Trojan Downloader.Agent.awf -- more?

Discussion in 'Malware Help (A Specialist Will Reply)' started by soem, Sep 3, 2008.

  1. soem

    soem Private E-2

    (This post is for a different computer [my Laptop] than my prior post yesterday.) Logs being attached

    After running the malware removal procedure, the Trojan Downloader.Agent.awf seems to be indicated in one of the MGTools logs I peeked into.

    Starting out, this laptop was in bad shape. It had a bogus screensaver with the message Warning! Spyware detected on your computer! Install an antivirus or spyware remover to clean your computer. Then the bogus screensaver would log me out every 10-15 minutes. And it made 2 of my Display Property Tabs disappear, so I couldn't change the screensaver behavior.

    The SUPERAntiSpyware followed by Spybot combo cleared up those problems -- saying it was Rogue.AntiVirus XP 2008, Trojan.FakeAlert/Desktop, and Rogue.AntiVirus.

    My laptop is usable again, but I don't know if there are more malware indicated in the logs (beyond the Trojan Downloader.Agent.awf that I mentioned earlier). Please review when you can. Thanks.
     

    Attached Files:

  2. soem

    soem Private E-2

    Last file from the Malware Removal procedure is attached.
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you haven't already, please disable the Guest account in User accounts.

    Run this: Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it. (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    Now tell me what these are:
    C:\Documents and Settings\David Scott\Desktop\STOPVirusImage
    C:\FightV
    C:\MayBeVirus
    C:\SaveSDAT

    If you didn't put them there ---> remove them!

    Now tell me how things are running.
     
  4. soem

    soem Private E-2

    Thank-you very much. Its nice to have my laptop back usable again.

    I was able to complete successfully your follow-up instructions.

    Yes, I put all 4 items you asked about there myself.

    The laptop is running fine. No slowdowns or other *visible* malware symptoms that I can detect.

    (Other notes and details are in the file attached)
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The icon is for your connectivity program.....something you put on possibly for windows mobile?

    If you are not having any other malware problems, it is time to do our final steps:
     
  6. soem

    soem Private E-2

    Completed the applicable final steps.
    Details attached.
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your system is xp ....if you are referring to a different computer....start a new thread and follow the instructions for Win 2000.
     
  8. soem

    soem Private E-2

    Thank-you again for all of your help.

    (Yes, the NT is another computer that was on my network. I'll get to cleaning that one sometime later, in a separate thread.)
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are very welcome ...safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds