Trojan Virtum-gen

Discussion in 'Malware Help (A Specialist Will Reply)' started by sbelgard, Jul 9, 2008.

  1. sbelgard

    sbelgard Private E-2

    Hello guys,

    It's been awhile since I have posted to your site. I ran all of the programs in the run me first forum and still have a problem. AVG free 8.0 shows I have troj-virtum gen on my computer. It says it is in the restore portion of the drive. Spysweeper also shows the trojan but it is still running the scan. I am sending this via another computer. I will send all logs from the read me once the scan stops unless told otherwise. If you want me to stop the scan and send logs to you I will.

    I have several spyware/virus programs on my computer. They are Avast!, AVG free, and spysweeper with Antivirus.Which of these programs do you suggest I use.

    Sonya
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    System Restore will be emptied when final steps are performed which is after all other active malware has been remove. Once you attach the logs from the READ & RUN ME, we will be able to determine your status.

    Did you skip the first important notes in the READ & RUN ME. Only one should ever be installed. If you have all of these installed, you need to uninstall all but one immediately.

    If you paid for SpySweeper with antivirus, you may as well use it since you will have full support.
     
  3. sbelgard

    sbelgard Private E-2

    I am attaching the logs from the scans.
     

    Attached Files:

  4. sbelgard

    sbelgard Private E-2

    last log
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We did not ask for a HijackThis log. You ned to attach the C:\MGlogs.zip file that was requested from running MGtools.exe.

    However you do have 3 antivirus programs installed which was the first thing the READ & RUN ME specified that needs to be fixed. So correct this first and then rerun MGtools and attach a new MGlogs.zip file.
     
  6. sbelgard

    sbelgard Private E-2

    I removed Avast and AVG. Left spysweeper and the other programs that I downloaded during run me first.

    Here is the log that I ran after removing programs.
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You are in pretty good shape. Just a few things todo....mostly due to Avast and AVG leftovers.

    First uninstall Ask Toolbar


    Now delete the below files:
    C:\wmcodec_update.exe
    C:\WINDOWS\Temp\avg8info.id
    C:\Documents and Settings\Sonya\Local Settings\temp\avg8inst.log

    Now delete the below folders:
    C:\Program Files\Alwil Software
    C:\Documents and Settings\All Users\Application Data\Avg8
    C:\Documents and Settings\Sonya\Local Settings\temp\_avast4_
    C:\WINDOWS\Temp\_avast4_


    Now let's toggle System Restore:
    Do run a new scan with Spy Sweeper and see if anything is detected. If it is tell me exactly what and where (give a log).
     
  8. sbelgard

    sbelgard Private E-2

    I removed asktoolbar as requested and deleted other files and folders.

    Ran spysweeper. Does not show any signs of trojan, adware or other spyware. It found 5 spy cookies and quarantined them.

    I am attaching a session log for you to look at.
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay since you are clean, we just need to put on finishing touches.


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.




    Now if you are not having any other malware problems, it is time to do our final steps:
    1. You can uninstall SUPERAntiSpyware now.
    2. We recommed you keep Malwarebytes Anti-Malware as a scanner. It uses no resources except a little disk space until you run a scan.
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combo-fix" /u
        • Notes: The space between the cf" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\cf folder from combofix.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  10. sbelgard

    sbelgard Private E-2

    Got this error message when tried to fix the registry:

    "Cannot import C:\Documents and settings\Sonya\Desktop\fixme.reg: The specified file is not a registry script. You can only import binary registry files from within the registry editor."

    I have not gone any farther with the instructions.

    Please advise.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That means that you did not follow the instructions properly to create the fixME.reg file. The REGEDIT4 line must be the first line in the file with NOTHING above it not even a blank line. Try again. ;)
     
  12. sbelgard

    sbelgard Private E-2

    It worked. Didn't put the regedit4 in the initial try. Will finish rest of the finishing touches.

    Thanks,
    Sonya
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds