Author Topic: Win32: Dropper-gen (Drp).dll and.exe  (Read 24593 times)

0 Members and 1 Guest are viewing this topic.

Offline e.harvey

  • Jr. Member
  • **
  • Posts: 66
Win32: Dropper-gen (Drp).dll and.exe
« on: July 23, 2014, 08:02:16 PM »
Couldn't see anything to reply to, so started a new topic. Hope these reports help!   :-\

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37532
  • Not a avast user
Re: Win32: Dropper-gen (Drp).dll and.exe
« Reply #1 on: July 23, 2014, 08:25:50 PM »
You dont say what the problem is?......

The malwarebytes log you attached is the protection log.....we need scan log
« Last Edit: July 23, 2014, 08:31:08 PM by Pondus »

Offline e.harvey

  • Jr. Member
  • **
  • Posts: 66
Re: Win32: Dropper-gen (Drp).dll and.exe
« Reply #2 on: July 23, 2014, 10:03:08 PM »
I wrote a PM to essexboy earlier today and received a reply from his student who asked for scan logs... this is what I wrote...   
"I posted a question last week regarding the Omiga-plus virus I seemed to have on my pc. I followed your instructions - (to install and run farbar recovery tool, Malwarebytes and aswMBR) but I didn't get as far as replying with reports - because I couldn't work out how to reply!!! IE seemed to go back to normal, so I gave up trying to post back to you.
Yesterday, Omiga returned in IE and when I did a scan with aswMBR today, I see I have...
20:31:19.245    File: C:\Users\Elizabeth\AppData\Local\Temp\nsh3749.tmp  **INFECTED** Win32:Dropper-gen [Drp]
20:31:20.290    File: C:\Users\Elizabeth\AppData\Local\Temp\nsz9052.tmp  **INFECTED** Win32:Dropper-gen [Drp] !!!
I also downloaded Combofix today and have scanned with this too."
You can probably tell that I am new here and am a bit confused about how to proceed!

REDACTED

  • Guest
Re: Win32: Dropper-gen (Drp).dll and.exe
« Reply #3 on: July 23, 2014, 11:08:12 PM »
Hi :)

I have responded in your previous thread that I am monitoring it, but you pasted nothing more there. Credits to Essexboy for bringing it to my attention... For future reference, please stick with one thread, as multiple people working on 1 issue may do more harm than good.

Give me some time to assess your situation and I should come back here later today or tomorrow at the latest :)

REDACTED

  • Guest
Re: Win32: Dropper-gen (Drp).dll and.exe
« Reply #4 on: July 23, 2014, 11:21:46 PM »
First - about using ComboFix without supervision of a trained expert:
This tool is not a toy and should be used only if told to do so by a Malware Analyst. Refrain from using it on your own. There were some cases in which CF interefered with a present infection, rendering machine unstable.


Scan with Farbar Recovery Scan Tool

Please download Farbar Recovery Scan Tool x64 and save it to your Desktop.
  • Right-click on icon and select Run as Administrator to start the tool.
    (XP users click run after receipt of Windows Security Warning - Open File).
  • When the tool opens click Yes to disclaimer.
  • Make sure that Addition option is checked.
  • Press Scan button and wait.
  • The tool will produce two logfiles on your desktop: FRST.txt and Addition.txt.
Please attach their content to your next reply.
« Last Edit: July 23, 2014, 11:33:54 PM by Naathim »

Offline e.harvey

  • Jr. Member
  • **
  • Posts: 66
Re: Win32: Dropper-gen (Drp).dll and.exe
« Reply #5 on: July 24, 2014, 09:37:24 AM »
Ok, here is the report... :)

REDACTED

  • Guest
Re: Win32: Dropper-gen (Drp).dll and.exe
« Reply #6 on: July 24, 2014, 09:48:55 AM »
This is only addition.txt report. I'm gonna need also FRST.txt one :)

Offline e.harvey

  • Jr. Member
  • **
  • Posts: 66
Re: Win32: Dropper-gen (Drp).dll and.exe
« Reply #7 on: July 24, 2014, 01:40:03 PM »
Sorry, I hope I have it right this time!

REDACTED

  • Guest
Re: Win32: Dropper-gen (Drp).dll and.exe
« Reply #8 on: July 24, 2014, 05:08:58 PM »
OK, there is some work here.
Multiple steps are listed - be sure to perform them in the order mentioned :)



Deactivate Windows Defender

Please follow the instructions here and temporarily switch-off Windows Defender.
It has to be done before other steps for the purpose of not interfering with the fix.



Fix with Farbar Recovery Scan Tool

This fix was created for this user for use on that particular machine.
Running it on another one may cause damage and render the system unstable.

Press the + R on your keyboard at the same time. Type Notepad and click OK.
  • Copy the entire content of the codebox below and paste into the Notepad document:
Code: [Select]
start
C:\Users\Elizabeth\AppData\Local\globalUpdate
C:\Program Files (x86)\globalUpdate
C:\Users\Elizabeth\AppData\Roaming\Bubble Dock.installation.log
C:\Users\Elizabeth\AppData\Roaming\Nosibay
C:\ProgramData\gogZnId
C:\Users\Elizabeth\Documents\PC Speed Maximizer
C:\Users\Elizabeth\AppData\Roaming\aps.uninstall.scan.results
C:\Program Files (x86)\NetCrawl
C:\Users\Elizabeth\AppData\Roaming\ProductData
C:\ProgramData\IObit
C:\Users\Elizabeth\AppData\Local\Slick Savings
C:\ProgramData\ProductData
C:\ProgramData\{3C5CBD7B-3D1D-411E-96C2-513FFCA84D2D}
C:\Program Files (x86)\IObit
C:\Users\Elizabeth\AppData\Roaming\IObit
C:\Radsteroids
C:\Program Files (x86)\predm
C:\Windows\SysWOW64\${LOGFILE}
C:\Program Files (x86)\CinemaD-V1
C:\Windows\Tasks\ImCleanDisabled
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
CHR HKCU\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
Error reading preferences. Please check "preferences" file for possible corruption. <======= ATTENTION
CHR HKLM-x32\...\Chrome\Extension: [aaaaihhnfnbnpbhpagnmoplpcjbediml] - C:\Users\Elizabeth\AppData\Local\imeshmusicboxtoolbar\GC\toolbar.crx []
C:\Users\Elizabeth\AppData\Local\imeshmusicboxtoolbar
C:\Program Files (x86)\di4BlockAndSurf
FF HKCU\...\Firefox\Extensions: [{0F0F3172-674B-A5D8-B3C3-5EF7C6C92F2F}] - C:\Program Files (x86)\di4BlockAndSurf\175.xpi
BHO-x32: No Name -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} ->  No File
Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} -  No File
Toolbar: HKLM-x32 - No Name - {45177936-603b-4261-8d42-df6f7091d5d0} -  No File
Toolbar: HKCU - No Name - {5733492D-4700-A76A-76A7-7A786E7484D7} -  No File
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
c:\program files (x86)\Common Files\Spigot
ShellIconOverlayIdentifiers: GDriveSharedOverlay -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44} => No File
SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
end
  • Click File, Save As and type fixlist.txt as the File Name.
Both files, FRST and fixlist.txt have to be in the same location or the fix will not work!
  • Right-click on icon and select Run as Administrator to start the tool.
    (XP users click run after receipt of Windows Security Warning - Open File).
  • Press the Fix button just once and wait.
  • If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
  • When finished FRST will generate a log on the Desktop, called Fixlog.txt.
Please include it in your reply.



Clean Temporary Files with TFC

Please download TFC by OldTimer and save it to your desktop.
  • Right-click on icon and select Run as Administrator to start the tool.
  • Close any open programs and save your current work.
  • Click the Start button to begin. Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a couple of minutes.
  • Once it's finished it should reboot your machine. If it does not, please manually reboot the machine yourself to ensure a complete clean.
This tool doesn't generate any report. Instead I recommend to keep it for good maintenance of your machine.



Fix with Junkware Removal Tool

Please download JRT by Thisisu and save the file to your desktop.
Temporary disable your AntiVirus and AntiSpyware protection - instructions here.

  • Right-click on icon and select Run as Administrator to start the tool.
  • Follow the prompts and let this process run uninterrupted.
  • This scan can take a while, depending on your System specs.
  • Upon completion, a log (JRT.txt) will open on your desktop.
Please include the contents of that file in your reply.

Do not forget to re-enable your previously switched off protection software!
Please also manually reboot your machine after this procedure.



Fix with AdwCleaner

Please download AdwCleaner by Xplode and save the file to your desktop.

  • Right-click on icon and select Run as Administrator to start the tool.
  • Follow the prompts and click Scan.
  • When finished, please click Clean.
  • Upon completion, click Report. A log (AdwCleaner[S*].txt) will open.
Please include the contents of that file in your reply.



Scan with Farbar Recovery Scan Tool

Please re-run Farbar Recovery Scan Tool to give me a fresh look at your system.
  • Right-click on icon and select Run as Administrator to start the tool.
    (XP users click run after receipt of Windows Security Warning - Open File).
  • Make sure that Addition option is checked.
  • Press Scan button and wait.
  • The tool will produce two logfiles on your desktop: FRST.txt and Addition.txt.
Please include their content into your next reply.

Offline e.harvey

  • Jr. Member
  • **
  • Posts: 66
Re: Win32: Dropper-gen (Drp).dll and.exe
« Reply #9 on: July 25, 2014, 11:56:15 AM »
Many thanks. Please find 4 reports attached.... :)

Offline e.harvey

  • Jr. Member
  • **
  • Posts: 66
Re: Win32: Dropper-gen (Drp).dll and.exe
« Reply #10 on: July 25, 2014, 11:57:18 AM »
...and here's the last one.... :)

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37532
  • Not a avast user
Re: Win32: Dropper-gen (Drp).dll and.exe
« Reply #11 on: July 25, 2014, 12:01:09 PM »
wow .... you had an enormous amount of crap programs! ...... computer must run like new now?


Offline e.harvey

  • Jr. Member
  • **
  • Posts: 66
Re: Win32: Dropper-gen (Drp).dll and.exe
« Reply #12 on: July 25, 2014, 12:10:45 PM »
Haha - I am not surprised! ;D
Does this mean my pc should be clean? Because I am still having problems with IE!
When I click on the icon - I get a blank page apart from the toolbars. When I open a new page - I still have the option to open the dreaded omega-plus home page!?
Is there still work to do?

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37532
  • Not a avast user
Re: Win32: Dropper-gen (Drp).dll and.exe
« Reply #13 on: July 25, 2014, 12:14:05 PM »
Naathim is the one working your case, he will be back ..... and when done he will remove all the tools used    ;)


Offline e.harvey

  • Jr. Member
  • **
  • Posts: 66
Re: Win32: Dropper-gen (Drp).dll and.exe
« Reply #14 on: July 25, 2014, 12:16:07 PM »
Ok, many thanks