Trojan/agent-GAU please help

Discussion in 'Windows - Virus and spyware problems' started by Noobling, Oct 15, 2007.

  1. Noobling

    Noobling Member

    Joined:
    Jun 25, 2007
    Messages:
    15
    Likes Received:
    0
    Trophy Points:
    11
    I ran Spysweeper and found this virus/trojan but cannot remove it.Spybot and Avg did NOT pick this up.How on earth am i going to remove this please help
    Many thanks.
     
  2. svtstang

    svtstang Regular member

    Joined:
    Apr 23, 2006
    Messages:
    4,564
    Likes Received:
    0
    Trophy Points:
    46
    Post a HJT log and I will see what the deal is.
     
  3. Noobling

    Noobling Member

    Joined:
    Jun 25, 2007
    Messages:
    15
    Likes Received:
    0
    Trophy Points:
    11
    This log is from spysweeper will this do?
    20:02: Informational: Virus infected file c:\office 2007\msoe2007kg.exe not cleaned.
    20:02: Quarantining All Traces: Troj/Agent-GAU
    20:02: Quarantining All Traces: questionmarket cookie
    20:02: Quarantining All Traces: adbureau cookie
    20:02: Traces Found: 3
    20:02: Custom Sweep has completed. Elapsed time 00:04:19
    20:02: File Sweep Complete, Elapsed Time: 00:00:55
    Trace marked as Always Remove
    20:02: C:\Office 2007\msoe2007kg.exe (ID = 0)
    20:02: Threat marked as Always Remove
    20:02: Found Troj/Agent-GAU: Troj/Agent-GAU
    20:01: Warning: AntiVirus engine for IFO returned [Access Denied] on [c:\pagefile.sys]
    20:01: Starting File Sweep
    20:01: Cookie Sweep Complete, Elapsed Time: 00:00:00
    Trace marked as Always Remove
    20:01: c:\documents and settings\robert\cookies\robert@questionmarket[2].txt (ID = 3217)
    20:01: Threat marked as Always Remove
    20:01: Found Spy Cookie: questionmarket cookie
    Trace marked as Always Remove
    20:01: c:\documents and settings\robert\cookies\robert@divx.adbureau[2].txt (ID = 2060)
    20:01: Threat marked as Always Remove
    20:01: Found Spy Cookie: adbureau cookie
    20:01: Starting Cookie Sweep
    20:01: Registry Sweep Complete, Elapsed Time:00:00:12
    20:01: Starting Registry Sweep
    20:01: Memory Sweep Complete, Elapsed Time: 00:03:03
    19:58: Starting Memory Sweep
    19:58: Start Custom Sweep
    19:58: Sweep initiated using definitions version 1010
    Keylogger: Off
    19:57: Informational: ShieldEmail: Start monitoring port 25 for mail activities
    E-mail Attachment: On
    19:57: Informational: ShieldEmail: Start monitoring port 110 for mail activities
    BHO Shield: On
    IE Security Shield: On
    Alternate Data Stream (ADS) Execution Shield: On
    Startup Shield: On
    Common Ad Sites: Off
    Hosts File Shield: On
    Internet Communication Shield: On
    ActiveX Shield: On
    Windows Messenger Service Shield: On
    IE Favorites Shield: On
    File System Shield: On
    Execution Shield: On
    System Services Shield: On
    IE Hijack Shield: On
    IE Tracking Cookies Shield: Off
    19:57: Shield States
    19:57: License Check Status (0): Success
    19:57: Spyware Definitions: 1010
    19:57: Informational: Loaded AntiVirus Engine: 2.49.1; SDK Version: 4.21E; Virus Definitions: 16/10/2007 05:34:06 (GMT)
    19:56: Spy Sweeper 5.5.7.48 started
    19:56: Spy Sweeper 5.5.7.48 started
    19:56: | Start of Session, 16 October 2007
     
  4. svtstang

    svtstang Regular member

    Joined:
    Apr 23, 2006
    Messages:
    4,564
    Likes Received:
    0
    Trophy Points:
    46
    Nope I cant do anything with that, Post a HJT log (click HJT...download it, chose the option to scan and save a log...and post the contents of thel og) and I will be able to see what kind of bad entries you have.
     

Share This Page