What happened to the Messenger Plus! forums on msghelp.net?
Shoutbox » MsgHelp Archive » Skype & Technology » Tech Talk » Nasty little trojan horse

Pages: (2): « First [ 1 ] 2 » Last »
Nasty little trojan horse
Author: Message:
RebelSean
Veteran Member
*****

Avatar
Microsoft Evangelist

Posts: 2602
Reputation: 59
34 / Male / Flag
Joined: May 2004
Status: Away
O.P. Nasty little trojan horse
Well, thanks to my brother just now telling me that our office computer has a virus on it I can't do a system restore to get rid of this little bastard. It's called "Generic2.AVS". I have used both AVG Professional and NOD32. Both have healed the virus, but after every reboot the stupid thing comes back. What it does is disconnect my internet and connect to some dodgy place in Austrailia which I'm being billed for. I've looked on my startup list (msconfig), and I don't see anything out of the norm. I've googled this but nothing has helped.

Solution anyone? Really annoying, especially now that the family computer is down :(.
I'm on: Twitter, Facebook, and Neowin
12-20-2006 05:06 AM
Profile PM Web Find Quote Report
matty
Scripting Guru
*****


Posts: 8336
Reputation: 109
39 / Male / Flag
Joined: Dec 2002
Status: Away
RE: Nasty little trojan horse
quote:
Originally posted by RebelSean
Well, thanks to my brother just now telling me that our office computer has a virus on it I can't do a system restore to get rid of this little bastard. It's called "Generic2.AVS". I have used both AVG Professional and NOD32. Both have healed the virus, but after every reboot the stupid thing comes back. What it does is disconnect my internet and connect to some dodgy place in Austrailia which I'm being billed for. I've looked on my startup list (msconfig), and I don't see anything out of the norm. I've googled this but nothing has helped.

Solution anyone? Really annoying, especially now that the family computer is down :(.
Download and run Autoruns from http://download.sysinternals.com/Files/Autoruns.zip and run it in Safe Mode then check for anything out of the ordinary.
12-20-2006 05:11 AM
Profile E-Mail PM Find Quote Report
RebelSean
Veteran Member
*****

Avatar
Microsoft Evangelist

Posts: 2602
Reputation: 59
34 / Male / Flag
Joined: May 2004
Status: Away
O.P. RE: Nasty little trojan horse
Woah, I have no idea what half that stuff is, or if it's sopossed to be there or not :-$.

This post was edited on 12-20-2006 at 05:20 AM by RebelSean.
I'm on: Twitter, Facebook, and Neowin
12-20-2006 05:17 AM
Profile PM Web Find Quote Report
matty
Scripting Guru
*****


Posts: 8336
Reputation: 109
39 / Male / Flag
Joined: Dec 2002
Status: Away
RE: Nasty little trojan horse
You should be able to save a text file of all of it then try and post it. (May need to copy it to a key drive to post it here). Or boot in Safe Mode with Networking.
12-20-2006 05:20 AM
Profile E-Mail PM Find Quote Report
RebelSean
Veteran Member
*****

Avatar
Microsoft Evangelist

Posts: 2602
Reputation: 59
34 / Male / Flag
Joined: May 2004
Status: Away
O.P. RE: Nasty little trojan horse
I think this is it.

.txt File Attachment: AutoRuns.txt (63.36 KB)
This file has been downloaded 729 time(s).
I'm on: Twitter, Facebook, and Neowin
12-20-2006 05:23 AM
Profile PM Web Find Quote Report
matty
Scripting Guru
*****


Posts: 8336
Reputation: 109
39 / Male / Flag
Joined: Dec 2002
Status: Away
RE: Nasty little trojan horse
quote:
Originally posted by AutoRuns.txt

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run   

+ gwiz            c:\windows\system32\ntsystem.exe

HKLM\System\CurrentControlSet\Control\Session Manager\BootExecute           

+             File not found: 

+ ????Ta             File not found: ????Ta

+ ?A??2            File not found: ?A??2

+ SsiEfr.e            File not found: SsiEfr.e

+ SsiEfr.e            File not found: SsiEfr.e

+ SsiEfr.e            File not found: SsiEfr.e

+ SsiEfr.exe\            File not found: SsiEfr.exe\

+ stera            File not found: stera

+ t?A(            File not found: t?A(

These are all oddities. However you ant to delete the gwiz and as well delete that file. (If you want to zip it up and post it I can open it in a VM and see if it does anything else).

[edit]

ZOMG My Post Counter~ 4666
[Image: attachment.php?pid=766658]

[/edit]

.jpg File Attachment: post4666.jpg (6.33 KB)
This file has been downloaded 7209 time(s).

This post was edited on 12-20-2006 at 05:57 AM by matty.
12-20-2006 05:53 AM
Profile E-Mail PM Find Quote Report
bladeswords
Junior Member
**

Avatar
This Space For Rent

Posts: 22
36 / Male / –
Joined: Nov 2003
RE: Nasty little trojan horse
Ok, I have had a look trough there.  First filter out verified microsoft processes (go to option then Hide Signed Microsoft....).  Second remove all the settings that say "File Not Found" next to them (they are obviously not needed and redundent) that is for general maintainance.  Filtering out the windows varified makes it alot easier for us looking at your log files.  (Damn trojans are annoying!)

It is all just a bunch of meaningless ASCII to me!
Creator of MSN Names and Tools
12-20-2006 05:59 AM
Profile PM Web Find Quote Report
RebelSean
Veteran Member
*****

Avatar
Microsoft Evangelist

Posts: 2602
Reputation: 59
34 / Male / Flag
Joined: May 2004
Status: Away
O.P. RE: RE: Nasty little trojan horse
quote:
Originally posted by Matty
quote:
Originally posted by AutoRuns.txt

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run   

+ gwiz            c:\windows\system32\ntsystem.exe

HKLM\System\CurrentControlSet\Control\Session Manager\BootExecute           

+             File not found: 

+ ????Ta             File not found: ????Ta

+ ?A??2            File not found: ?A??2

+ SsiEfr.e            File not found: SsiEfr.e

+ SsiEfr.e            File not found: SsiEfr.e

+ SsiEfr.e            File not found: SsiEfr.e

+ SsiEfr.exe\            File not found: SsiEfr.exe\

+ stera            File not found: stera

+ t?A(            File not found: t?A(

These are all oddities. However you ant to delete the gwiz and as well delete that file. (If you want to zip it up and post it I can open it in a VM and see if it does anything else).

[edit]

ZOMG My Post Counter~ 4666
[Image: attachment.php?pid=766658]

[/edit]


So I can untick those boxes and then delete the ntsystem file?
I'm on: Twitter, Facebook, and Neowin
12-20-2006 07:02 PM
Profile PM Web Find Quote Report
matty
Scripting Guru
*****


Posts: 8336
Reputation: 109
39 / Male / Flag
Joined: Dec 2002
Status: Away
RE: Nasty little trojan horse
quote:
Originally posted by RebelSean
So I can untick those boxes and then delete the ntsystem file?
Yup.
12-20-2006 08:13 PM
Profile E-Mail PM Find Quote Report
bladeswords
Junior Member
**

Avatar
This Space For Rent

Posts: 22
36 / Male / –
Joined: Nov 2003
RE: Nasty little trojan horse
Better now RebelSean?  I want to know if our advice worked....
It is all just a bunch of meaningless ASCII to me!
Creator of MSN Names and Tools
12-21-2006 08:40 PM
Profile PM Web Find Quote Report
Pages: (2): « First [ 1 ] 2 » Last »
« Next Oldest Return to Top Next Newest »


Threaded Mode | Linear Mode
View a Printable Version
Send this Thread to a Friend
Subscribe | Add to Favorites
Rate This Thread:

Forum Jump:

Forum Rules:
You cannot post new threads
You cannot post replies
You cannot post attachments
You can edit your posts
HTML is Off
myCode is On
Smilies are On
[img] Code is On