AVG found virus, but.....

Discussion in 'Software' started by JoeN, Jul 14, 2004.

  1. JoeN

    JoeN Corporal

    Need some help here - Frantic call from Sister-inlaw yesterday - computer not working very good - drive 20 miles to see if I can help: 6 mo. old Dell Desktop, XP Home Ed., 256 MB ram, high speed cable (Road Runner), problem - computer running extremley slow and LOTS of Pop-ups, 1st thing I notice is NO working AV program and NO working Firewall, removed outdated AV and Firewall and installed Sygate and AVG, ran scan with AVG - it found 9 viruses, could fix all but one, said it could not be removed from its present location, Virus name - "trojan horse backdoor.afcore.bn", location - "c:\windows\system32\wiaswrvc.dll", let this problem go for right then and installed Spybot S&D, ran that and found 100's of bits of spyware, cleaned as many as I could but started to get error message when I selected "fix selected problems" that stated I needed to reinstall "wdengine.dll" and "msjava.dll", I stopped there and decided to reboot - after computer rebooted AVG"s Resident Shield showed that the above virus needed to be removed - at that point when I tried to do ANYTHING with the computer it would crash and I got a blue screen stating ALL physcial memory was gone, contact Tech help - computer can be booted in safe mode, I found the suspect file but was not sure if I should or could remove it safely - my niece who is the primary user of the computer is 14 yrs. old and who knows WHAT she has been doing on this machine - a starting place and direction to go in would be greatly appericated !!!!!!!!!!!!
     
  2. Just Playin

    Just Playin MajorGeek

    Go to the FAQ section at the topof this forum (here is the link: http://forums.majorgeeks.com/forumdisplay.php?f=33 ). Read them, There are valuable tips on how to ask for help,dealing with viruses and spyware, and more. For this, you will get more help in the spyware specific forum.
     
  3. JoeN

    JoeN Corporal

    My main problem is a VIRUS issue, the Virus Forum says "Read Only", that is why I posted here - I'm just looking for a little help -
     
  4. goldfish

    goldfish Lt. Sushi.DC

    Ugh this is why I hate HJT logs : http://www.google.co.uk/search?hl=en&ie=UTF-8&q=afcore.bn&btnG=Search&meta=

    Ok. According to Symantec it doesnt exist, but according to Sophos...
    http://www.sophos.com/search/index.cgi?scope=whole_site&lang=english&terms=afcore.bn&x=10&y=9
    There are several variats of this virus it seems..
    http://www.sophos.com/virusinfo/analyses/trojafcoreaj.html <- thats your type... I think.

    Another variant : http://www.viruslist.com/eng/viruslist.html?id=169606
    More info : http://secunia.com/virus_information/10519/afcore-aj/
    Yet more : http://www.emsisoft.com/en/malware/?Backdoor.Afcore.i

    Seems like a squared should get rid of it. But I'm too tired to find the link. *zonks*
     
  5. JoeN

    JoeN Corporal

    Thanks, I'll let you know how I make out
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  7. JoeN

    JoeN Corporal

    Can't tell you how much I and I'm sure all of us seeking help appericate the support found here on MG - had no problems at all using the info offered to correct ALL problems with my Niece's computer -
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds