Rogue.Dropper/Gen

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by ForeverYoung, Aug 25, 2008.

  1. ForeverYoung

    ForeverYoung Private E-2

    I have a windows xp

    I'm in the process of downloading the tools on the Read & Run first section to try & clean out the Rogue.Dropper/Gen. I ran the Super antispyware as soon as I noticed a problem but apparently didn't run it correctly according to the instructions :confused

    Anyways, I did run accross a Rogue remover on this website, would that be useful for the Rogue.Dropper/Gen?

    Also, while doing the read & run first, is everything done in safe mode? Although the SuperAntiSpyware supposively caught the Rogue.Dropper/Gen, it still did'nt help much because I still am having problems with my display properties & a blue background screen
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just run the READ & RUN ME.

    No! Nothings is done in safe mode except for running CCleaner on the Administrator account which is normally only available in safe mode.
     
  3. ForeverYoung

    ForeverYoung Private E-2

    Had Rogue.Dropper/Gen

    Not sure if everything is OK or not so I am hoping someone could take a look just to make sure, I'm not sure if I am uploading the files right either. Thanks!
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Re: Had Rogue.Dropper/Gen

    Please stay in one thread and attach ALL of the logs from the READ & RUN ME. Do not manipulate the text files as you did with SUPERAntiSpyware. Attach the original logs.

    I'm merging this thread back to your other thread.
     
  5. ForeverYoung

    ForeverYoung Private E-2

    Re: Had Rogue.Dropper/Gen

    Here are the other ones
     

    Attached Files:

  6. ForeverYoung

    ForeverYoung Private E-2

    umm then I'm not sure how to upload the files
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do not load them into whatever editor you are loading them into (possibly Wordpad). You are changing them from being regular text files. Just upload the logs that were created by SAS, MBAM and ComboFix exactly as they are saved by the programs.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you are not sure how to find the logs, they are listed below directly from your MGlogs.zip file.;) I highlighted in bold the ones you should attach. Since you ran SAS more than once, I want to see the last two logs.
    Code:
    "C:\Documents and Settings\ox inst\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Logs\"
    [B]su31a2~1.log  Aug 25 2008        1430  "SUPERAntiSpyware Scan Log - 08-25-2008 - 01-33-30.log"
    [/B]su3724~1.log  Aug 15 2008         463  "SUPERAntiSpyware Scan Log - 08-15-2008 - 21-35-23.log"
    sub0ea~1.log  Jul 22 2008         463  "SUPERAntiSpyware Scan Log - 07-22-2008 - 12-33-50.log"
    sub43e~1.log  Aug  6 2008         463  "SUPERAntiSpyware Scan Log - 08-06-2008 - 20-33-06.log"
    sub822~1.log  Jun 25 2008        3268  "SUPERAntiSpyware Scan Log - 06-25-2008 - 22-47-23.log"
    [B]sub8f4~1.log  Aug 25 2008         628  "SUPERAntiSpyware Scan Log - 08-25-2008 - 10-37-26.log"
    [/B]subda7~1.log  Aug 24 2008         560  "SUPERAntiSpyware Scan Log - 08-24-2008 - 00-06-14.log"
    supera~1.log  Jun 19 2008         706  "SUPERAntiSpyware Scan Log - 06-19-2008 - 13-47-49.log"
    supera~2.log  Jun 19 2008        1284  "SUPERAntiSpyware Scan Log - 06-19-2008 - 18-01-39.log"
    supera~3.log  Jun 25 2008        3493  "SUPERAntiSpyware Scan Log - 06-25-2008 - 17-50-02.log"
    supera~4.log  Jun 25 2008         454  "SUPERAntiSpyware Scan Log - 06-25-2008 - 19-49-14.log"
    "C:\Documents and Settings\ox inst\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\"
    [B]mbam-l~1.txt  Aug 25 2008       11813  "mbam-log-08-25-2008 (13-11-36).txt"[/B]
    
    "C:\"
    [B]combofix.txt  Aug 25 2008       11663  "ComboFix.txt"[/B] 
     
  9. ForeverYoung

    ForeverYoung Private E-2

    Ok, My brain hurts now. :-D The zip file is on C drive which I can find, but could you please tell me step by step how to do what you want me to do? I'm so sorry, but I am really lost here trying to figure out how to attach the files you need. I thought a simple copy & paste to notepad would of worked. I know how to attach files, it's just getting to the files you need is what is so confusing. Wow, & I thought I knew alot about computers.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just use the Browse button on the Manage Attachments window and browse to and select the below files:

    First browse to the below folder and attach the two bold print files.

    C:\Documents and Settings\ox inst\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\Logs
    SUPERAntiSpyware Scan Log - 08-25-2008 - 01-33-30.log
    SUPERAntiSpyware Scan Log - 08-25-2008 - 10-37-26.log

    Now browse to the below folder and attach the bold print file.

    C:\Documents and Settings\ox inst\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs
    mbam-log-08-25-2008 (13-11-36).txt

    Now start a new message since you can only attach 3 logs in a single message. Then go to the Manage Attachments window and simply enter the below file name to the left of one of the Browse buttons and then click Upload.

    C:\ComboFix.txt

    You don't need to browse since this is short and easy enough to just type in.

    The problem with the previous file is that you are editing them by loading them into WordPad and they are no longer valid text files and are more difficult to read. You should not be manipulating the text logs at all.
     
    Last edited: Aug 26, 2008
  11. ForeverYoung

    ForeverYoung Private E-2

    Yay! I believe I did it! :)
     

    Attached Files:

  12. ForeverYoung

    ForeverYoung Private E-2

    Thanks! You are such a great help!
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes now you got it! ;)


    Uninstall the below software:
    Java 2 Runtime Environment, SE v1.4.2_03
    Java(TM) 6 Update 5
    Viewpoint Media Player <-- should have been uninstalled in step 1 of the READ ME

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.co.uk/myway
    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
    O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER

    After clicking Fix, exit HJT.

    Now reboot your PC.


    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below log:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  14. ForeverYoung

    ForeverYoung Private E-2

    Everything seems to be working great now. when I ran Hijack this, I didn't see O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe", though. I also got a success message when I added to the registry.
     

    Attached Files:

  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your logs are clean.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significan amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  16. ForeverYoung

    ForeverYoung Private E-2

    Thanks so much! you've worked wonders for my sick computer:wave
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds