AVG says trojan - BackDoor.Generic5.EYF

Discussion in 'Malware Help (A Specialist Will Reply)' started by overdue82, Mar 4, 2007.

  1. overdue82

    overdue82 Private E-2

    I searched google for the exact phrase "BackDoor.Generic5.EYF" and couldn't find anything ending in eyf. Anyone know if AVG will remove it on it's own or do I have to take my own action and if so what will I have to do? This trojan is making me nervous.

    I've attached my hijackthis file but it wasn't done in safe mode since AVG is still running. I'll update with a safe mode copy once AVG finishes. Also, I rarely use Internet Explorer. I use Mozilla Firefox, if you need to know that.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Welcome to Majorgeeks!

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.
    • Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    • Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    • After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:
    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.
    • When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
      • CounterSpy
      • AVG Antispyware log - ONLY IF NEEDED you were not able to run CounterSpy
      • Bitdefender - from step 6
      • Panda Scan - from step 6
      • runkeys.txt - the log from GetRunKey.bat
      • newfiles.txt - the log from ShowNew.bat
      • HijackThis
    NOTE: You can only attach 3 files in a single message so it will require that you use two messages to attach all of these logs!
     
  3. overdue82

    overdue82 Private E-2

    I'm going through the steps, downloading all the programs that I will need, and when I got to the AVG settings listed in the Read & Run Me first thread. I had to stop. I can't find half of the settings you guys want me to use in my AVG program.

    I don't see the "scanner" icon at the top of the screen. Nor, do I see anything that says "Recommended actions" or "Quarantine". Please help. I have no idea where this is at. I'm running AVG 7.5.

    Nevermind, I just realized it was talking about the spyware program not antivirus. I'll just download the free trial of CounterSpy.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The READ & RUN ME instructions are for AVG Antispyware not for AVG Antivirus. Make sure that you did not violate step 3 of the READ ME and install two antivirus programs.
     
  5. overdue82

    overdue82 Private E-2

    Yeah, I edited my post and said that I just noticed it was for antispyware and not antivirus. I downloaded Counter Spy since I don't have AVG AntiSpyware. Is this okay? The only antivirus program I have is AVG.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    CounterSpy is the first one we request. We use AVG AntiSpyware as a backup if you cannot run CounterSpy. So yes, run CounterSpy.
     
  7. overdue82

    overdue82 Private E-2

    Okay, I did all the steps and have all the logs for you.
     

    Attached Files:

  8. overdue82

    overdue82 Private E-2

    Here's the last set of logs. Just so you know I did change the filename of HJT and also put it in the C:\Program Files\HJT folder.
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes you did and we would know that without you telling us. However you got your log from Safe Boot mode which is not what we want. However I don't see any major problmes at this point. Perhaps you should use a legal copy of AVG rather than one obtained from a Torrent download.

    I will post a few things to cleanup in my next message.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Uninstall the Sunbelt CounterSpy trial since we are finished with it now! Then delete the below two folders which may be left behind by the uninstall:
    C:\Documents and Settings\All Users\Application Data\Sunbelt Software
    C:\Program Files\Sunbelt Software

    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 10
    J2SE Runtime Environment 5.0 Update 11
    Mozilla Firefox (1.5)

    Make sure you reboot after uninstalling the above!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Then install the current version of FireFox from: Mozilla Firefox


    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Note for IE 7 users: You need to select Internet Options then the Advanced tab and then Reset Internet Explorer Settings!

    Now reboot in normal mode

    Now attach the below new logs and tell me how the above steps went.
    1. ShowNew
    2. HJT


    Make sure you tell me how things are working now!
     
  11. overdue82

    overdue82 Private E-2

    Sorry it took so long for me to reply. I've been in bed with a cold.

    Anyway, I did all the steps you asked. Uninstall the Counterspy stuff, but I couldn't find the folders to remove them manually. I uninstalled Java and reinstall the updated version and the same with Firefox. Problem I'm having now with Firefox though is that it takes webpages twice as long to load and when they do they do this weird thing. They jumped up. I don't know any other way to explain it. They shake up and down in the Firefox window. It's very annoying.

    Here's the two logs you asked for.
     

    Attached Files:

  12. overdue82

    overdue82 Private E-2

    Also, I just reran Bitdefender to see if it came up with the trojan again and it did. I guess it hasn't been completely erased. Is there anything else I can do to get rid of it?

    Here's the latest bitdefender log.
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This does not sound like malware. It sounds like a problem with the installation. Did you uninstall the old version and reboot as requested before installing new software?

    Uninstall FireFox now. After reboot make sure you have all applications, browsers....etc closed. Then run the install for the the new FireFox.

    Any change?
     
  14. overdue82

    overdue82 Private E-2

    No, there wasn't any change so I searched the Firefox forum and found that a lot of others had the same problem. It had to do with the corrupt localstore.rdf file. That's all fixed now.

    Any idea why the trojan still came up in bitdefender the second time? I'm sure you knew by looking at my logs that I have an extra harddrive as my storage drive. That drive is drive F and the bitdefender log says it also is infected with the trojan.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You are jumping the gun! ;) I did not ask you to run BitDefender again, and we were not done with our final steps. After doing our final steps you will not find those items anymore because they are in System Restore.

    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix you can delete the ComboFix.exe file and associated C:\combofix.txt log that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    5. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    8. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  16. overdue82

    overdue82 Private E-2

    Whoops! :D

    Okay, I did the steps you asked and it seems that everything is running a lot smoothly. Do trojans usually make the hard drive run a lot slower? Because before when I'd sometimes go to open a program I'd get a pop up telling me that the system had insufficient sources to open it and I'd have to restart. Is that what might have caused that problem? This is a brand new hard drive I'm using so I couldn't imagine what else would make it do that.

    Thanks for all your help!
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes they can make things run slower. They can cause all kinds of problems. ;)

    I'm happy to hear things are working better now! Surf safely.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds