dropper.agent.dgo need major help!!!

Discussion in 'Malware Help (A Specialist Will Reply)' started by chinny, Jan 30, 2008.

  1. chinny

    chinny Private E-2

    hey!

    i am new to the site but i do know that other people on here have sufferd from this malware. I have read the other threads and have done the 'hijack this' part and have got the logs. i just need to know which ones to delete or if there is any more steps.... any help would be great!

    cheers
    chinny!
     

    Attached Files:

  2. abri

    abri MajorGeek

    Hi chinny!
    Welcome to Major Geeks!

    If you read the other threads, then you'll know we require more than HijackThis. HijackThis is a great tool, but it's simply not adequate to remove most viruses. Please go ahead and work through the instructions in the READ & RUN ME FIRST so we can look at the information we need to help you. There will be three (possibly only 2 logs) when you finish which you can then attach to your next post.

    Thanks.
    abri
     
  3. chinny

    chinny Private E-2

    hey!

    sorry for not getting back sooner.
    I hope these are the logs that you wanted.
    having some trouble getting the AVG reports to save, they only seem to save for certain scans... so i have the latest report from AVG but it might not be accurate to my current position.

    cheers
    Chinny!
     

    Attached Files:

  4. abri

    abri MajorGeek

    Hi Chinny,

    I would like for you to start by running CCleaner in the default setting with the Windows tab as the one on top. Then continue as follows:

    1) Download a new tool we will need.
    • Download and save to RenV.exe to your Desktop (must be on the Desktop)
    • Now Copy the bold text in the below code box to notepad. Save it as Log.txt to your desktop. (It must be on your Desktop).
    Code:
    C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc .exe
    C:\Program Files\Hewlett-Packard\Default Settings\cpqset .exe
    C:\Program Files\HP\HP Software Update\HPWuSchd2 .exe
    C:\Program Files\HP\QuickPlay\QPService .exe
    C:\Program Files\HPQ\HP Wireless Assistant\HP Wireless Assistant .exe
    C:\Program Files\iTunes\iTunesHelper .exe
    C:\Program Files\Java\jre1.6.0_04\bin\jusched .exe
    C:\Program Files\Lexmark 1200 Series\lxczbmgr .exe
    C:\Program Files\MSN Messenger\MsnMsgr .Exe
    C:\Program Files\Spyware Doctor\pctsTray .exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh .exe
    C:\WINDOWS\CREATOR\Remind_XP .exe
    C:\WINDOWS\ehome\ehtray .exe
    C:\WINDOWS\SMINST\RecGuard .exe
    C:\WINDOWS\system32\ctfmon .exe
    C:\WINDOWS\system32\hkcmd .exe
    C:\WINDOWS\system32\igfxpers .exe
    C:\WINDOWS\system32\igfxtray .exe
    • Now using your mouse, drag Log.txt onto RenV.exe
    • When finished, RenV.exe will produce a new log names Log.txt on your Desktop I may or may not ask for this log later.
    2) Download and install Erunt. Use it to create a backup of your registry.

    3) Please copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    4) Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    5) Please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.
    • Double-click ATF-Cleaner.exe to run the program.
    • Under Main choose: Select All
    • Click the Empty Selected button.
    If you use Firefox browser
    • Click Firefox at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    If you use Opera browser
    • Click Opera at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    Click Exit on the Main ATF Cleaner menu to close the program.


    6) Please run C:\MGtools\GetLogs.bat and attach the fresh MGlogs.zip it generates along with the Avenger log.


    Let me know how things are running now?

    abri
     
  5. abri

    abri MajorGeek

    Hi Chinny,

    I would like for you to start by running CCleaner in the default setting with the Windows tab as the one on top. Then continue as follows:

    1) Download a new tool we will need.
    • Download and save to RenV.exe to your Desktop (must be on the Desktop)
    • Now Copy the bold text in the below code box to notepad. Save it as Log.txt to your desktop. (It must be on your Desktop).
    Code:
    C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc .exe
    C:\Program Files\Hewlett-Packard\Default Settings\cpqset .exe
    C:\Program Files\HP\HP Software Update\HPWuSchd2 .exe
    C:\Program Files\HP\QuickPlay\QPService .exe
    C:\Program Files\HPQ\HP Wireless Assistant\HP Wireless Assistant .exe
    C:\Program Files\iTunes\iTunesHelper .exe
    C:\Program Files\Java\jre1.6.0_04\bin\jusched .exe
    C:\Program Files\Lexmark 1200 Series\lxczbmgr .exe
    C:\Program Files\MSN Messenger\MsnMsgr .Exe
    C:\Program Files\Spyware Doctor\pctsTray .exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh .exe
    C:\WINDOWS\CREATOR\Remind_XP .exe
    C:\WINDOWS\ehome\ehtray .exe
    C:\WINDOWS\SMINST\RecGuard .exe
    C:\WINDOWS\system32\ctfmon .exe
    C:\WINDOWS\system32\hkcmd .exe
    C:\WINDOWS\system32\igfxpers .exe
    C:\WINDOWS\system32\igfxtray .exe
    • Now using your mouse, drag Log.txt onto RenV.exe
    • When finished, RenV.exe will produce a new log names Log.txt on your Desktop I may or may not ask for this log later.
    2) Download and install Erunt. Use it to create a backup of your registry.

    3) Please copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    4) Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    5) Please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.
    • Double-click ATF-Cleaner.exe to run the program.
    • Under Main choose: Select All
    • Click the Empty Selected button.
    If you use Firefox browser
    • Click Firefox at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    If you use Opera browser
    • Click Opera at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    Click Exit on the Main ATF Cleaner menu to close the program.


    6) Please run C:\MGtools\GetLogs.bat and attach the fresh MGlogs.zip it generates along with the Avenger log.


    Let me know how things are running now?

    abri
     
  6. chinny

    chinny Private E-2

    hey abri!

    Thanks for all the help, I think my computer is back to normal again!!

    cheers!
    Chinny!
     
  7. abri

    abri MajorGeek

    Thanks chinny!
    To be sure, please post the logs for Avenger and the MGlogs.zip and let me know if you got a success message on the registry patch. It's important with the new Vundo variant to make sure it's gone.

    If your logs are clean, I will post a final set of cleanup instructions for you to take out all the logs and tools etc. that we put on your computer.

    abri
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds