Identified virus by AVG Free Edition

Discussion in 'Malware Help (A Specialist Will Reply)' started by Jud149, Oct 16, 2007.

  1. Jud149

    Jud149 First Sergeant

    Last week my Comodo Firewall indicated that my PC ID info was at risk as something had accessed my computer thru an open port. I ran AVG anti-virus
    (free edition) which found "Trojan Horse Genereic5.VIN. This was stored in their Virus Vault. Just today the same thing happened regarding the Comodo Firewall message and AVG found and located the same Trojan Horse. I'd appreciate some input on this if anyone can help. (XP Pro, SP2)
     
  2. Jud149

    Jud149 First Sergeant

    P.S. The 2 trojans have been deleted from the AVG Virus Vault.
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    So are you saying you have no more problems now?

    If your problems keep reoccurring, you should follow the steps below.


    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, renaming, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.
    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
      • CounterSpy - only for Windows XP, 2K, & NT users
      • AVG Antispyware log - ONLY IF NEEDED you were not able to run CounterSpy. - only for Windows XP, 2K, & NT users
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • runkeys.txt - the log from GetRunKey.bat
      • newfiles.txt - the log from ShowNew.bat
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  4. Jud149

    Jud149 First Sergeant

    Yes, my PC seems to be running fine. I was/am just concerned about this same Trojan appearing twice. I'm set up, BTW, as you have outlined in "How To Protect Yourself From Malware" and have never had any problems with my system (year old last August) since doing so. One question regarding your "Read me First" writeup and that pertains to startup. After changing the startup mode to normal, I assume you go back to selective startup after running AVG anti-virus, etc.; correct? Thanks much for your help, Chas. Hopefully I won't have to bother you again.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No! We do not recommend this. MSconfig is a temporary debugging tool. Why do you need to be in selective startup mode?
     
  6. Jud149

    Jud149 First Sergeant

    Well, I have 21 potential items in here to startup, but I only need 6. I thought that was the idea to have as few as possible "startup". Do the other 15 need to be deleted from the possible startup items? If so, how do I do this? As I'm sure you know, when I change to normal startup, all items here will "startup". One other thing, what do you mean about msconfig being a temp debugging tool?
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    How to deal with startup processes.
    • First you should uninstall any software that you do not use.
    • Second if you have processes still trying to load at startup even though you have uninstalled them. You can simple use HijackThis to easily remove the startup. That way you will not have to manually edit the registry.
    • Third for software you do not want to uninstall but you don't want it to load at startup, look in the program for an option not to load when Windows starts and disable it this way. If you cannot find an option like that you have two possible actions:
      • if you never want it to load at startup, use HJT to permanently remove the startup.
      • if you sometimes want it to load at startup, use a program like Startup CPL to enable or disable as you see fit.
    It means exactly what it says. It should only be used to control startups, services, etc as a temporary solution while debugging problems. And after problems have been debugged, you should be in normal startup mode.
     
  8. Jud149

    Jud149 First Sergeant

    In attempting to clean up the starting process, I have gotten virtually nowhere other than deleting 1 program. I tried to get my Quicken file off the list but ended up actually adding another component of this program. In going to HJT file, I only saw 1 entry indicating "startup" and that was for AVG which I want running. Another program is Sonic which I deleted but is still on the startup list but not in HJT. Anyway, what is the downside to just leaving various programs unchecked so that they won't be running. I think I'm in over my head on this. Thanks again for your help.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It can clutter up you MSconfig registry entries with obsolete information which can slow down startup. Also if you disable things with MSconfig and then later uninstall the program, the uninstall will be incomplete because things are being disabled by MSconfig and they will not be removed. If you then choose Normal Startup, you will have things trying to load and run that cannot run properly because the software has been uninstalled. This is probably why you have the issue you stated with Sonic. I repeat, DO NOT USE msconfig. Use the StartUpCPL program I gave you a link to and use the below program to cleanup things that may have already been messed up by using MSconfig:

    MSConfig Cleanup
     
  10. Jud149

    Jud149 First Sergeant

    I got it now, Chas and I'm in normal startup mode. Thanks again. Jud
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Are you actually working thru the READ & RUN ME or are you just trying to figure our what to do about startup processes?
     
    Last edited: Oct 18, 2007
  12. Jud149

    Jud149 First Sergeant

    Yes, I've worked thru that write up. Actually, that is how this MSConfig problem started when I asked you about returning to "selective mode" after running malware removal in "normal mode" as I wasn't clear on that. Anyway, I think my system is ok now and hope that trojan doesn't return. AS mentioned, I am setup according to your "How to Protect" writeup and have been for sometime.
    :)
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    So you don't feel you need to attach any logs? Also all your problems are resolved?

    If that is true, then we are finished. ;)
     
  14. Jud149

    Jud149 First Sergeant


    Attached is my HJT log: BTW, how often do you suggest running CCleaner for temp files and registry?
     

    Attached Files:

  15. abri

    abri MajorGeek

    C:\Documents and Settings\Jud\Desktop\Jud.exe

    Is this HijackThis? If so, it's in the wrong location and won't give the right information.

    You have an old version of Java installed which needs to be uninstalled via add/remove programs as per the instructions in Step 6a of the READ & RUN ME. All old versions of Java need to be uninstalled via add/remove programs. Since you don't seem to have the current version installed, you need to REBOOT your computer after uninstalling the old ones and then you need to click on the link in Step 6a to download the updated version.

    If you want continued help, please post all the requested logs run and installed from the right locations and in the right order.

    Thanks.
    abri
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    As Abri stated, if you do wish us to check your PC for malware, you must complete ALL of the steps in the READ ME and you must attach ALL of the logs. HijackThis is the last thing with need and by itself HijackThis logs are not that useful in determining malware status. That is why it is the last thing we want/need.

    Weekly for cleaning Temp files. More frequently if you do lots of surfing. I don't recommend using the Issues tab at all on any schedule. It is not normally necessary.
     
  17. Jud149

    Jud149 First Sergeant

    Thanks for all the help, Chas. Since my system seems to be okay speedwise as well as otherwise, I think I'll skip sending any logs, at least for now.
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds