted]
->Temp folder emptied: 2154259 bytes
->Temporary Internet Files folder emptied: 344509975 bytes
->Java cache emptied: 0 bytes
->Apple Safari cache emptied: 0 bytes
->Opera cache emptied: 0 bytes
->Flash cache emptied: 2475 bytes

User: Public

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 6430399 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 842433337 bytes

Total Files Cleaned = 1,140.00 mb


OTL by OldTimer - Version 3.2.55.0 log created on 08012012_211002

Files\Folders moved on Reboot...
C:\Users\[redacted]\AppData\Local\Temp\VGX698B.tmp moved successfully.

PendingFileRenameOperations files...
File C:\Users\[redacted]\AppData\Local\Temp\VGX698B.tmp not found!

Registry entries deleted on Reboot...
askey127 Admin/Teacher
marlene,
Looks like we got it this time.
Let me know if MBAM finds anything. (It could possibly find something in the C:_OTL\ folder but that's a harmless quarantine location).

Should be clean now.

askey127
marlenefoung
Thank you for your help and for your time:)
askey127 Admin/Teacher

✨ Ask AI about this thread

No ads, no affiliate links — generated on request from this thread's own archived content, not written by forum staff. Never run a scan/removal tool as a self-service step if the original thread describes it being done under a helper's direct supervision, and don't include your name, email, or other personal details in a follow-up question. See our privacy page for details on how this works.