Avira PE classic found Gen trojan

Discussion in 'Malware Help (A Specialist Will Reply)' started by tester36, Sep 9, 2008.

  1. tester36

    tester36 Private First Class

    Things started going haywire I could not access my hallmark card program it says application failed to start b/c MSVCR 70.dll was not found reinstall may help I went to add/remove and it wouldnot let me remove.
    I came here and started do before posting and I got to remove 2 ole sunjava in add and remove programs and it saysWindows installer service could not be accessed this can occur if you are running windows in safe mode (which I am not) or if not correctly installed.

    I continued on to try to do what I could reset the msconfig after restart I got the message Messenger Plus has not been properly installed please download and install.

    when I tried to install super anti spy it says the same as above about the windows installer not being properly installed.
    please advise me what to do.
    the last time I got help yall had to help me with the windows installer but I have not had a minutes trouble until this trojan gen showed up:(
    thanks in advance
    stephanie
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The first thing you need to do is get rid of Messenger Plus--the likely cause of your issues.

    Then download and run the MGTools.exe from the Read and RUn FIrst and attach the MGLogs.zip
     
  3. tester36

    tester36 Private First Class

    Hey Tim,
    Thank you for your time. I unistalled Messenger Plus a good while back I had trouble with zone alarm uninstalled it and followed a posting here then which also caused a problem with windows installer we also got that fixed here too or so I thought. when I went in on the run and read me first step and checked the ms config is when the messenger plus message showed up. I did get the mgtools to run though and attached log I hope. I have tried again to remove the old versions of java and add and remove still will not let me. Avira again popped up HTML/Crypted Gen now it will not let me quarentine it jumps back to deny.
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You will have to tell me the exact path of what Avira is reporting.

    Some things to clean up:

    Please use add/remove programs to uninstall:
    J2SE Runtime Environment 5.0 Update 6
    Java(TM) SE Runtime Environment 6 Update 1

    Run this: Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it. (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now use windows explorer to find and delete:
    C:\\Program Files\\Messenger Plus! 2
    C:\temp
    NOw download and install:
    Java Runtime 6

    Now see if you can run SAS and MWB's and get me those logs. Then run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip
     
  5. tester36

    tester36 Private First Class

    Hey Tim,
    Just the same as the other day I went to add and remove programs click on the appropriate program
    Java(TM) SE Runtime Environment 6 Update 1
    J2SE Runtime Environment 5.0 Update 6

    and I still get the message below

    I got to remove 2 old sunjava in add and remove programs and it says "Windows installer service could not be accessed this can occur if you are running windows in safe mode (which I am not) or if not correctly installed"

    I did get windows messenger removed with the assigned program or it appeared to work properly.

    I did not proceed with the rest of your fix until I have your permission since I could not remove the above Java programs I thought that might created more problems.

    As of this posting I could not get the Avira to pop up the warning again but a box comes up and says avira has detected " HTML/Crypted Gen "
    what do you want to do it gives 4 choices I think the deny choice is already ticked and if you tick the quarentine choice it automaticly goes back to the deny choice.

    Thanks
    Steph
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let's not worry with Java at the moment...just do the rest and get me the logs.
     
  7. tester36

    tester36 Private First Class

    Tim
    The SAS still will not run it continues to give me "Windows installer service could not be accessed this can occur if you are running windows in safe mode (which I am not) or if not correctly installed" message. I did however get the MWB to run and I did the fix without problems. MGtoolls log also.:confused
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your malwarebytes log shows that you did not fix any of the problems it found.....
     
  9. tester36

    tester36 Private First Class

    Tim,
    I am sorry for that I meant I did the fix you had listed, but I rescanned and clicked the MWB fix also and redid MGtools.:eek: Still cannot do the SAS.
     

    Attached Files:

  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Items in my fixes are not being removed. You must disable all of your AV and AS programs.

    Try running this Windows Installer Cleanup

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):
    Run C:\MGtools\analyse.exe by double clicking on it. (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.
    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Tell me what malware issues you may still be having.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file.
     
  11. tester36

    tester36 Private First Class

    Tim
    the windows installer cleanup gives the same message as the others, "Windows installer service could not be accessed this can occur if you are running windows in safe mode (which I am not) or if not correctly installed. whether I try to run or install. I only see one thing obviously different from before but when I log out and back on I get a screen with two little strange carictures in an odd looking language you click on it and it goes away and of course the issue with the windows installer started when this stuff showed up. :cry
     

    Attached Files:

  12. tester36

    tester36 Private First Class

    Tim,
    After I posted the above I thought I really don't know what problems I still may have so I again tried SAS would not run but Spybot Search and Destroy did run and found My Way. My Web. Combo Fix also ran this time like it should I think I will attach the combofix log. The main thing i notice now is that add and remove programs still will not work and gives that notice about Windows installer. I have a Hallmark card program that I use quite a bit also it quit working when this stuff started showing up it gives the message " application failed to start because MSVCR 70.dll was not found reinstall may help but when you go to add and remove it gives the windows installer message too.
     

    Attached Files:

  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let's try a few things:

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it. (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Use windows explorer to find and delete:
    C:\Program Files\Common Files\PagingSYS.dll
    C:\Program Files\PagingSYS.dll

    Reboot and go to start / run / type "sfc /scannow" without qoutes and have your xp cd handy. (Note the space between sfc and /scannow).
     
  14. tester36

    tester36 Private First Class

    Tim,
    I think I did all that you asked without a problem just now the updates for xp 3 came up, but the add and remove programs still does not work nor the other has not changed do I need to post a log or something?
    stephanie
     
  15. tester36

    tester36 Private First Class

    One thing did start to work now after definitions update Adaware se Personal log attached.
    Thanks again for all your help
    Stephanie
     

    Attached Files:

  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Are you still having problems?

    If not, we need to do some cleaning from the scans:

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.
     
  17. tester36

    tester36 Private First Class

    Tim
    I still seem to be having the unusable Hallmark program, add and remove programs not working, some windows updates seem not to be installing.The computer is running faster.I got a success message after merging.
     
  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let's do one more thing before I send you to the software section:

    Now go to Bitscan link: agree to the license and then select Scan. DO NOT CHANGE THE OPTIONS TO SHOW ALL FILES SCANNED. That will make your logs huge and we don't need to see clean files. Once Bitdefender completes the scan:

    Click-on the Detected Problems tab. Then select Click here to export the scan report

    When the window comes up to save the report, change the Save as type: box to Text (Tab Delimited) (*.txt) and then in the File name box enter change to bdscan then click save. This will save a file named bdscan.txt in whatever folder you are currently in when you save the file (take notice of where you are at so you can find it later). This bdcan.txt file will actually contain HTML code that we can easily view later while reviewing your log. All we have to do is rename the file to bdscan.html.
     
  19. tester36

    tester36 Private First Class

    Tim
    bitdefender scan reports no problems :-D
     
  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you are not having any other malware problems, it is time to do our final steps:
     
  21. tester36

    tester36 Private First Class

    Tim,
    I left SAS and hope when every thing is done it will work and if it does I will run and use it. We did not use pocket kill box this time but I do have an old log file in c:\ should I just delete it?
    I uninstalled combofix.
    Add and remove programs says no hijack this.
    deleted MGlogs ect
    microsoft updates has some that fail over and over.
    windows installer error still comes up some times with error 1719.
    add and remove still does not remove java and other things.
    system restore turned off and on new restore point created.
    will try to work through the thread.
    Do you think the paid versionof RegCure would cause me these problems? I got it back in january it scanned yesterday on its on and is giving some errors that I did not let it fix until I came back here.

    thanks again
    steph:)
     
  22. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Reg Cure could have removed some things it shouldn't have..... I would look at what the last run removed and possibly reinstall those items to see if that is the problem.

    At this point, a trip to the software section might be a good idea. :)
     
  23. tester36

    tester36 Private First Class

    Tim
    Thank you very much for all your help. I will visit the soft ware forum for my other problems. I have been coming here for years now and you folks are the greatest in my book:cool;)

    Steph
     
  24. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are quite welcome....and good luck with the other issues. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds