Dropper.Agent.GIT

Discussion in 'Tech' started by Binky, Jan 5, 2008.

  1. Binky

    Binky New Member

    Messages:
    7
    Trophy Points:
    0
    Oh crap. I downloaded a serial so I could test how well SpeedUpMyPC optimizes your computer... So the serial came with a text file and 2 .exes. The text file had the serial in it, and I didn't know what the .exes were for. I accidentally clicked one of them, and nothing happened. Thinking nothing of it, I went to my business. A little bit later, AVG popped up with an alert that a file was infected with Dropper.Agent.GIT, I forget which file, it was avgcc.exe or something. So I clicked heal without really looking at it, thinking it would fix it right away... But then I tried opening another .exe that was ituneshelper.exe, from the iTunes directory. And AVG said it had a virus/trojan, the same Dropper.Agent.GIT as before. So then I got worried. There was another one that popped up that was jkkih.exe, and it was with the same thing. So I rebooted the computer, and it said that it couldn't open this jkkih.exe and stuff. But then it booted as normal, except that the AVG control center didn't open, probably because the control center got infected with the virus... It probably has infected, by how it seems, more files now... Can ANYONE help me!? I'm getting kind of frantic. How can I fix the problem? Please!
  2. j0k3r

    j0k3r El Chupacabra

    Messages:
    2,644
    Trophy Points:
    0
    Location:
    http://localhost/
  3. tweakmonkey

    tweakmonkey Webmaster Staff Member

    Messages:
    7,869
    Trophy Points:
    78
    I second HouseCall, it's a great free app.

    I'd uninstall AVG immediately if it's corrupt. You could also download and re-install it, and run a full scan from Windows Safe Mode, which may fix the virus without causing further headaches.
  4. cured

    cured Tech No0b

    Messages:
    559
    Trophy Points:
    0
    Location:
    Melbourne, Australia
    Never click on .exe's unlesss you know there safe.

    I still havn't come accross a serial website that is clean
  5. mistawiskas

    mistawiskas kik n a and takin names

    Messages:
    30,180
    Trophy Points:
    98
    Location:
    Rogue Valley Oregon
    The last virus to hit the wiskas household was devastating to my wife's system. Killed two HDD's wiped out the backup drive and the cost hasn't even been totally realized yet. She'll DL anything if it says "free" on it. :(
  6. Alacrity

    Alacrity New Member

    Messages:
    4
    Trophy Points:
    0
    I too have recently been hit with this virus. It is a evil one.

    What I have basically discovered is that it (Dropper.Agent.GIT) wrote itself to all the start up .exe including avgcc.exe (AVG Antivirus control panel) and to all the system restore points.

    Once it was up and going and started rewriting the .exes, AVG caught it. I used the heal function, which DELETED the files!!! So now all the exes which had been starting up (including AVG) have been deleted. I did not realize it at the time.

    I rebooted into safe mode, and manually launched AVG and ran a scan. It found 30 files... again I tried to heal them. AVG claims they were healed. I then tried to find the files and to my aggravation realized that they had been deleted and then to my horror realized that they were my restore points.

    I plan to go back into Safe Mode and rescan and use a few other programs (Spybot, Ad Aware, Counter Spy) and see if I can get rid of the damn thing then I guess I will have to manually reinstall ALL the old startup exe.

    Alacrity
  7. tweakmonkey

    tweakmonkey Webmaster Staff Member

    Messages:
    7,869
    Trophy Points:
    78
    Most the stuff run at startup isn't very critical - unless you're talking about system files. If it's something you can remove using msconfig.exe, it's probably safe and you'll be able to boot at least and worry about what it was later. The same goes for HiJackThis but you'd best off removing just the BHO type if you're worried about it.

    That sucks AVG deleted instead of cleaned the files. Did it quarantine them or delete them outright?

    Spy Sweeper could probably clean it up without a problem, but I'd try Spybot and Ad-Aware if you don't have a copy.
  8. j0k3r

    j0k3r El Chupacabra

    Messages:
    2,644
    Trophy Points:
    0
    Location:
    http://localhost/
    After you are done, run sfc.exe /scannow. It will ask you for your Windows XP CD and it will replace any Windows files that have become deleted. Then of course visit Windows Update. Stay away from t3h w4r3z kiddies!!
  9. MSP

    MSP Haunting a dead forum...

    Messages:
    29,575
    Trophy Points:
    78
    When I'm downloading warez I'll scan all of it before I touch a thing. But I don't download much of that these days...
  10. Alacrity

    Alacrity New Member

    Messages:
    4
    Trophy Points:
    0
    AVG deleted the files... most were general startup exes but that included the laptops soundcard and wireless drivers...
    I have Spybot and Ad Aware and they will definitely be run... it just sux that it shutdown AVG on reboot and killed the .exe for AVG... which means it has to be reinstalled... you think AVG could protect itself...

    Alacrity
  11. Alacrity

    Alacrity New Member

    Messages:
    4
    Trophy Points:
    0
    FYI, I did scan the .exe that caused all this problem and AVG either missed it or I missed the popup telling me it was a virus...
    Either way... pain the a**
  12. Goofus Maximus

    Goofus Maximus Too old to be this dumb!

    Messages:
    7,158
    Trophy Points:
    78
    Location:
    St. Louis area, but in Illinois
  13. darktides

    darktides Hot stuff tonight

    Messages:
    457
    Trophy Points:
    23
    I got this as well, odd it was on my laptop which has no wares.. I am not sure where it came from but I re-imaged last night and all is well :)
  14. Alacrity

    Alacrity New Member

    Messages:
    4
    Trophy Points:
    0
    Turns out is was vtspp.exe vtspp.dll and wusrpm.dll - VundoFix.exe was able to get it fixed in Safe Mode... now I have to reinstall all the apps it infected. Thank all of you who posted and helped out.

    All ways do a virus scan on ANY files...

    Alacrity
  15. Binky

    Binky New Member

    Messages:
    7
    Trophy Points:
    0
    Ok, doesn't matter anymore. Somehow, maybe it was the virus, I don't know, I can't log in, and I have all my stuff(No infected .exe's, of course) on a couple disks, so I'm just gonna format and reinstall XP.