Author Topic: [Resolved] VBS: ExeDropper-Gen [trj] notifications every few minutes  (Read 13289 times)

0 Members and 1 Guest are viewing this topic.

pogo4eva

  • Guest
Re: VBS: ExeDropper-Gen [trj] notifications every few minutes
« Reply #15 on: November 01, 2010, 11:45:39 AM »
Left that scan running overnight and it found something like 2600 infected files and was still running this morning at over 14 hours scan time  :o. Got to go through it after work and cure/quarantine anything that didnt get automatically cured, then will post the log...

pogo4eva

  • Guest
Re: VBS: ExeDropper-Gen [trj] notifications every few minutes
« Reply #16 on: November 01, 2010, 04:59:24 PM »
Whoah, my log file is 134MB, so wont be able to post it, any other options?

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: VBS: ExeDropper-Gen [trj] notifications every few minutes
« Reply #17 on: November 01, 2010, 10:30:55 PM »
Could you copy a selection of say 20 lines of the infection for me to see

Also is Avast still reporting the virus ?

pogo4eva

  • Guest
Re: VBS: ExeDropper-Gen [trj] notifications every few minutes
« Reply #18 on: November 02, 2010, 09:17:08 AM »
Hi,

Here is a random exerpt that shows some infections. Avast hasnt given any notifications since the Drweb scan completed.




>>E:\System Volume Information\_restore{1CAD30BF-DE5C-40BE-898C-EF0AC5FBF6EA}\RP6\A0045089.exe/Microsoft Frontpage 2003/ZY561401.CAB/SETUP.CHM_1033/img/comm_cd.jpg - OK
>>>E:\System Volume Information\_restore{1CAD30BF-DE5C-40BE-898C-EF0AC5FBF6EA}\RP6\A0045089.exe/Microsoft Frontpage 2003/ZY561401.CAB/SETUP.CHM_1033/img/comm_faq.jpg - OK
>>>E:\System Volume Information\_restore{1CAD30BF-DE5C-40BE-898C-EF0AC5FBF6EA}\RP6\A0045089.exe/Microsoft Frontpage 2003/ZY561401.CAB/SETUP.CHM_1033/img/comm_intro.jpg - OK
>>>E:\System Volume Information\_restore{1CAD30BF-DE5C-40BE-898C-EF0AC5FBF6EA}\RP6\A0045089.exe/Microsoft Frontpage 2003/ZY561401.CAB/SETUP.CHM_1033/img/comm_website.jpg - OK
>>>E:\System Volume Information\_restore{1CAD30BF-DE5C-40BE-898C-EF0AC5FBF6EA}\RP6\A0045089.exe/Microsoft Frontpage 2003/ZY561401.CAB/SETUP.CHM_1033/img/expandtri.gif - OK
>>>E:\System Volume Information\_restore{1CAD30BF-DE5C-40BE-898C-EF0AC5FBF6EA}\RP6\A0045089.exe/Microsoft Frontpage 2003/ZY561401.CAB/SETUP.CHM_1033/img/home2.gif - OK
>>>E:\System Volume Information\_restore{1CAD30BF-DE5C-40BE-898C-EF0AC5FBF6EA}\RP6\A0045089.exe/Microsoft Frontpage 2003/ZY561401.CAB/SETUP.CHM_1033/img/netall.gif - OK
>>>E:\System Volume Information\_restore{1CAD30BF-DE5C-40BE-898C-EF0AC5FBF6EA}\RP6\A0045089.exe/Microsoft Frontpage 2003/ZY561401.CAB/SETUP.CHM_1033/img/setall.gif - OK
>>>E:\System Volume Information\_restore{1CAD30BF-DE5C-40BE-898C-EF0AC5FBF6EA}\RP6\A0045089.exe/Microsoft Frontpage 2003/ZY561401.CAB/SETUP.CHM_1033/img/setcom.gif - OK
>>>E:\System Volume Information\_restore{1CAD30BF-DE5C-40BE-898C-EF0AC5FBF6EA}\RP6\A0045089.exe/Microsoft Frontpage 2003/ZY561401.CAB/SETUP.CHM_1033/img/setfirst.gif - OK
>>>E:\System Volume Information\_restore{1CAD30BF-DE5C-40BE-898C-EF0AC5FBF6EA}\RP6\A0045089.exe/Microsoft Frontpage 2003/ZY561401.CAB/SETUP.CHM_1033/img/setnet.gif - OK
>>>E:\System Volume Information\_restore{1CAD30BF-DE5C-40BE-898C-EF0AC5FBF6EA}\RP6\A0045089.exe/Microsoft Frontpage 2003/ZY561401.CAB/SETUP.CHM_1033/img/setnot.gif - OK
>>>E:\System Volume Information\_restore{1CAD30BF-DE5C-40BE-898C-EF0AC5FBF6EA}\RP6\A0045089.exe/Microsoft Frontpage 2003/ZY561401.CAB/SETUP.CHM_1033/setup.hhc - OK
>>E:\System Volume Information\_restore{1CAD30BF-DE5C-40BE-898C-EF0AC5FBF6EA}\RP6\A0045089.exe/Microsoft Frontpage 2003/ZY561401.CAB/SETUP.CHM_1033 - OK
>E:\System Volume Information\_restore{1CAD30BF-DE5C-40BE-898C-EF0AC5FBF6EA}\RP6\A0045089.exe/Microsoft Frontpage 2003/ZY561401.CAB - OK
>E:\System Volume Information\_restore{1CAD30BF-DE5C-40BE-898C-EF0AC5FBF6EA}\RP6\A0045089.exe/Microsoft Frontpage 2003/ZZ561401.CAB - archive CAB
>>E:\System Volume Information\_restore{1CAD30BF-DE5C-40BE-898C-EF0AC5FBF6EA}\RP6\A0045089.exe/Microsoft Frontpage 2003/ZZ561401.CAB/TREEHELP.TXT - OK
>E:\System Volume Information\_restore{1CAD30BF-DE5C-40BE-898C-EF0AC5FBF6EA}\RP6\A0045089.exe/Microsoft Frontpage 2003/ZZ561401.CAB - OK
E:\System Volume Information\_restore{1CAD30BF-DE5C-40BE-898C-EF0AC5FBF6EA}\RP6\A0045090.dll infected with Win32.Rmnet - cured
E:\System Volume Information\_restore{1CAD30BF-DE5C-40BE-898C-EF0AC5FBF6EA}\RP6\A0045090.dll - OK
E:\System Volume Information\_restore{1CAD30BF-DE5C-40BE-898C-EF0AC5FBF6EA}\RP6\A0045091.dll infected with Win32.Rmnet - cured
E:\System Volume Information\_restore{1CAD30BF-DE5C-40BE-898C-EF0AC5FBF6EA}\RP6\A0045091.dll - OK
E:\System Volume Information\_restore{1CAD30BF-DE5C-40BE-898C-EF0AC5FBF6EA}\RP6\A0045092.dll infected with Win32.Rmnet - cured
E:\System Volume Information\_restore{1CAD30BF-DE5C-40BE-898C-EF0AC5FBF6EA}\RP6\A0045092.dll - OK
E:\System Volume Information\_restore{1CAD30BF-DE5C-40BE-898C-EF0AC5FBF6EA}\RP6\A0045093.exe infected with Win32.Rmnet - cured
E:\System Volume Information\_restore{1CAD30BF-DE5C-40BE-898C-EF0AC5FBF6EA}\RP6\A0045093.exe - OK
E:\System Volume Information\_restore{1CAD30BF-DE5C-40BE-898C-EF0AC5FBF6EA}\RP6\change.log - OK
E:\System Volume Information\_restore{1CAD30BF-DE5C-40BE-898C-EF0AC5FBF6EA}\RP6\RestorePointSize - OK




Let me know if you need any more.

Thanks,

Gaz

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: VBS: ExeDropper-Gen [trj] notifications every few minutes
« Reply #19 on: November 02, 2010, 09:40:39 PM »
OK they are all in your restore point so system restore at the moment is useless lets get a new one made and the other removed

Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following

    Quote
    :Commands
    [resethosts]
    [purity]
    [emptytemp]
    [EMPTYFLASH]
    [CLEARALLRESTOREPOINTS]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done

THEN

Please run a fresh OTL sca (you will only get one log this time) and attach that, also let me know of any problems that you are experiencing 

pogo4eva

  • Guest
Re: VBS: ExeDropper-Gen [trj] notifications every few minutes
« Reply #20 on: November 02, 2010, 11:52:58 PM »
Hi,

Please see new OTL log attached. No other issues to report, all running OK and no more virus notifications...

Thanks,

Gary

emantoyaks

  • Guest
Re: VBS: ExeDropper-Gen [trj] notifications every few minutes
« Reply #21 on: November 03, 2010, 07:16:54 AM »
try to use this software for ur protection:

http://wormblaster.net/Virus_Remover_Update.zip



Goodluck...

SafeSurf

  • Guest
Re: VBS: ExeDropper-Gen [trj] notifications every few minutes
« Reply #22 on: November 03, 2010, 08:54:17 AM »
@ emantoyaks,  Thank you for your input, but the OP is working with a Certified Malware Expert.  ;)

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: VBS: ExeDropper-Gen [trj] notifications every few minutes
« Reply #23 on: November 03, 2010, 10:34:58 PM »
I will remove my tools now and give some recommendations, but I would like you to run for 24 hours or so and come back if you have any problems

 Now the best part of the day ----- Your log now appears clean  :thumbsup:

A good workman always cleans up after himself so..The following will implement some cleanup procedures as well as reset  System Restore points:

Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following

    Quote
    :Commands
    [resethosts]
    [purity]
    [emptytemp]
    [EMPTYFLASH]
    [CLEARALLRESTOREPOINTS]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done
.
Click Start > Run  and copy/paste the following bolded text into the Run box and click OK:

ComboFix /Uninstall

Run OTL and hit the cleanup button.  It will remove all the programmes we have used plus itself.  MBAM can be uninstalled via control panel add/remove along with ERUNT.  But they may be useful tools to keep

We will now confirm that your hidden files are set to that, as some of the tools I use will change that
  • Click Start.
  • Open My Computer.
  • Select the Tools menu and click Folder Options.
  • Select the View Tab.
  • Under the Hidden files and folders heading select Do not show hidden files and folders.
  • Click Yes to confirm.
  • Click OK.


SPRING CLEAN
 
Download and run Puran Disc Defragmenter

Now that you are clean, to help protect your computer in the future I recommend that you get the following free programmes: It is critical to have both a firewall and anti virus to protect your system and to keep them updated.

To keep your operating system up to date visit To learn more about how to protect yourself while on the internet read our little guide  How did I get infected in the first place ?
Keep safe  :wave:

pogo4eva

  • Guest
Re: VBS: ExeDropper-Gen [trj] notifications every few minutes
« Reply #24 on: November 04, 2010, 09:31:25 PM »
OK, going to run the cleanup and install your recommended software to help keep myself protected.

Can I just say a massive THANK YOU to Essexboy for being so helpful and sorting out all my problems with my PC.

Gonna stick with Avast and will be supporting the development of this amazing software/community by upgrading to the paid version and recommending it to all my friends.

I am forever in your debt, and if I can ever return the favour, you only need to ask!!!!

You truly are a lifesaver!!!!

Thanks again,

Gary

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: VBS: ExeDropper-Gen [trj] notifications every few minutes
« Reply #25 on: November 04, 2010, 09:38:16 PM »
Our pleasure - keep an eye on it for the next 24 hours or so though  ;D

SafeSurf

  • Guest
[RESOLVED] Re: VBS: ExeDropper-Gen [trj] notifications every few minutes
« Reply #26 on: November 06, 2010, 10:28:22 AM »
pogo4eva (Gary),

I'm am glad to hear that things are looking good for you now.  :D 

If you feel that your issue is now resolved/fixed, please go back to the first open post in this topic, click the modify button in that Post and change the title/subject, add [Resolved] to the beginning of the title so this thread can be closed. 

Feel free to come back any time you need help, to learn something new, or just to ask questions.  We are here 24/7 for your convenience.  Thank you for allowing us to assist you.