Author Topic: Problems with Win32:Agent-HKL [Trj] (Totour.exe)  (Read 4299 times)

0 Members and 1 Guest are viewing this topic.

flrobert

  • Guest
Problems with Win32:Agent-HKL [Trj] (Totour.exe)
« on: July 03, 2007, 10:27:37 AM »
Hello,

I've been having problems with that Trojan that avast recognizes but can't eradicate. I've tried several ideas I found on the web but it's still there. SuperAntispyware recognizes it as Trojan.spam-Rucrzy but can't get rid of it. I've tried to boot in safe mode and erase the c:\cd1041.nls file created by the Trojan but doesn't work. I've also tried to replace the infected ndis.sys by a clean version but without any success. Any help or ideas would be welcome.

thanks!!

flrobert

Offline FreewheelinFrank

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 4871
  • I'm a GNU
    • Don't Surf in the Nude!
Re: Problems with Win32:Agent-HKL [Trj] (Totour.exe)
« Reply #1 on: July 03, 2007, 10:49:05 AM »
Hi flrobert,

Have you tried a boot time scan with avast!? (Right click the scanner screen, select 'schedule a boot time scan' and reboot when requested.)

Have you tried AVG Anti-Spyware Free?

If still having problems, post a HijackThis! log.

     Bambleweeny 57 sub-meson brain     Don't Surf in the Nude Blog

Offline FreewheelinFrank

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 4871
  • I'm a GNU
    • Don't Surf in the Nude!
     Bambleweeny 57 sub-meson brain     Don't Surf in the Nude Blog

Offline FreewheelinFrank

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 4871
  • I'm a GNU
    • Don't Surf in the Nude!
Re: Problems with Win32:Agent-HKL [Trj] (Totour.exe)
« Reply #3 on: July 03, 2007, 11:36:02 AM »
I suspect that it may be the ability of SDFix to deal with rootkits (hidden malware) that enables it to remove this infection, so you could also try these anti-rootkit scanners:

Panda Antirootkit
Blacklight
AVG Anti-Rootkit
     Bambleweeny 57 sub-meson brain     Don't Surf in the Nude Blog

flrobert

  • Guest
Re: Problems with Win32:Agent-HKL [Trj] (Totour.exe)
« Reply #4 on: July 03, 2007, 02:36:29 PM »
Avast with boot time scan didn't work, however SDFix seems to have solved the problem. Thank you very much for your help and for replying so quickly to my request. I still don't understand very well how this totour.exe manages to behave the way it does. I'd be interested to learn more about it. You guys call it a rootkit, is that right? Merci again!

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67183
Re: Problems with Win32:Agent-HKL [Trj] (Totour.exe)
« Reply #5 on: July 03, 2007, 02:44:49 PM »
Avast with boot time scan didn't work
Do you mean didn't detect or avast did not work? Do you need further help?

You guys call it a rootkit, is that right? Merci again!
Yeah.
The best things in life are free.

Offline FreewheelinFrank

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 4871
  • I'm a GNU
    • Don't Surf in the Nude!
Re: Problems with Win32:Agent-HKL [Trj] (Totour.exe)
« Reply #6 on: July 03, 2007, 03:38:11 PM »
Quote
I still don't understand very well how this totour.exe manages to behave the way it does.

There may be a clue here:

Quote
I bet there's something in the registry that instructs explorer to download totour.exe at first connection availability.

http://forums.pcpitstop.com/index.php?showtopic=137078
     Bambleweeny 57 sub-meson brain     Don't Surf in the Nude Blog

Offline FreewheelinFrank

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 4871
  • I'm a GNU
    • Don't Surf in the Nude!
Re: Problems with Win32:Agent-HKL [Trj] (Totour.exe)
« Reply #7 on: July 03, 2007, 03:49:11 PM »
If you haven't got one already, a third-party firewall can help you control what has access to the internet and may prevent an infection downloading more malware onto your computer:

http://www.geocities.com/dontsurfinthenude/rec_firewalls.htm
     Bambleweeny 57 sub-meson brain     Don't Surf in the Nude Blog