Author Topic: win32:Agent-QJ  (Read 2708 times)

0 Members and 1 Guest are viewing this topic.

weedynes

  • Guest
win32:Agent-QJ
« on: July 31, 2006, 08:33:16 AM »
Had this trojan that kept spawning itself every time I rebooted and went on line. Avast did the right thing a dleted it but it unfortunately did not kill the source that was somewhere on my machine.
Found that going online caused a file to suddenly appear in root - "drsmartload.exe" and this in turn downloaded "ddsmart.exe" also in root.
The Hijackthis printout showed up an executable file called "winrestores.exe" (from Windows\system32 folder). And this seemed to bring up unusual "Microsoft Telecoms Center" items in my Hijackthis printout after each Spyware Doctor entry.
After much searching around found the culprit to be:
HKEY_LOCAL_USER\Software\Microsoft\drsmartload
I deleted this folder and successfully (so far) have stopped this pest re-occurring each time I go online.

Online DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89089
  • No support PMs thanks
Re: win32:Agent-QJ
« Reply #1 on: July 31, 2006, 02:36:35 PM »
Files need some help (permissions) to be able to be placed into the system folders and to create registry entries.

Whilst browsing or collecting email, etc. if you get infected then the malware by default inherits the same permissions that you have for your user account. So if the user account has administrator rights, the malware has administrator rights and can reap havoc. With limited rights the malware can't put files in the system folders, create registry entries, etc. This greatly reduces the potential harm that can be done by an undetected or first day virus, etc.

Check out the link to DropMyRights (in my signature below) - Browsing the Web and Reading E-mail Safely as an Administrator. This obviously applies to those NT based OSes that have administrator settings, winNT, win2k, winXP.

Also to be able to download other stuff it would need to get past any firewall outbound checks for unauthorised connections. Do you have a firewall and if so what ?
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33908
  • malware fighter
Re: win32:Agent-QJ
« Reply #2 on: July 31, 2006, 04:10:28 PM »
Hi weedynes,

Here is a nice cleansing routine:
http://www.castlecops.com/print-1-160099.html

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!