Vinzenz Feenstra’s WebLog

August 7, 2006

How to remove Trojan.Downloader.uj

by @ 3:23 pm. Filed under News, Downloads, Articles, Security, Tutorials

I have previous posted about the Windows threat ‘Trojan.downloader.uj’ and that I have build a removal help tool for it.

I think it would be best for all if I post here some removal steps for this special threat which is really tricky, since it is a trojan but uses userland rootkit techniques.

Here are the steps:

  1. Download the file "rmdlagentuj.exe" from following location: http://fileserver.ewido.net/public.cgi?id=20845
  2. Execute the file "rmdlagentuj.exe" if it was successful you will get a message dialog where you will be asked to reboot
  3. Reboot your computer (Important!)
  4. Execute a complete system scan with ewido anti-spyware 4.0 ( http://www.ewido.net )

Or you can try Grisoft AVG Anti-Rootkit Beta 1.0.0.13, but be careful it is a beta!
Thats’s all the threat should be removed now.


Aliases for this threat are:

Antivirus Alias
AntiVir TR/Dldr.Agent.uj.1
Authentium W32/Downloader.LTB
Avast Win32:Agent-IU
AVG Downloader.Agent.BAH
BitDefender Trojan.Downloader.FFZ
CAT-QuickHeal TrojanDownloader.Agent.uj
ClamAV Trojan.Downloader.Agent-262
DrWeb Trojan.DownLoader.4316
eTrust-InoculateIT Win32/SillyDL.51200!Trojan
eTrust-Vet Win32/Alureon.Y
Ewido Downloader.Agent.uj
Fortinet RuinDl.G!tr
F-Prot security risk named W32/Downloader.LTB
F-Prot4 W32/Downloader.LTB
Ikarus Trojan-Downloader.Win32.Agent.uj
Kaspersky Trojan-Downloader.Win32.Agent.uj
McAfee Downloader-ASI
Microsoft TrojanDownloader:Win32/Agent.RR
NOD32v2 a variant of Win32/Small.FB
Norman W32/DLoader.NNL
Panda Trj/Ruins.MB
Sophos Troj/RuinDl-G
Symantec Downloader
TheHacker Trojan/Downloader.Agent.uj
UNA TrojanDownloader.Win32.Agent.68D6
VBA32 Trojan.DownLoader.4316

I hope this is helpful.

Regards,

Vinzenz Feenstra



Tags: , , , , , , ,

19 Responses to “How to remove Trojan.Downloader.uj”

  1. irish dave Says:

    Dude, I had that P.O.S trojan on my computer for four weeks and couldn’t get that mo-fo out.

    Your little programme got rid of it in the first try.

    Hah, burn you little trojan rooters!!! Burn!!

    So….. thanks a lot !!!!!!!!!!!!!

  2. Rod Says:

    Hey-
    I did what you said. Now I have trojan.small.fb not able to be deleted, and I still have trojan.downloader.uj being found. Now what?

  3. Jeff Says:

    Same thing. I had uj now I also have small.fb.

    Once in safe mode I cannot even launch ewido. Ewido does not appear to be able to run in safe mode.

    I can get all the others to run in safe mode (like AVG, Spybot, etc.) but Ewido will not work in safe mode.

    Anyone else have this same problem, or do you have no problem getting Ewido to run in safe mode?

    Thanks a lot.

    Jeff

  4. Alston Says:

    On rebooting i ran ewido and my system just froze !!

    This happened on 2 more occasions and finally after rebooting the third time i removed dmlaj.exe from my startup and uninstalled ewido too .. now i dunno what to do ..

  5. Mario Says:

    It worked fine for me!

    Many thanks, Vinzenz.

  6. steven Says:

    Thanks Guys, this post really help i was finally able to remove this nasty downloader.agent.uj

  7. bert Says:

    hey dude thanks for the post.. i had a hard time deleting this Downloader.Agent.uj. but after downloading rmdlagentuj.exe,
    and ran ewido again its gone.problem solved :)

  8. Jayne Says:

    Thanks mate, this did the trick - Great!

  9. lee Says:

    cheers fior the link, had all sorts of trouble getting my virus protecter to delete it, then with this it got rid of all viruses

  10. Peter van Dijk Says:

    Hardstikke bedankt, die pest Trojaan is nu eindelijk foetsie…pffffffff…leuke blog

    thanks a lot, the bl…trojan had finally disappeared, cool site man…

    Sory for the 2 languages; guess Feenstra was quite Dutch(Fries/Frisian)…lol..if not, my apologies

  11. Peter van Dijk Says:

    WARNING: removing the trojan this way will screw up your OS defenitively….it did it with mine W2K…

  12. Demodus Says:

    @Peter van Dijk:

    I have W2K aswell (SP4). Didn’t hose my OS in any way.

  13. Kendra Says:

    Just wanted to say Thank you so much. I use AVG and never had an issue. Your trick did it!
    Thank you!

  14. David Says:

    I wanted to tell you that your file worked. Downloader.Agent.uj is GONE! My machine is also faster.
    Thanks!!!

  15. Thanks from Croatia Says:

    Thanks from Croatia, I try and try, and there virus write in ntdlr :)

    Thanhs for program :)

  16. Confused Says:

    Help I tried the above instructions and it doesn’t work for me, I got something like “Trojan-Downloader.Win32.Agent variant” what can i do?!

  17. joe Says:

    Same thing i got a Trojan-Downloader.Win32.Agent variant..and i dont know what it is

  18. Terry Armstrong Says:

    Your program did not delete Downloader.Agent.uj No message came up to say reboot. What do I do next. Have AVG 7.5 ,XP pack 2 ,AMD64 Athalon

  19. jason rosenberger Says:

    i’ve been using avg but it will not remove this trojan.it sees it
    and removes it every time i run a scan but it may copy itself or something
    because every scan i run it’s back again even after 3 seconds of a scan.
    help please!!!

Leave a Reply

archives:

August 2006
M T W T F S S
« Jul   Oct »
 123456
78910111213
14151617181920
21222324252627
28293031  

internal links:

categories:

Search

other:

Advertisement