.funkyblue { color:#0000AF; }
I have previous posted about the Windows threat ‘Trojan.downloader.uj’ and that I have build a removal help tool for it.
I think it would be best for all if I post here some removal steps for this special threat which is really tricky, since it is a trojan but uses userland rootkit techniques.
Here are the steps:
Or you can try Grisoft AVG Anti-Rootkit Beta 1.0.0.13, but be careful it is a beta!
Thats’s all the threat should be removed now.
Aliases for this threat are:
| Antivirus | Alias |
| AntiVir | TR/Dldr.Agent.uj.1 |
| Authentium | W32/Downloader.LTB |
| Avast | Win32:Agent-IU |
| AVG | Downloader.Agent.BAH |
| BitDefender | Trojan.Downloader.FFZ |
| CAT-QuickHeal | TrojanDownloader.Agent.uj |
| ClamAV | Trojan.Downloader.Agent-262 |
| DrWeb | Trojan.DownLoader.4316 |
| eTrust-InoculateIT | Win32/SillyDL.51200!Trojan |
| eTrust-Vet | Win32/Alureon.Y |
| Ewido | Downloader.Agent.uj |
| Fortinet | RuinDl.G!tr |
| F-Prot | security risk named W32/Downloader.LTB |
| F-Prot4 | W32/Downloader.LTB |
| Ikarus | Trojan-Downloader.Win32.Agent.uj |
| Kaspersky | Trojan-Downloader.Win32.Agent.uj |
| McAfee | Downloader-ASI |
| Microsoft | TrojanDownloader:Win32/Agent.RR |
| NOD32v2 | a variant of Win32/Small.FB |
| Norman | W32/DLoader.NNL |
| Panda | Trj/Ruins.MB |
| Sophos | Troj/RuinDl-G |
| Symantec | Downloader |
| TheHacker | Trojan/Downloader.Agent.uj |
| UNA | TrojanDownloader.Win32.Agent.68D6 |
| VBA32 | Trojan.DownLoader.4316 |
I hope this is helpful.
Regards,
Vinzenz Feenstra
August 15th, 2006 at 8:43 am
Dude, I had that P.O.S trojan on my computer for four weeks and couldn’t get that mo-fo out.
Your little programme got rid of it in the first try.
Hah, burn you little trojan rooters!!! Burn!!
So….. thanks a lot !!!!!!!!!!!!!
August 24th, 2006 at 10:20 pm
Hey-
I did what you said. Now I have trojan.small.fb not able to be deleted, and I still have trojan.downloader.uj being found. Now what?
August 29th, 2006 at 11:30 pm
Same thing. I had uj now I also have small.fb.
Once in safe mode I cannot even launch ewido. Ewido does not appear to be able to run in safe mode.
I can get all the others to run in safe mode (like AVG, Spybot, etc.) but Ewido will not work in safe mode.
Anyone else have this same problem, or do you have no problem getting Ewido to run in safe mode?
Thanks a lot.
Jeff
September 29th, 2006 at 9:53 pm
On rebooting i ran ewido and my system just froze !!
This happened on 2 more occasions and finally after rebooting the third time i removed dmlaj.exe from my startup and uninstalled ewido too .. now i dunno what to do ..
October 1st, 2006 at 12:59 pm
It worked fine for me!
Many thanks, Vinzenz.
November 5th, 2006 at 11:47 pm
Thanks Guys, this post really help i was finally able to remove this nasty downloader.agent.uj
November 27th, 2006 at 5:31 pm
hey dude thanks for the post.. i had a hard time deleting this Downloader.Agent.uj. but after downloading rmdlagentuj.exe,
and ran ewido again its gone.problem solved
December 16th, 2006 at 1:49 pm
Thanks mate, this did the trick - Great!
December 28th, 2006 at 9:59 pm
cheers fior the link, had all sorts of trouble getting my virus protecter to delete it, then with this it got rid of all viruses
January 9th, 2007 at 1:46 pm
Hardstikke bedankt, die pest Trojaan is nu eindelijk foetsie…pffffffff…leuke blog
thanks a lot, the bl…trojan had finally disappeared, cool site man…
Sory for the 2 languages; guess Feenstra was quite Dutch(Fries/Frisian)…lol..if not, my apologies
January 13th, 2007 at 6:44 pm
WARNING: removing the trojan this way will screw up your OS defenitively….it did it with mine W2K…
January 14th, 2007 at 8:16 pm
@Peter van Dijk:
I have W2K aswell (SP4). Didn’t hose my OS in any way.
January 15th, 2007 at 4:09 pm
Just wanted to say Thank you so much. I use AVG and never had an issue. Your trick did it!
Thank you!
February 13th, 2007 at 3:47 am
I wanted to tell you that your file worked. Downloader.Agent.uj is GONE! My machine is also faster.
Thanks!!!
February 28th, 2007 at 8:39 am
Thanks from Croatia, I try and try, and there virus write in ntdlr
Thanhs for program
March 8th, 2007 at 7:06 am
Help I tried the above instructions and it doesn’t work for me, I got something like “Trojan-Downloader.Win32.Agent variant” what can i do?!
March 9th, 2007 at 2:29 am
Same thing i got a Trojan-Downloader.Win32.Agent variant..and i dont know what it is
April 14th, 2007 at 10:35 pm
Your program did not delete Downloader.Agent.uj No message came up to say reboot. What do I do next. Have AVG 7.5 ,XP pack 2 ,AMD64 Athalon
August 13th, 2007 at 8:36 pm
i’ve been using avg but it will not remove this trojan.it sees it
and removes it every time i run a scan but it may copy itself or something
because every scan i run it’s back again even after 3 seconds of a scan.
help please!!!