View Full Version : Can't get rid of this damned virus.
M2 Carbine
03-08-2010, 13:14
AVG keeps popping up with multiple copies of
Trojan Horse Back Door Generic12 GOG.dropper
I've run AVG,
Spywearfighter
SuperAnti Spywear,
Spy Bot,
and
Malwearbytes in and out of safe mode
No luck, AVG continues to poop up every few minutes with the virus.
AVG says,
C;\Windows\system32\316716.exe
is infected.
The last couple numbers change. Now 32\974590.exe just popped up.
Any ideas?
Dalton Wayne
03-08-2010, 13:20
When was the last time you upgraded AVG? you moved it to the vault and it didn't clear it, You may have to start over by cleaning the drive writing zeros to it then reinstall everything that's the worst case.
Sorry I wasn't much help
Regards
DW
can you log into mutiple user accounts on that computer or do you just have 1 log on. If you have multiple accounts, try and log out and then log into another account, and see if the pop ups still appear. I got a feeling that you getting these pop ups in safe mode..you might be SOL.
let us know.
usually whenever i get a virus..i say..thats it. and i format and reinstall. you just can never trust the virus or the virus software...of course i haven't gotten a virus in probably 10 years..but i mean here at my office..if someone gets one, i usually just image the computer.
M2 Carbine
03-08-2010, 13:33
AVG is up to date.
Only one account.
Best I can tell AVG doesn't work in safe mode, I tried it this morning.
I wasn't getting the AVG popups in safe mode.
Malwearbytes does work in safe mode.
Got a line of thunderstorms moving in in about 20 minutes. Have to shut down but when I start up I'll see if I'm getting the pop ups in safe mode.
D-E-F-E-N-S-E!
03-08-2010, 16:44
Before doing something drastic like reformatting, try a program called Combofix.
It is a little hardcore, a little scary to use, and might be overkill, but should work as a last resort.
http://www.bleepingcomputer.com/combofix/how-to-use-combofix
I was forced to use it once. It knocked out the virus...but had unfortunate side effects.
This program kills everything associated with the virus, and it seems that this virus had hijacked my login ID. When the virus was killed, so was any chance of logging in through normal channels.
User beware.
Sorry but I just don't understand why people keep with Windows. An O.S. that is this vulnerable is so 1990.
There are better ways.
I'm not slamming you. It's your choice, I just don't understand the mind set. I like to do Internet banking and browse where ever I choose without worring about bad guys hijacking my identity or making the system I paid for part of a botnet.
Is it because you like to play games?
Patrick Graham
03-08-2010, 17:50
Sorry but I just don't understand why people keep with Windows. An O.S. that is this vulnerable is so 1990.
There are better ways.
I'm not slamming you. It's your choice, I just don't understand the mind set. I like to do Internet banking and browse where ever I choose without worring about bad guys hijacking my identity or making the system I paid for part of a botnet.
Is it because you like to play games?
Adobe CS4 and Roland VersaCAMM for starters.
Linux is fine if you are just surfing the net.
"Sorry but I just don't understand why people keep with Windows."
Because it works just fine if you have half a clue about running a pc. I've had half a clue since 1987 when I got my first pc and I get along with Vista okay. I've thought about taking my first computer class and seeing about that other half a clue, but I've made it this far without any formal training.
John
DID YOU SCAN IN SAFE MODE????
If you do NOT scan in safe mode, most viruses/malware/trojans will stealth themselves and YOU WILL NEVER CLEAN THE SYSTEM.
I have seen veteran techs blow this off regularly. Stealth technology came into play 7 to 8 years ago, and it works, and it's gotten better.
Safe Mode removes the opportunity to stealth program loads.
YOU ARE WASTING YOUR TIME ATTEMPTING TO CLEAN IN ANY STATUS BUT SAFE MODE.
PERIOD.
So try again!
The rest of you can prevent a future visit from the "Safe Mode Gremlin" by stating that you are scanning in safe mode somewhere in your post... :cool:
Regarding which ever operating system you should use... I think that it is certain that whoever wins the operating system war will be attacked, probed, reverse engineered, and exploited at every point possible. Some systems just aren't worth the effort yet, and because of this appear to be rock solid...
As I have heard said "We just haven't played Cowboys and Macs, or Cowboys and Linux yet"... Know what I mean?
Suggesting a wholesale change of OS into an environment you have never seen or evaluated... *PRICELESS*
"Sorry but I just don't understand why people keep with Windows."
Because it works just fine if you have half a clue about running a pc. I've had half a clue since 1987 when I got my first pc and I get along with Vista okay. I've thought about taking my first computer class and seeing about that other half a clue, but I've made it this far without any formal training.
John
I have used Windows since 1995. Only had 2-3 harmless viruses through the years despite being not overly protective. However, I have always had an up-to-date antivirus software and have never clicked on those maleware-popups that litters the Internet.
M2 Carbine
03-09-2010, 08:23
DID YOU SCAN IN SAFE MODE????
If you do NOT scan in safe mode, most viruses/malware/Trojans will stealth themselves and YOU WILL NEVER CLEAN THE SYSTEM.
I have seen veteran techs blow this off regularly. Stealth technology came into play 7 to 8 years ago, and it works, and it's gotten better.
Safe Mode removes the opportunity to stealth program loads.
YOU ARE WASTING YOUR TIME ATTEMPTING TO CLEAN IN ANY STATUS BUT SAFE MODE.
PERIOD.
So try again!
Yes, I have run Megabytes in Safe Mode a number of times .
Megabytes is the only one of the anti virus programs I have been able to get to run in safe mode.
It, and all the other anti-virus programs find the virus, or at least the results of the virus. They appear to do their thing, quarantine, etc, but then within a minute a anti-virus program will show there's infected files again.
Apparently the virus has hidden itself somewhere and the anti-virus programs keep working on what the virus is doing but can't get rid of the virus.
Before doing something drastic like reformatting, try a program called Combofix.
Thanks. I'll save this as a last resort. I suspect it may cause big problems since the virus is screwing up system32 files.
Sorry but I just don't understand why people keep with Windows.
Because that's what comes with the computer. Most people that buy a new computer don't want to, and haven't a clue about installing another operating system.
Suggesting a wholesale change of OS into an environment you have never seen or evaluated... *PRICELESS*
750SpiritRdr
03-09-2010, 09:04
SuperAnti Spy ware will run in Safe mode, make sure it's updated and run it in safe mode. If you have to then put it on a jump drive and run it from there in safe mode
750SpiritRdr
03-09-2010, 09:07
by the way i work at a hospital in the IT Dept. and this is the best way to get rid of this. Run a scan more than once also.
Adobe CS4 and Roland VersaCAMM for starters.
Linux is fine if you are just surfing the net.
Or if you are a scientist or mathematician or a researcher. Almost all of the 500 most powerful computers run Linux.
http://www.top500.org/stats/list/34/osfam
If you want to work on Digital Cinema, digital projection of feature films, then the O.S. is required by the Digital Cinema Initiative
http://www.dcimovies.com/
How about movie special effects artist, aka migrant pixel worker? Not home movies, professionals.
http://www.linuxmovies.org/
Security? If it's good enough for the NSA I guess it's good enough for me.
http://www.nsa.gov/research/selinux/index.shtml
And lets not forget people who just want to surf the web, write a few letters, do their banking and taxes show pictures and home videos and just don't want to have to worry about getting infected.
M2 Carbine
03-09-2010, 11:18
SuperAnti Spy ware will run in Safe mode, make sure it's updated and run it in safe mode. If you have to then put it on a jump drive and run it from there in safe mode
I'll try it again.
I have a desktop icon for SuperAnti Spyware in safe mode but unlike Malwearbytes, SAS wouldn't open.
Thanks, I'll try and get SAS working in safe mode.
Now, in normal mode, as I'm typing SPYWAERfighter has popped up four times showing,
Infected file has been found,
Trojan.DR.Mudrop.CDO
every few minutes now.
I'd like to get my hands on the POS that created this virus. SOB would never touch a computer keyboard again.:steamed:
750SpiritRdr
03-09-2010, 11:43
I'll try it again.
I have a desktop icon for SuperAnti Spyware in safe mode but unlike Malwearbytes, SAS wouldn't open.
Thanks, I'll try and get SAS working in safe mode.
Now, in normal mode, as I'm typing SPYWAERfighter has popped up four times showing,
Infected file has been found,
Trojan.DR.Mudrop.CDO
every few minutes now.
I'd like to get my hands on the POS that created this virus. SOB would never touch a computer keyboard again.:steamed:
Have you been playing online games? That seems to be an online game hack
M2 Carbine
03-09-2010, 12:42
Have you been playing online games? That seems to be an on line game hack
No games but I'm bad for looking at stuff to see if might be something I can use.
I don't remember what I was doing before this popped up, so I could have got the virus anywhere.
I got SuperAntiSpyware working in safe mode. All it came up with is 20 tracking cookies. I'm running a full scan now.
Lucky I've got a couple computers to use but the infected one is the main one with everything on it. I've started to make sure I've got everything backed up in case it comes down to formatting the HD. I'm almost tempted to buy a new computer. All mine are several years old. How's Win 7 working out?
The hell with this aggravation, I'm going shooting.:supergrin:
IndyGunFreak
03-09-2010, 13:31
Adobe CS4 and Roland VersaCAMM for starters.
Linux is fine if you are just surfing the net.
Hogwash...
There's plenty of programs that you can use that will do what those programs do.... The problem is, idiots install Linux and the first thing they say is "How do I make my Windows software run"... Well if you're gonna do that, just keep running Windows.
Learn to use Linux alternatives, and only use emulators/WINE when you have to. Makes life far easier.
IGF
TnGlocker12
03-09-2010, 15:45
I don't know much about computers, but a few months back I got a virus. I stumbled on the safe mode and then I did a "Restore" for a few weeks back and have not had any problems since.
M2 Carbine
03-10-2010, 08:03
I don't know much about computers, but a few months back I got a virus. I stumbled on the safe mode and then I did a "Restore" for a few weeks back and have not had any problems since.
In the past with some problems this has worked but has had no effect in this case.
As I'm typing now,
"Infected file has been found
Trogan.DR.Mudrop.CDO
C:\WINDOWS\system32\52489.exe"
still keeps popping up ever couple minutes.
If you Linux fans can say that Linux will run ALL the programs that Windows will run and is as easy to use as Windows, then I might consider it. If not, save your breath. I don't need more agrivation screwing with an operating system that it takes a computer geek to operate.
One day I might install Linux on a spare computer to see what it is,
but in the mean time Linux is doing nothing to help get rid of this virus.
Patrick Graham
03-10-2010, 09:12
Hogwash...
There's plenty of programs that you can use that will do what those programs do.... The problem is, idiots install Linux and the first thing they say is "How do I make my Windows software run"... Well if you're gonna do that, just keep running Windows.
Learn to use Linux alternatives, and only use emulators/WINE when you have to. Makes life far easier.
IGF
LOL!! :supergrin:
I'll tell that to the Graphics arts shops I support.
failedreality
03-11-2010, 19:59
In the past with some problems this has worked but has had no effect in this case.
As I'm typing now,
"Infected file has been found
Trogan.DR.Mudrop.CDO
C:\WINDOWS\system32\52489.exe"
still keeps popping up ever couple minutes.
Have you tried to manually remove this file under safe mode?
Have you tried hijack this? If you do, save a log and pm me, i will look at it..
DSMonsta
03-11-2010, 21:26
If you Linux fans can say that Linux will run ALL the programs that Windows will run and is as easy to use as Windows, then I might consider it. If not, save your breath. I don't need more agrivation screwing with an operating system that it takes a computer geek to operate.
One day I might install Linux on a spare computer to see what it is,
but in the mean time Linux is doing nothing to help get rid of this virus.
Reformat your computer with Windows as the primary partition and a small partition of Ubuntu for web browsing. That is of course if you're unable to solve the current problem.
gwalchmai
03-12-2010, 20:27
Buck, if you can remove the HD from your PC and put it into an external HD enclosure you can connect the HD to a friend's clean PC and scan it from there. That works even better than safe mode.
IndyGunFreak
03-12-2010, 21:00
LOL!! :supergrin:
I'll tell that to the Graphics arts shops I support.
An inability to learn, doesn't mean its not available.
IGF
An inability to learn, doesn't mean its not available.
IGF
yeah man, i use the GIMP all the time!
M2,
I had the exact same virus and I too have AVG. I got it from a guitar tab site that has tons of pop-ups. I had to run multiple scans with AVG before it finally got rid of it. I tried several other programs and they didn't even pick it up. Try running AVG a few more times and see how it goes.
Disclaimer: Not a computer expert by any stretch of the imagination. This is just what worked for me.
That's why I love Acronis True Image 10.0. I NEVER even worry about viruses. This backup utility will completely restore 90+g on my 120g hard drive in under an hour. And, that's not just data...we're talking a completely identical and bootable copy of everything. That's a lot less time for many virus scanners to even run...if they can find the virus and IF they can fullly remove it. Acronis formats as it goes along during the restore so it's a "nuke it from orbit" type solution. I keep several backup archives on two USB external drives and clone an identical internal D: drive I put in my desktop when I built it. So, if the C drive completely fails mechanically, I just unplug it and reboot from the D drive like nothing happened. Replace the fried drive at my own convenience. :cool:
vBulletin® v3.8.7, Copyright ©2000-2013, vBulletin Solutions, Inc.