Skip Links

Network World

  • Social Web 
  • Email 
  • Close

Malwarebytes finds pesky Trojan

By Mark Gibbs , Network World , 01/07/2009
Gibbs
Newsletter Signup
  • Share/Email
  • Tweet This
  • Comment
  • Print

In the last Gearhead column of 2008 I discussed the weird behavior of one of my desktop machines.

This machine, running Windows XP Professional SP2, insisted on launching a windowless instance of Internet Explorer 7 that was, in turn, loading Flash content that I could hear but not see. The obvious conclusion was that some kind of malware was responsible, but what was it?

I had tried a few antimalware products (PrevX CSI, AVG Anti-Spyware, and AdAware) as well as attempted to pick the system apart using SysInternals Process Explorer to find the source of the weirdness, but all to no avail.

I asked for suggestions and, wow, did y'all come through! One of the first suggestions was from reader Mike Wolfe, who wrote, "There was a really nasty virus (actually five) on a friend's computer and I was almost down to doing a complete re-image when I finally went to Microsoft Online Malware Scanning, which helped me clear the problems."

This sounded promising so I went to the Microsoft site and, of course, the service won't work with Firefox. OK, so I ran up Explorer 7, allowed it to download the scanner control and let it run . . . for hours. I came back the next morning, the PC had crashed. So I reran the Microsoft scanner, again for hours. And the next morning the PC had crashed again. I'm thinking that this particular Microsoft technology isn't ready for prime time.

The most recommended approach was to use Malwarebytes' Anti-Malware. Reader Joel Dunn was the first to suggest this tool and described it as "a silver bullet."

So, with high hopes, I started Anti-Malware just over three and half hours ago. So far it has examined 358,320 files and found nothing. It's late so I'll leave it running and we'll see if it has found anything in the morning.

Ta-da! It's bright and early and Anti-Malware has finished its run. The full scan took 4 hours, 8 minutes, 16 seconds to examine 483,040 objects (in memory processes as well as DLLs and other disk files) and it found one infected memory process, one infected registry data item and two infected files.

The culprit was something identified by Anti-Malware as Trojan.Agent, but here's the odd thing -- I can't find a good description of what this thing actually does. Malwarebytes doesn't provide any useful details, and other companies seem to disagree on what the Trojan does and how it works. Of course, there's no guarantee that these various antimalware vendors are referring to the same piece of code as there is no identification method or naming scheme that all antimalware vendors agree on.

  • Share/Email
  • Tweet This
  • Comment
  • Print
Comments (2)
Login
Forgot your account info?

Okay I am a bit paranoidBy Whitemist on February 3, 2009, 12:02 pmMy home computer I use 2 separate firewalls which require me to allow programs to access the internet. They also give me location and address of those programs....

Reply | Read entire comment

You don't Have to Reformat But Be Prepared for More WorkBy MarkG on January 22, 2009, 10:00 pmA family member had a similar issue. As a quasi-security professional I wasn't surprised at the programming skill the bad guys used on the family PC or on yours....

Reply | Read entire comment

View all comments

Add comment
Anonymous comments subject to approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed