AVG-cannot repair some trojans?

Discussion in 'Malware Help (A Specialist Will Reply)' started by frontera, Apr 27, 2006.

  1. frontera

    frontera Private E-2

    I scanned my pc with AVG free edition...it found some files infected with trojans...but it says it cannot heal the files...do I have other option or I have to delet them...some of files are like "32s.exe"(infected with Bobax.AA), drev.exe(infected with trojan horse dowloader generic) and A0031692.exe (infected with worm/Bobax.AA).....
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sounds like they may be in System Restore. Disable System Restore and then run your AVG scan. Then re-enable System Restore. The below explains how to toggle system restore:

    Disable And Enable System Restore
     
  3. frontera

    frontera Private E-2

    thank you chaslang. I'll do it. do you think that this way AVG will fix those files?
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes! Things that are in System Restore cannot not be fixed. The only way to remove them is to remove the restore points by disabling system restore. This is all assuming that my assumption was correct about your problems being in system restore. You did not give the full path of the files. I just assume it was in System Volume Information based soley on the file name you gave.
     
  5. frontera

    frontera Private E-2

    Hi chaslang. I stopped system restore, I scanned with AVG again and the viruses are still there, IO mean the files are still infected and the software says they cannot be healed. are there other software on MGeeks that would do only trojans horse removal?I think I saw somwthing like this on "antivirus" section....
    for more details of my problem ckeck below, this is the info given at the end of scanning:

    1.file: winapi32.exe
    infection:trojan horse generic
    path:c:\api39exe:\winapi32.exe

    2.file:winapi64.exe
    infection:trojan horse proxy.ATG
    path:c:\api39exe:\winapi64.exe

    3. file A0031692.exe
    infection: worm/Bobax.AA
    path: c:\system volume information\_restore

    thank you again
    frontera
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    One of them is in System Restore! Are you sure System Restore is disabled?
    At this point it would be best if you work thru standard cleaning procedures. You may have several problems!

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too (these scans are covered in steps 6 & 7 of the READ & RUN ME sticky)
      • Bitdefender
      • Panda Scan
      • HijackThis
    .
    .
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds