PDA

View Full Version : Trojan-Downloader.Agent.OGP


bchickens
03-06-2009, 09:38 PM
Everytime i removed the virus, upon reboot it is back without fail. I have cleared out the startup in programs as well as in the registry. But if I reboot the pc its back. If i start my pc plugged into a network i can only get it to work in safe mode (50% of the time it works in safe plugged in) otherwise it blue screens with a failure uvsync.sys
. If i boot it with the network card unplugged and then plug it in, once I get an IP i blue screen.

Any thoughts?


Virus is: Trojan-Downloader.Agent.OGP
ERROR: uvsync.sys blue screen and constant reboots

Oh and i have updated my virus scanner yesterday, seems to remove it but it just keeps coming back. After a few removals i end up having to revert to last known good configuration or it just keeps rebooting before I even get to the windows login screen.


Oh and the registry entry it makes is under:
Hkey_users\s-1-5-21-1248999094-226332432-1197758776-500
software
microsoft
windows
currentversion
Explorer
idstrf with a value of 1-1C99EA54037711C

And one i remove this everything wont work... cept for if i goto last known config..

GoneToPlaid
03-07-2009, 04:31 AM
Have you tried booting into Safe Mode and then using SD to remove this virus?

haapy
03-07-2009, 05:02 AM
Go for the big fix. Do is a systematic cleanup. This will take a lot of scan time, but it is worth it.

Clean the restore points.

Manually create a new restore point
%SystemRoot%\system32\restore\rstrui.exe

Go to Disk Cleanup
%SystemRoot%\system32\cleanmgr.exe

and choose options , delete all but the current restore point.

Download, install and update Avira free edition antivirus. If you have some other AV program, temporarily disable it.

Download, install and update Superantispyware.

Download, install and update Malwarebytes Antimalware.

Temporarily disable Spyware Doctor.

Run the Restore point procedure previously mentioned.

Download, install nxd run CCleaner files and registry.

Run Avira scan.

Run Malwarebytes full scan.

Run Superantispyware full scan.

Uninstall or disable the realtime protection of Superantispyware (it has real time protection that may conflict with SD).

If you have another AV program, uninstall or disable real time protection of Avira and scan with the other AV program (you never want mor than one AV program running).

Enable SD, update and run a full scan.

If this does not clean up your system, then you have some really bad malware and it will take a lot more time to research and find out what it is.

When you are all done, you should have only SD and the AV of your choice in the Information Tray.