AGP440.sys file infected

Discussion in 'Malware Help (A Specialist Will Reply)' started by LaurelC, Feb 6, 2010.

  1. LaurelC

    LaurelC Private E-2

    HI,

    I am trying to fix my daughter's computers. She has various issues, Unfortunately, I have another daughter who THINKS she 'knows about computers' who has been 'helping' her.

    I think I'm good except for the AGP440.sys file. Combofix found it but I don't know what to DO about it.

    Would you check all the log files and let me know if you find anything else?

    Thanks,
    Laurel
     

    Attached Files:

  2. LaurelC

    LaurelC Private E-2

    Here's the MGTools zip file
     

    Attached Files:

  3. LaurelC

    LaurelC Private E-2

    P.S. I don't have an initial problem with THIS computer, however, I'm trying to clean up the puters for my daughter's bridal shop before she reopens in a new location. Did all the scans and they looked good to ME except for the AGP440.sys file.

    Installed COMODO firewall and AV after all the scans.
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please use windows explorer to find and delete:
    c:\windows\Ghufulazexizu.dat

    Now, download OTL to your desktop.
    * Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    * When the window appears, underneath Output at the top change it to Minimal Output.
    * Copy and paste the following in the Custom/Scans and fixes box.

    AGP440.sys

    Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.

    * When the scan completes, it will open two notepad windows. OTListIt.Txt and Extras.Txt. These are saved in the same location as OTL.
    * Please attach these files.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  5. LaurelC

    LaurelC Private E-2

    OK, here they are! Sorry it took so long!

    Did I say thank you? If not, THANK YOU!

    Cheers,
    Laurel
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please go to start / run / and type:
    services.msc

    When that opens, scroll down to AGP440 and tell me what it is set to ( ie: Auto, Manual, etc.).
     
  7. LaurelC

    LaurelC Private E-2

    uummmmm....don't get mad at me, but I think I might have mixed up the scans for two different puters about half way through this thread! I'm gonna start over and try to keep them straight this time.

    SOOOOOOOO sorry! :-o
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    That is why we want separate threads for separate computers. :(
     
  9. LaurelC

    LaurelC Private E-2

    Oh, I understand. BELIEVE me, I understand! I just got them confused when my daughter moved them around. :confused

    God bless her little heart!
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Where do we stand at this point?
     
  11. LaurelC

    LaurelC Private E-2

    I'm starting over with all three machines. Now that they're permanently where they will STAY and I have recorded the machine names, etc, I will post each set of logs to a different thread and go from there.

    I have been working on this in the evenings after I leave work, but then my daughters get back on the machines the next day and no telling WHAT they're doing, so I plan to go either this Sunday or next and spend the whole day getting everthing resolved.

    Have I thanked you for your geekiness? ;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds