GlockTalk.com
Home Forums Classifieds Blogs Today's Posts Search Social Groups



  
SIGN-UP
Notices

Glock Talk
Welcome To The Glock Talk Forums.
Reply
 
Thread Tools Display Modes
Old 03-08-2010, 13:14   #1
M2 Carbine
Senior Member
 
M2 Carbine's Avatar
 
Join Date: Dec 2002
Location: Texas
Posts: 27,066
Can't get rid of this damned virus.

AVG keeps popping up with multiple copies of
Trojan Horse Back Door Generic12 GOG.dropper

I've run AVG,
Spywearfighter
SuperAnti Spywear,
Spy Bot,
and
Malwearbytes in and out of safe mode

No luck, AVG continues to poop up every few minutes with the virus.
AVG says,
C;\Windows\system32\316716.exe
is infected.

The last couple numbers change. Now 32\974590.exe just popped up.

Any ideas?
M2 Carbine is offline   Reply With Quote
Old 03-08-2010, 13:20   #2
Dalton Wayne
CLM Number 239
Epic mustache
 
Dalton Wayne's Avatar
 
Join Date: Apr 1999
Location: Florida
Posts: 12,064
Send a message via MSN to Dalton Wayne
When was the last time you upgraded AVG? you moved it to the vault and it didn't clear it, You may have to start over by cleaning the drive writing zeros to it then reinstall everything that's the worst case.
Sorry I wasn't much help
Regards
DW
__________________
Regards
DW
I am a professional I always aim true whether firing single shots or full automatic, I know neither fatigue nor failure I would take pride in my work but for one thing, I do not know my target, I am not the one that kills, that distinction belongs to the man who pulls my trigger, I am an assault rifle my name is Kalashnikov

Dalton Wayne is online now   Reply With Quote
Old 03-08-2010, 13:20   #3
MavsX
The Dude Abides
 
MavsX's Avatar
 
Join Date: Jan 2009
Location: Arlington, VA
Posts: 3,033
can you log into mutiple user accounts on that computer or do you just have 1 log on. If you have multiple accounts, try and log out and then log into another account, and see if the pop ups still appear. I got a feeling that you getting these pop ups in safe mode..you might be SOL.

let us know.

usually whenever i get a virus..i say..thats it. and i format and reinstall. you just can never trust the virus or the virus software...of course i haven't gotten a virus in probably 10 years..but i mean here at my office..if someone gets one, i usually just image the computer.
__________________
Glock 22 .40 S&W
CMMG M4 LEP II
Mossberg 500 Mariner
MavsX is offline   Reply With Quote
Old 03-08-2010, 13:33   #4
M2 Carbine
Senior Member
 
M2 Carbine's Avatar
 
Join Date: Dec 2002
Location: Texas
Posts: 27,066
AVG is up to date.

Only one account.

Best I can tell AVG doesn't work in safe mode, I tried it this morning.
I wasn't getting the AVG popups in safe mode.

Malwearbytes does work in safe mode.


Got a line of thunderstorms moving in in about 20 minutes. Have to shut down but when I start up I'll see if I'm getting the pop ups in safe mode.
M2 Carbine is offline   Reply With Quote
Old 03-08-2010, 16:44   #5
D-E-F-E-N-S-E!
AAAAAAAAAAAAAH!
 
D-E-F-E-N-S-E!'s Avatar
 
Join Date: May 2004
Posts: 1,154
Before doing something drastic like reformatting, try a program called Combofix.

It is a little hardcore, a little scary to use, and might be overkill, but should work as a last resort.

http://www.bleepingcomputer.com/comb...o-use-combofix

I was forced to use it once. It knocked out the virus...but had unfortunate side effects.
This program kills everything associated with the virus, and it seems that this virus had hijacked my login ID. When the virus was killed, so was any chance of logging in through normal channels.

User beware.

Last edited by D-E-F-E-N-S-E!; 03-08-2010 at 16:47..
D-E-F-E-N-S-E! is offline   Reply With Quote
Old 03-08-2010, 17:38   #6
Linux3
Senior Member
 
Linux3's Avatar
 
Join Date: Dec 2008
Posts: 1,384
Sorry but I just don't understand why people keep with Windows. An O.S. that is this vulnerable is so 1990.
There are better ways.
I'm not slamming you. It's your choice, I just don't understand the mind set. I like to do Internet banking and browse where ever I choose without worring about bad guys hijacking my identity or making the system I paid for part of a botnet.
Is it because you like to play games?
__________________
It it's not on fire,
It's a software problem.

Linux3 is offline   Reply With Quote
Old 03-08-2010, 17:50   #7
Patrick Graham
Footlong Jr.
 
Patrick Graham's Avatar
 
Join Date: Sep 2001
Location: Kokomo Indiana
Posts: 5,450


Quote:
Originally Posted by Linux3 View Post
Sorry but I just don't understand why people keep with Windows. An O.S. that is this vulnerable is so 1990.
There are better ways.
I'm not slamming you. It's your choice, I just don't understand the mind set. I like to do Internet banking and browse where ever I choose without worring about bad guys hijacking my identity or making the system I paid for part of a botnet.
Is it because you like to play games?
Adobe CS4 and Roland VersaCAMM for starters.

Linux is fine if you are just surfing the net.
__________________
Never feed a cat anything that isn't the same color as the carpet.
Patrick Graham is offline   Reply With Quote
Old 03-09-2010, 05:54   #8
JohnBT
NRA Patron
 
Join Date: Feb 2000
Location: Richmond, Virginia
Posts: 5,911
"Sorry but I just don't understand why people keep with Windows."

Because it works just fine if you have half a clue about running a pc. I've had half a clue since 1987 when I got my first pc and I get along with Vista okay. I've thought about taking my first computer class and seeing about that other half a clue, but I've made it this far without any formal training.

John
JohnBT is offline   Reply With Quote
Old 03-09-2010, 06:50   #9
Pierre!
NRA Life Member
 
Pierre!'s Avatar
 
Join Date: Jun 2003
Location: Just Returned to Tucson AZ!
Posts: 4,044
DID YOU SCAN IN SAFE MODE????

If you do NOT scan in safe mode, most viruses/malware/trojans will stealth themselves and YOU WILL NEVER CLEAN THE SYSTEM.

I have seen veteran techs blow this off regularly. Stealth technology came into play 7 to 8 years ago, and it works, and it's gotten better.

Safe Mode removes the opportunity to stealth program loads.

YOU ARE WASTING YOUR TIME ATTEMPTING TO CLEAN IN ANY STATUS BUT SAFE MODE.

PERIOD.

So try again!

The rest of you can prevent a future visit from the "Safe Mode Gremlin" by stating that you are scanning in safe mode somewhere in your post...

Regarding which ever operating system you should use... I think that it is certain that whoever wins the operating system war will be attacked, probed, reverse engineered, and exploited at every point possible. Some systems just aren't worth the effort yet, and because of this appear to be rock solid...

As I have heard said "We just haven't played Cowboys and Macs, or Cowboys and Linux yet"... Know what I mean?

Suggesting a wholesale change of OS into an environment you have never seen or evaluated... *PRICELESS*
__________________
The Seeber Consulting Blog

Download YOUR copy of Internet Safety Tips - "The Essentials"!
My Gift to You, AND it's >FREE<
Pierre! is offline   Reply With Quote
Old 03-09-2010, 06:52   #10
Swiper
Senior Member
 
Swiper's Avatar
 
Join Date: Dec 2009
Location: Texas
Posts: 2,731
Quote:
Originally Posted by JohnBT View Post
"Sorry but I just don't understand why people keep with Windows."

Because it works just fine if you have half a clue about running a pc. I've had half a clue since 1987 when I got my first pc and I get along with Vista okay. I've thought about taking my first computer class and seeing about that other half a clue, but I've made it this far without any formal training.

John
I have used Windows since 1995. Only had 2-3 harmless viruses through the years despite being not overly protective. However, I have always had an up-to-date antivirus software and have never clicked on those maleware-popups that litters the Internet.
Swiper is offline   Reply With Quote
Old 03-09-2010, 08:23   #11
M2 Carbine
Senior Member
 
M2 Carbine's Avatar
 
Join Date: Dec 2002
Location: Texas
Posts: 27,066
Quote:
DID YOU SCAN IN SAFE MODE????
If you do NOT scan in safe mode, most viruses/malware/Trojans will stealth themselves and YOU WILL NEVER CLEAN THE SYSTEM.
I have seen veteran techs blow this off regularly. Stealth technology came into play 7 to 8 years ago, and it works, and it's gotten better.
Safe Mode removes the opportunity to stealth program loads.
YOU ARE WASTING YOUR TIME ATTEMPTING TO CLEAN IN ANY STATUS BUT SAFE MODE.
PERIOD.
So try again!
Yes, I have run Megabytes in Safe Mode a number of times .
Megabytes is the only one of the anti virus programs I have been able to get to run in safe mode.

It, and all the other anti-virus programs find the virus, or at least the results of the virus. They appear to do their thing, quarantine, etc, but then within a minute a anti-virus program will show there's infected files again.
Apparently the virus has hidden itself somewhere and the anti-virus programs keep working on what the virus is doing but can't get rid of the virus.

Quote:
Before doing something drastic like reformatting, try a program called Combofix.
Thanks. I'll save this as a last resort. I suspect it may cause big problems since the virus is screwing up system32 files.

Quote:
Sorry but I just don't understand why people keep with Windows.
Because that's what comes with the computer. Most people that buy a new computer don't want to, and haven't a clue about installing another operating system.
Quote:
Suggesting a wholesale change of OS into an environment you have never seen or evaluated... *PRICELESS*

Last edited by M2 Carbine; 03-09-2010 at 08:26..
M2 Carbine is offline   Reply With Quote
Old 03-09-2010, 08:37   #12
Slug71
Senior Member
 
Slug71's Avatar
 
Join Date: Mar 2010
Location: Oregon - U.S.A
Posts: 3,287
Install Ubuntu.
Slug71 is offline   Reply With Quote
Old 03-09-2010, 09:04   #13
750SpiritRdr
Senior Member
 
750SpiritRdr's Avatar
 
Join Date: Feb 2010
Location: Brazoria, Tx
Posts: 152
SuperAnti Spy ware will run in Safe mode, make sure it's updated and run it in safe mode. If you have to then put it on a jump drive and run it from there in safe mode
750SpiritRdr is offline   Reply With Quote
Old 03-09-2010, 09:07   #14
750SpiritRdr
Senior Member
 
750SpiritRdr's Avatar
 
Join Date: Feb 2010
Location: Brazoria, Tx
Posts: 152
by the way i work at a hospital in the IT Dept. and this is the best way to get rid of this. Run a scan more than once also.
750SpiritRdr is offline   Reply With Quote
Old 03-09-2010, 09:24   #15
Linux3
Senior Member
 
Linux3's Avatar
 
Join Date: Dec 2008
Posts: 1,384
Quote:
Originally Posted by Patrick Graham View Post
Adobe CS4 and Roland VersaCAMM for starters.
Linux is fine if you are just surfing the net.
Or if you are a scientist or mathematician or a researcher. Almost all of the 500 most powerful computers run Linux.
http://www.top500.org/stats/list/34/osfam
If you want to work on Digital Cinema, digital projection of feature films, then the O.S. is required by the Digital Cinema Initiative
http://www.dcimovies.com/
How about movie special effects artist, aka migrant pixel worker? Not home movies, professionals.
http://www.linuxmovies.org/
Security? If it's good enough for the NSA I guess it's good enough for me.
http://www.nsa.gov/research/selinux/index.shtml

And lets not forget people who just want to surf the web, write a few letters, do their banking and taxes show pictures and home videos and just don't want to have to worry about getting infected.
__________________
It it's not on fire,
It's a software problem.

Linux3 is offline   Reply With Quote
Old 03-09-2010, 11:18   #16
M2 Carbine
Senior Member
 
M2 Carbine's Avatar
 
Join Date: Dec 2002
Location: Texas
Posts: 27,066
Quote:
SuperAnti Spy ware will run in Safe mode, make sure it's updated and run it in safe mode. If you have to then put it on a jump drive and run it from there in safe mode
I'll try it again.
I have a desktop icon for SuperAnti Spyware in safe mode but unlike Malwearbytes, SAS wouldn't open.
Thanks, I'll try and get SAS working in safe mode.


Now, in normal mode, as I'm typing SPYWAERfighter has popped up four times showing,

Infected file has been found,
Trojan.DR.Mudrop.CDO

every few minutes now.


I'd like to get my hands on the POS that created this virus. SOB would never touch a computer keyboard again.
M2 Carbine is offline   Reply With Quote
Old 03-09-2010, 11:43   #17
750SpiritRdr
Senior Member
 
750SpiritRdr's Avatar
 
Join Date: Feb 2010
Location: Brazoria, Tx
Posts: 152
Quote:
Originally Posted by M2 Carbine View Post
I'll try it again.
I have a desktop icon for SuperAnti Spyware in safe mode but unlike Malwearbytes, SAS wouldn't open.
Thanks, I'll try and get SAS working in safe mode.


Now, in normal mode, as I'm typing SPYWAERfighter has popped up four times showing,

Infected file has been found,
Trojan.DR.Mudrop.CDO

every few minutes now.


I'd like to get my hands on the POS that created this virus. SOB would never touch a computer keyboard again.
Have you been playing online games? That seems to be an online game hack
750SpiritRdr is offline   Reply With Quote
Old 03-09-2010, 12:42   #18
M2 Carbine
Senior Member
 
M2 Carbine's Avatar
 
Join Date: Dec 2002
Location: Texas
Posts: 27,066
Quote:
Have you been playing online games? That seems to be an on line game hack
No games but I'm bad for looking at stuff to see if might be something I can use.
I don't remember what I was doing before this popped up, so I could have got the virus anywhere.


I got SuperAntiSpyware working in safe mode. All it came up with is 20 tracking cookies. I'm running a full scan now.
Lucky I've got a couple computers to use but the infected one is the main one with everything on it. I've started to make sure I've got everything backed up in case it comes down to formatting the HD. I'm almost tempted to buy a new computer. All mine are several years old. How's Win 7 working out?


The hell with this aggravation, I'm going shooting.

Last edited by M2 Carbine; 03-09-2010 at 12:45..
M2 Carbine is offline   Reply With Quote
Old 03-09-2010, 13:31   #19
IndyGunFreak
RIP Jack
 
IndyGunFreak's Avatar
 
Join Date: Jan 2001
Location: Indiana
Posts: 27,784
Send a message via ICQ to IndyGunFreak Send a message via AIM to IndyGunFreak Send a message via MSN to IndyGunFreak Send a message via Yahoo to IndyGunFreak Send a message via Skype™ to IndyGunFreak


Quote:
Originally Posted by Patrick Graham View Post
Adobe CS4 and Roland VersaCAMM for starters.

Linux is fine if you are just surfing the net.
Hogwash...

There's plenty of programs that you can use that will do what those programs do.... The problem is, idiots install Linux and the first thing they say is "How do I make my Windows software run"... Well if you're gonna do that, just keep running Windows.

Learn to use Linux alternatives, and only use emulators/WINE when you have to. Makes life far easier.

IGF
__________________
The NRA will fight for your rights in the halls of Congress.
The Second Amendment Foundation will fight for your rights in the courts.
The GOA will send out a fax or press release saying they will not compromise.

Join the NRA and SAF today!
IndyGunFreak is offline   Reply With Quote
Old 03-09-2010, 15:45   #20
TnGlocker12
Senior Member
 
TnGlocker12's Avatar
 
Join Date: Mar 2009
Location: West Tennessee
Posts: 601
Send a message via AIM to TnGlocker12
I don't know much about computers, but a few months back I got a virus. I stumbled on the safe mode and then I did a "Restore" for a few weeks back and have not had any problems since.
__________________
I believe in gun control. That's why I use two hands.
TnGlocker12 is offline   Reply With Quote
Old 03-10-2010, 08:03   #21
M2 Carbine
Senior Member
 
M2 Carbine's Avatar
 
Join Date: Dec 2002
Location: Texas
Posts: 27,066
Quote:
Originally Posted by TnGlocker12 View Post
I don't know much about computers, but a few months back I got a virus. I stumbled on the safe mode and then I did a "Restore" for a few weeks back and have not had any problems since.
In the past with some problems this has worked but has had no effect in this case.

As I'm typing now,

"Infected file has been found
Trogan.DR.Mudrop.CDO
C:\WINDOWS\system32\52489.exe"

still keeps popping up ever couple minutes.



If you Linux fans can say that Linux will run ALL the programs that Windows will run and is as easy to use as Windows, then I might consider it. If not, save your breath. I don't need more agrivation screwing with an operating system that it takes a computer geek to operate.

One day I might install Linux on a spare computer to see what it is,
but in the mean time Linux is doing nothing to help get rid of this virus.
M2 Carbine is offline   Reply With Quote
Old 03-10-2010, 09:12   #22
Patrick Graham
Footlong Jr.
 
Patrick Graham's Avatar
 
Join Date: Sep 2001
Location: Kokomo Indiana
Posts: 5,450


Quote:
Originally Posted by IndyGunFreak View Post
Hogwash...

There's plenty of programs that you can use that will do what those programs do.... The problem is, idiots install Linux and the first thing they say is "How do I make my Windows software run"... Well if you're gonna do that, just keep running Windows.

Learn to use Linux alternatives, and only use emulators/WINE when you have to. Makes life far easier.

IGF
LOL!!

I'll tell that to the Graphics arts shops I support.
__________________
Never feed a cat anything that isn't the same color as the carpet.
Patrick Graham is offline   Reply With Quote
Old 03-11-2010, 19:59   #23
failedreality
Junior Member
 
failedreality's Avatar
 
Join Date: Apr 2007
Location: Arlington, tx
Posts: 11
Quote:
Originally Posted by M2 Carbine View Post
In the past with some problems this has worked but has had no effect in this case.

As I'm typing now,

"Infected file has been found
Trogan.DR.Mudrop.CDO
C:\WINDOWS\system32\52489.exe"

still keeps popping up ever couple minutes.

Have you tried to manually remove this file under safe mode?
Have you tried hijack this? If you do, save a log and pm me, i will look at it..
__________________
Lone Star Glockers #301
failedreality is offline   Reply With Quote
Old 03-11-2010, 21:26   #24
DSMonsta
Linux Pimp
 
DSMonsta's Avatar
 
Join Date: Oct 2004
Location: Northampton County, PA
Posts: 546
Quote:
Originally Posted by M2 Carbine View Post
If you Linux fans can say that Linux will run ALL the programs that Windows will run and is as easy to use as Windows, then I might consider it. If not, save your breath. I don't need more agrivation screwing with an operating system that it takes a computer geek to operate.

One day I might install Linux on a spare computer to see what it is,
but in the mean time Linux is doing nothing to help get rid of this virus.
Reformat your computer with Windows as the primary partition and a small partition of Ubuntu for web browsing. That is of course if you're unable to solve the current problem.
__________________
Pray for peace. Prepare for the alternative.
DSMonsta is offline   Reply With Quote
Old 03-12-2010, 20:27   #25
gwalchmai
Lead Membership
 
gwalchmai's Avatar
 
Join Date: Jan 2002
Location: Outside the perimeter
Posts: 41,899


Buck, if you can remove the HD from your PC and put it into an external HD enclosure you can connect the HD to a friend's clean PC and scan it from there. That works even better than safe mode.
__________________
I'll submit to an audited open-records background check the same day Obama does.
gwalchmai is offline   Reply With Quote
Sponsored Links
Advertisement
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump




All times are GMT -6. The time now is 05:34.



Homepage
FAQ
Forums
Calendar
Advertise
Gallery
GT Wiki
GT Blogs
Social Groups
Classifieds


Users Currently Online: 1,153
529 Members
624 Guests

Most users ever online: 5,723
Apr 16, 2009 at 11:36