Win32.agent.akk

I cannot get rid if a pop-up, saying my browser has been hijacked by a variant of 'Trojan.Win32.Agent.akk'. When you click on the box it wants you to download anit virus software from 'ie.defender' I have been unable to get rid of it with bitdefender. Nor have the downloads, from the website, helped either. Suggestions?

Comments

  • Dear davem


    When does that pop-up appears?


    Please download hijackthis. Install it and run it. Click on do a system scan and save a logfile. Post the output of the scan into your next post.


    Best regards


    Niels

  • Thanks for the reply. It usually pops up when you start internet explorer, or when you go to a new web page, and also when you first log on. I will try out the hijackthis download

  • Neils,


    Here it is. I figured it out. Vista is new to me, as is BD. Sorry for the mess


    Logfile of Trend Micro HijackThis v2.0.2


    Scan saved at 1:42:36 PM, on 07/12/2007


    Platform: Windows Vista (WinNT 6.00.1904)


    MSIE: Internet Explorer v7.00 (7.00.6000.16546)


    Boot mode: Normal


    Running processes:


    C:\Windows\system32\Dwm.exe


    C:\Windows\Explorer.EXE


    C:\Windows\sttray.exe


    C:\Windows\System32\igfxtray.exe


    C:\Windows\System32\hkcmd.exe


    C:\Windows\System32\igfxpers.exe


    C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe


    C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe


    C:\Windows\system32\igfxsrvc.exe


    C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe


    C:\Program Files\Nero\Nero 7\InCD\InCD.exe


    C:\Windows\System32\wpcumi.exe


    C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe


    C:\Program Files\iTunes\iTunesHelper.exe


    C:\Program Files\Windows Sidebar\sidebar.exe


    C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe


    C:\Windows\system32\taskeng.exe


    C:\Program Files\Internet Explorer\ieuser.exe


    C:\Program Files\Internet Explorer\iexplore.exe


    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe


    C:\Windows\system32\SearchFilterHost.exe


    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896


    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://sympatico.msn.ca/?lang=en-CA


    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.mdg.ca


    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896


    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896


    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157


    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =


    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =


    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =


    O1 - Hosts: ::1 localhost


    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll


    O2 - BHO: Video - {14A6B963-7C6C-414B-B5BD-9CD0929F928F} - C:\Windows\stream32a.dll


    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll


    O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2008\IEToolbar.dll


    O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide


    O4 - HKLM\..\Run: [sigmatelSysTrayApp] sttray.exe


    O4 - HKLM\..\Run: [igfxTray] C:\Windows\system32\igfxtray.exe


    O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe


    O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe


    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"


    O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"


    O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"


    O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"


    O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe


    O4 - HKLM\..\Run: [securDisc] C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe


    O4 - HKLM\..\Run: [inCD] C:\Program Files\Nero\Nero 7\InCD\InCD.exe


    O4 - HKLM\..\Run: [WPCUMI] C:\Windows\system32\WpcUmi.exe


    O4 - HKLM\..\Run: [bDAgent] "C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe"


    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime


    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"


    O4 - HKCU\..\Run: [sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun


    O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter


    O4 - HKCU\..\Run: [sUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe


    O4 - HKUS\S-1-5-19\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')


    O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')


    O4 - HKUS\S-1-5-20\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')


    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE


    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll


    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll


    O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL


    O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll


    O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll


    O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll


    O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll


    O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll


    O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll


    O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll


    O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll


    O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll


    O13 - Gopher Prefix:


    O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/controls/Facebo...toUploader3.cab


    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll


    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe


    O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe


    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe


    O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender S.R.L. - C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe


    O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe


    O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe


    O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe


    O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\Windows\system32\STacSV.exe


    O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S.R.L. - C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe


    O23 - Service: BitDefender Communicator (XCOMM) - BitDefender - C:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe


    --


    End of file - 6940 bytes

  • Dear davem


    You are using an out of date java version please remove the older version by going to control panel,software, remove java runtime environement,reboot your pc. Download and install the newest version. Click on free java update.


    Select the checkboxes that you will find before these entries and press on fix checked confirm the removal question:


    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =


    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =


    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =


    O2 - BHO: Video - {14A6B963-7C6C-414B-B5BD-9CD0929F928F} - C:\Windows\stream32a.dll


    Navigate to the windows folder and see if stream32a.dll is still present if so delete it. It could be hidden so go to the tools menu,folder options,display (view),check show hidden files and folders press on apply.


    Download this registry file. You have to right click on it and use save file as or save link as. Now double click on it and confirm that this entry is being placed in the registry.


    Make a new hijackthis log.


    Best regards


    Niels

  • Niels,


    Thanks for the help. One question, though, when you refer to 'remove java runtime environement', you mean to uninstall it, correct?

  • Dear davem


    Yes, sorry for the confusion.


    Best regards


    Niels

  • Niels,


    I no longer have the issue with the pop-up. Thank-you very much for your help.


    Once I got rid of my version of java, and rebooted, the pop-up no longer appeared. Once my desk top came up, BD alerted me to a trojan it had blocked. It was identified, by BD, as 'Trojan.Agent.AGBL'. I then carried out the remaining intructions, you had provided. I checked off the indicated boxes in the 'hijackthis' log, and clicked on 'fixed checked items'. When I went looking for the 'stream32a.dll' folder it was not present. I have completed the new registry file download, and created a new 'hijackthis' log, which is included below.


    Once again, thanks so much. If there is anything awry, in the new log, please let me know.


    Logfile of Trend Micro HijackThis v2.0.2


    Scan saved at 3:56:13 PM, on 09/12/2007


    Platform: Windows Vista (WinNT 6.00.1904)


    MSIE: Internet Explorer v7.00 (7.00.6000.16546)


    Boot mode: Normal


    Running processes:


    C:\Windows\system32\taskeng.exe


    C:\Windows\system32\Dwm.exe


    C:\Windows\sttray.exe


    C:\Windows\System32\hkcmd.exe


    C:\Windows\System32\igfxpers.exe


    C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe


    C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe


    C:\Program Files\Nero\Nero 7\InCD\InCD.exe


    C:\Windows\System32\wpcumi.exe


    C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe


    C:\Windows\system32\igfxsrvc.exe


    C:\Program Files\iTunes\iTunesHelper.exe


    C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe


    C:\Program Files\Windows Sidebar\sidebar.exe


    C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe


    C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe


    C:\Windows\explorer.exe


    C:\Program Files\Internet Explorer\ieuser.exe


    C:\Program Files\Internet Explorer\iexplore.exe


    C:\Windows\system32\SearchFilterHost.exe


    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe


    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896


    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://sympatico.msn.ca/?lang=en-CA


    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.mdg.ca


    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896


    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896


    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157


    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =


    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =


    O1 - Hosts: ::1 localhost


    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll


    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll


    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll


    O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2008\IEToolbar.dll


    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll


    O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide


    O4 - HKLM\..\Run: [sigmatelSysTrayApp] sttray.exe


    O4 - HKLM\..\Run: [igfxTray] C:\Windows\system32\igfxtray.exe


    O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe


    O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe


    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"


    O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"


    O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"


    O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe


    O4 - HKLM\..\Run: [securDisc] C:\Program Files\Nero\Nero 7\InCD\NBHGui.exe


    O4 - HKLM\..\Run: [inCD] C:\Program Files\Nero\Nero 7\InCD\InCD.exe


    O4 - HKLM\..\Run: [WPCUMI] C:\Windows\system32\WpcUmi.exe


    O4 - HKLM\..\Run: [bDAgent] "C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe"


    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime


    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"


    O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"


    O4 - HKCU\..\Run: [sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun


    O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter


    O4 - HKCU\..\Run: [sUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe


    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe


    O4 - HKUS\S-1-5-19\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')


    O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')


    O4 - HKUS\S-1-5-20\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')


    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE


    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll


    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll


    O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL


    O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll


    O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll


    O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll


    O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll


    O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll


    O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll


    O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll


    O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll


    O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll


    O13 - Gopher Prefix:


    O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/controls/Facebo...toUploader3.cab


    O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl-esd.sun.com/update/1.6.0/jin...ows-i586-jc.cab


    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll


    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe


    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe


    O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe


    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe


    O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender S.R.L. - C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe


    O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe


    O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe


    O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe


    O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\Windows\system32\STacSV.exe


    O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S.R.L. - C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe


    O23 - Service: BitDefender Communicator (XCOMM) - BitDefender - C:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe


    --


    End of file - 7459 bytes

  • Dear davem


    Your log is clean. Perform a deep scan with BitDefender but normally your computer didn't get infected because BitDefender blocked it. Glad that I could help you. To be sure that it isn't hidden go to the tools menu,folder options,display (view),check show hidden files and folders press on apply.


    Best regards


    Niels

  • Hello davem,


    It might be a good idea to run a specialized tool to clean IE Defender and Win32.agent.akk. Here are some instructions: http://www.geekstogo.com/forum/How-to-remo...kk-t179227.html


    Cris.