two types of dropper virus and others.

Discussion in 'Malware Help (A Specialist Will Reply)' started by callmetmax, Jan 14, 2008.

  1. callmetmax

    callmetmax Private E-2

    dropper.agent virus found and others

    Hi yesterday 1/13/08 I contracted some type of virus or trojan. The problems it is making is that when mozilla is open I.E. creates popups. also, whenever i run avg then restart my computer i am not able to open the program again. I also can't get proper access to some windows files. I am currently running my computer in the normal startup mode. AVG found dropper.agent.dgo. But wasn't able to erase it. I am going to attach my combofix report, avg one, and mgtools. Thank you so much for the help.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Re: dropper.agent virus found and others

    Please use add/remove programs to uninstall:
    Java 2 Runtime Environment, SE v1.4.2_03
    Viewpoint Manager (Remove Only)"
    Viewpoint Media Player

    Reboot and install:
    Java Runtime 6

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now download The Avenger by Swandog469, and save it to your Desktop.

    * Extract avenger.exe from the Zip file and save it to your desktop
    * Run avenger.exe by double-clicking on it.
    * Check the 'Input script manually' box.
    * Click on the magnifying glass icon.
    * Copy everything in the Quote box below, and paste it in the box that opens:

    * Now click the 'Done' button.
    * Click on the traffic light icon and OK the prompt.
    * You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.
     
  3. callmetmax

    callmetmax Private E-2

    Re: dropper.agent virus found and others

    Ok thanks so much for the response. I will do all that you say. Will i still be able to receive help if i do that a little later and post the results because I have to run to class. If i cant do that i can miss class and take care of it now. thanks
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Re: dropper.agent virus found and others

    Do it when you can ...we'll be here. :)
     
  5. callmetmax

    callmetmax Private E-2

    Re: dropper.agent virus found and others

    alright i got some more time than i thought ill get to work on it. thanks
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Re: dropper.agent virus found and others

    No problem.....:)
     
  7. callmetmax

    callmetmax Private E-2

    Re: dropper.agent virus found and others

    Ok so i did it and here are the attached files. I looked at the avenger one and there is nothing on it although im pretty sure i did everything right.
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Re: dropper.agent virus found and others

    Apparently Avenger did not run correctly ...please try it again and make sure you do everything in the instructions I gave you.
     
  9. callmetmax

    callmetmax Private E-2

    Re: dropper.agent virus found and others

    alright i ran avenger again and it worked. here are the attachments
     

    Attached Files:

  10. callmetmax

    callmetmax Private E-2

    Re: dropper.agent virus found and others

    were you able to take a look at my results? thanks for the help
     
  11. callmetmax

    callmetmax Private E-2

    Re: dropper.agent virus found and others

    so i did what you told me to do and attached the logs in an earlier post. Some things are still not working. I ran avg anti-virus and it found dropper.agent.git. Im not sure if this is a whole new thing or not. Let me know if you need me to post anymore logs thanks.
     
  12. callmetmax

    callmetmax Private E-2

    So i ran a scan on avg anti-spyware and it came up with dropper.agent.dio and avg anti-virus found another type of one. I had a little help yesterday from a diffferent thread and it didnt clear everything. If someone can take a look at my logs and help it would be much appreciated.
     

    Attached Files:

  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Re: dropper.agent virus found and others

    Post me the log from AVG ---> I'd like to see where it is reporting it. Also you could attach the single log for ShowNew after running MGTools.exe, as the last log was empty.
     
  14. callmetmax

    callmetmax Private E-2

    Re: dropper.agent virus found and others

    im not sure what you mean about what i am supposed to post form mgtools. Do you want me to run it again and post the whole log?
     
  15. callmetmax

    callmetmax Private E-2

    Re: dropper.agent virus found and others

    here is my mgtools log and i also posted the avg and avg anti-spyware logs for the last tests i ran. Actually i tried to upload the spyware and mglogs one but it said it was already attached in this thread
     

    Attached Files:

  16. callmetmax

    callmetmax Private E-2

    Re: dropper.agent virus found and others

    i just ran mgtools again so it would let me post the results. Sorry if i am posting too much and seeming impatient im just afraid my computer is going to re ruined
     

    Attached Files:

  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You need to keep your replies in the same thread!

    Why did you run AVG and not have it fix the issues it found?

    What exactly is "still not working"?

    I'm not seeing any malware.....what issues are you still having?
     
  18. callmetmax

    callmetmax Private E-2

    i think everything is working fine now that i restarted a few times. i was having problems with windows saying it wasnt a valid copy but those seem to work. I did have avg fix the problems although that report might not have showed it. The only thing i can see right away is that my function keys are not working. like pressing the volume from the front of my dell. Maybe that was from something i turned off when setting up for the malware removal. Other than that though i think everything is good. Ill let you know if something else pops up. thanks
     
  19. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Not a problem ...let us know ...in the meantime:
    If you are not having any other malware problems, it is time to do our final steps:

    1. If we used Pocket Killbox during your cleanup, do the below
    * Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, C:\combofix.txt and C:\ComboFix-quarantined-files.txt logs that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    9. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    10. If you are running Windows XP or Windows ME, do the below:
    * Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
    * Then reboot and Enable System Restore to create a new clean Restore Point.
    11. After doing the above, you should work thru the below link:
    * How to Protect yourself from malware!
     
  20. callmetmax

    callmetmax Private E-2

    It seems as though my computer is running malware free. But i have a few questions. It seems as though some of my settings got changed and I don't know how to bring them back. When I use the function keys it seems as some of them work as in changing volume, brightness, etc. However there is no figure on the screen that shows up and gives me the level. Like the volume meter. Was there something we did in the process that got that erased. Also the battery life of my laptop icon doesnt show up in my taskbar so i dont know how much is left. Also is it normal that a lot of my visual settings change after i start in safe mode then go back to normal mode. Thanks for the help again
     
  21. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Right click the taskbar / properties / customize / ...check the items and the settings (hide/never hide/etc.)

    You should post in software as to keeping your settings after booting into safe mode...:)
     
  22. callmetmax

    callmetmax Private E-2

    i did that but all those icons are not there anymore. Also do you know anything about my function keys not displaying? does it have something to do with me having uninstalled viewpoint manager?
     
  23. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Nothing to do with viewpoint manager ...are you also missing icons on the desktop?
     
  24. callmetmax

    callmetmax Private E-2

    no nothing is missing from my desktop. Icons that i notice are missing is the battery life one when not plugged in. The icon that shows me wireless status and networks. For the wireless thing it was different than the one that shows windows wireless configurations, but i dont know where the icon is. And then my function key bars don't show
     
  25. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Do you have an F key lock on the keyboard?

    When you right click the wireless connection / properties / do you have the checkbox to show the connection?

    Perhaps you should post in the software section, as this is not a malware issue.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds