AVG reports multiple Win32/Heur, Trojan Horse Dropper Generic4, and more

Discussion in 'Malware Help (A Specialist Will Reply)' started by minorgeek2001, May 1, 2013.

  1. minorgeek2001

    minorgeek2001 Private E-2

    Hi everybody,

    I am a new usr here, my level of expertise would be moderate I guess.

    This PC is a part of small home LAN (3PCs) with a pwd protected router and NAT. It is a XP PRO 32 bit system on Intel P4 mobo with 2Gb RAM, and all the Windows updates (incl. SP3), a default windows firewall is on, (a NAT hardware firewall in router is secured by pwd and encryption. No hardware issues reported by Device Mgr. Recently I added to this PC 2 HDDs from old PC of my son. Then my troubles started.

    PC started suddenly crawling, even when I closed all but one instance of windows explorer, or killed all the unnecessary processes. "Darn, we are infected"... (I disconnected this PC from LAN but noticed a slow down on another PC, which I powered down).

    AVG free reported a Win32/Heur in several copies on one of additional HDDs (non system drive i.e.) in a hidden "_restore" folder with a long number. I tried AVG to remove it, and it reported success, but subsequent scans revealed that the same virus comes back and shows in different locations on two of non system HDDs on this PC.

    After I used Malware Bytes I got more different viruses reported, about 6 of them, including Generic horse Dropper 4.

    Following google hints I made D and E:\_restore{...} folders visible and allowed AVG to delete them both. It reported success but next AVG scan revealed 10 different viruses in different locations on both data drives, and infected hidden "_restore" folders were back.

    Each time I run AVG free it finds around 10 threats and some six warnings about broken certificates, and offers to clean all, but next scan shows some of the same and often new ones back. If I do nothing and allow infections to multiply (approx. each hour AVG resident shield reports another one found) the number of copies of threats stops at about 10-16 infections of several different viruses, and does not progress further. It all stays on data drives so far.

    At this point I contacted this forum and downloaded software as per "readme first" instructions. I have followed the steps for Malware removal. I turned off AVG (disabled until the reboot) and run scans as per instructions.

    Rogue killer reported 1 totally different virus on C drive and offered to clean it, which I did not proceed with as per instructions.

    Malwarebytes - (I used my existing program) did not find anything this time.

    MGtools started in DOS shell but stopped at second item of the script (GetRunKey.bat) with a comment below "Just wait for the program to finish running" and blinking cursor below (no C prompt or "done" or whatever report... I waited 48 hrs checking occasionally if the log file has been generated (but found only these that I zipped together here). It looks like the batch script did not finish.

    Any suggestion would be greatly appreciated, as I have to learn how to clean all the LAN. Thank You in advance.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    What about the log fromTDSSKiller? Also run the below.

    Please download OTL by OldTimer.
    • Save it to your desktop.
    • Double click on the OTL icon on your desktop. (If running Vista, Win7, or Win8 right-click and select Run as Administrator)
    • Check the "Scan All Users" checkbox.
    • Check the "Standard Output".
    • Change the setting of "Drivers" and "Services" to "All"
    • Copy the text in the code box below and paste it into the Customs Scans/Fixes text-field.
      Code:
      activex
      netsvcs
      drives
      /md5start
      afd.sys
      atapi.sys
      csrss.exe
      dhcpcsvc.dll
      explorer.exe
      lsass.exe
      nsiproxy.sys
      regedit.exe
      services.exe
      svchost.exe
      tcpip.sys
      tdx.sys
      userinit.exe
      winlogon.exe
      /md5stop
      %systemdrive%\*.*
      %systemdrive%\MGtools\*.*
      %systemroot%\*. /mp /s
      %systemroot%\system32\*.sys /90
      %systemroot%\system32\*.exe /lockedfiles
      %systemroot%\system32\drivers\*.sys /lockedfiles
      
    • Now click the Run Scan button.
    • Two reports will be created:
      • OTL.txt <-- Will be opened
      • Extra.txt <-- Will be minimized
    • Attach both OTL.txt and Extras.txt to your next message. (See how to attach)
     
  3. minorgeek2001

    minorgeek2001 Private E-2

    Thank You for helping. Sorry I for missed TDSSkiller report. It did not save this one itself, so I simply copied it to a txt file manually. I also provided an earlier AVG report with some of threats it found. I am not sure if all of them are real, or some might be a positive false, but PC is going through very obvious now infection manifested by frequent disappearing of objects on the interface like icons and opened windows (a background shows through), suddenly loosing its opacity and content, which I can get back only after minimizing and restoring them. Thanks again for helping me.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  5. minorgeek2001

    minorgeek2001 Private E-2

    I have no idea how I missed this one, I was pretty sure I uploaded all of them including OTL.txt and extras.txt. I apologize. I was sure I saw them in uploaded list, but obviously I was mistaken. It won't happen again. Here is OTL.txt
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Still missing. Check the messages when uploading. It may be telling you it is too large or some other error. If too large, put it into a ZIP file and attach it.
     
  7. minorgeek2001

    minorgeek2001 Private E-2

    Thanks... yup it was over the allowed upload limit... I could not see it for some reason (I possibly looked for comments below the window and this one was above, once I resized the window to a larger one I saw the system comment. Thank You again.
     

    Attached Files:

    • OTL.zip
      File size:
      46.7 KB
      Views:
      3
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. The only potential problems seen in your logs are the things that AVG and Malwarebytes pointed out. It is from download illegal software or cracks for software.
     
  9. minorgeek2001

    minorgeek2001 Private E-2

    If I understood you correctly there seems to be no infection on the system drive. If so, then would it be safe to format both data drives? Or should it be just deleted, and if so, is there any particular way of doing so to avoid spreading infection onto the system disk? Or is the only way out of it now to dump both HDDs?
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Correct.

    It is always safe to format but you probably don't need to. You just need to stop downloading cracks and delete everything in the below folder which is where AVG and Malwarebytes found problems.

    D:\data\__ftp\_software\programs

    If you delete everything there and then toggle system restore off and then back on, your detections should all be gone unless you have more of these kinds of files in another folder.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds