Trojan horse Dropper Small.4.AG

Discussion in 'Trojan Defence Suite' started by DavidD, Apr 12, 2004.

Thread Status:
Not open for further replies.
  1. kyllaine

    kyllaine Registered Member

    Joined:
    May 17, 2004
    Posts:
    2

    ***hi!r u using the avg free edition? also,did avg clean both trojan horses found on ur pc?thanks! :)
     
  2. kyllaine

    kyllaine Registered Member

    Joined:
    May 17, 2004
    Posts:
    2
    hi!what is/are the effects of this trojan horse?im using the avg free edition and my OS is win xp.also,what is a TDS?i had this trojan horse yesterday and the avg cannot heal it..help please?
     
  3. spy1

    spy1 Registered Member

    Joined:
    Dec 29, 2002
    Posts:
    3,139
    Location:
    Clover, SC
    Puzzling. I don't find a definition for that as given even on AVG's site. No Google results for that name, either. Is the name given ( Dropper.Small.4.AG ) spelled and punctuated correctly? Exactly as presented by AVG? Pete
     
  4. Jooske

    Jooske Registered Member

    Joined:
    Feb 12, 2002
    Posts:
    9,713
    Location:
    Netherlands, EU near the sea
    I'm really losing my trail here:
    you guys post in the TDS forum, Trojan Defence Suite, the infection you write about is in the TDS primaries and thus can detect it just fine and you can delete it.
    But to be sure find your infection, zip it and send it to submit@diamondcs.com.au so Gavin can look for you if you might have a new version.
    BUT: when you are going to scan with TDS: first open your AVG GUI and uncheck all scan options, the resident protection everything, you'll see the AVG systray icon grey out and then with your fully updated TDS and all unnecessary programs closed you do your TDS scan.
    For those who write in the TDS forum without knowing nor having TDS installed yet get your free evaluation copy at the DiamondCS site
    http://tds.diamondcs.com.au/index.php?page=download
    install, go back to that page to get your last update manually, reboot the system and make sure the AVG is closed (and other scanners you might have) and start TDS, and it's Full system Scan with all scanoptions selected and worm slider on the second page to highest sensitivity.
    If you know about any files AVG did detect and TDS not, please be so kind as to locate those files and (preferable zipped) send them in to submit@diamondcs.com.au , if TDS sees something "suspicious" other then double filename extensions send them to the same address or in the TDS bottom console rightclick the file and press submit (for this you need to have your proper email address in the Configuration upper left)
    When scanning is finished rightclick on one of the finds and save the finds as text, a scandump.txt will popup which you can select and post here for us to look at it.

    See also up in this thread the urgent question to PLEASE go to the HijackThis forum to post your log there, as is exactly explained in that place how to do it.
    Hope this helps; looking forward to your postings.
     
  5. Luke18

    Luke18 Registered Member

    Joined:
    May 24, 2004
    Posts:
    15
    My Trojan horse Dropper.Small.4.AG is nested in my C:\System Volume Information

    AVG and Norton cannot pick it up during full system scans, neither can TDS.
    I posted a HiJack This thread.

    Nothing appears to be working.
     
  6. Jooske

    Jooske Registered Member

    Joined:
    Feb 12, 2002
    Posts:
    9,713
    Location:
    Netherlands, EU near the sea
    If you scan:
    open the AVG console uncheck all scan options so it is really closed completely.
    now open norton and close that all completely, so none of the two has a resident protection running either.
    Now you can scan with TDS.
    If TDS is not actively scanning you can leave that up if you start your scan with ONE of the other scanners and that one you close if you scan with the other. Only one of those two can be set for resident protection.
    If TDS detects that individual file in your system restore, guess a file like _a123456.exe, send it to the lab with a rightclick on it before you delete it.

    Now you say it's in your system-restore -- only there? for something in the system restore must have been or is also somewhere else on your system --
    just disable system restore, reboot enable system restore and make manually a new restore point and all the older points have gone. Complete with your infection.
    Make it a ruleif you cleaned out infections in future to do this again or that system restore puts the infections back each time.
    Wished the windows creators had thought of possibilities to have system restores cleansed out as well, but that was not yet in their concept, for the current situation keeps bringing users into the same trouble over and over again completely unnecessary.
    Anyway, after this clean restore operation post your hijackthis log please!
     
  7. dvk01

    dvk01 Global Moderator

    Joined:
    Oct 9, 2003
    Posts:
    3,131
    Location:
    Loughton, Essex. UK
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.