Author Topic: Trojan.Ransom.Gend  (Read 5728 times)

0 Members and 1 Guest are viewing this topic.

bagdet46

  • Guest
Trojan.Ransom.Gend
« on: May 14, 2014, 03:38:49 PM »
Hi again dear community,

just to be sure I used Malwarebytes to scan for some threats and found a trojan with the name pvexui.dat in my C:\ProgramData\ folder.
Put it in quarantine and thought that's it, but then thought that it can not be a coincidence.

Some days ago I got a problem based on nearly the same thing:
http://forum.avast.com/index.php?topic=150112.0

So I am asking again for some help as I
1) don't know how to handle it.
2) don't know what is the real threat as it can't be just a coincidence that the same trojan(with just another name) is in the same directory.
3) don't know what should be done.

I apologize for my rude request and hope you guys can help me out once more!

Bagdet

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: Trojan.Ransom.Gend
« Reply #1 on: May 14, 2014, 03:45:05 PM »
 --> http://forum.avast.com/index.php?topic=53253.0

Run MBAM and attach the log. Yours says nothing.

THEN

Run OTL.
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

bagdet46

  • Guest
Re: Trojan.Ransom.Gend
« Reply #2 on: May 14, 2014, 04:27:48 PM »
--> http://forum.avast.com/index.php?topic=53253.0

Run MBAM and attach the log. Yours says nothing.

THEN

Run OTL.

Thank you for replying!
My problem is that I have no log for the quarantined data.
Not sure how to fix that...

argus

  • Guest
Re: Trojan.Ransom.Gend
« Reply #3 on: May 14, 2014, 05:41:44 PM »
Hi,



Please download Farbar Recovery Scan Tool () by Farbar and save it to your desktop.

Note: You need to run the version compatibale with your system. If you are not sure which version applies to your system download both of them and try to run them.
Only one of them will run on your system, that will be the right version.


  • Double-click to run it. When the tool opens click Yes to disclaimer.
  • Press Scan button.
  • It will make a log (FRST.txt) in the same directory the tool is run. Please attach it to your reply.
  • The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.
8) http://www.youtube.com/watch?v=NTQMhoACXzs

bagdet46

  • Guest
Re: Trojan.Ransom.Gend
« Reply #4 on: May 14, 2014, 05:51:39 PM »
Hi,



Please download Farbar Recovery Scan Tool () by Farbar and save it to your desktop.

Note: You need to run the version compatibale with your system. If you are not sure which version applies to your system download both of them and try to run them.
Only one of them will run on your system, that will be the right version.


  • Double-click to run it. When the tool opens click Yes to disclaimer.
  • Press Scan button.
  • It will make a log (FRST.txt) in the same directory the tool is run. Please attach it to your reply.
  • The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.
8) http://www.youtube.com/watch?v=NTQMhoACXzs

Ok done!

argus

  • Guest
Re: Trojan.Ransom.Gend
« Reply #5 on: May 14, 2014, 06:28:24 PM »
1. Open notepad and copy/paste the text present inside the code box below.
To do this highlight the contents of the box and right click on it. Paste this into the open notepad.
NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to the operating system

Code: [Select]
>>> FIX <<<
2. Save notepad as fixlist.txt to your Desktop.
NOTE: => It's important that both files, FRST and fixlist.txt are in the same location or the fix will not work.


3. Run FRST/FRST64 and press the Fix button just once and wait.
If the tool needed a restart please make sure you let the system to restart normally and let the tool completes its run after restart.

The tool will make a log on the Desktop (Fixlog.txt). Please attach it to your reply.
Note: If the tool warned you about the outdated version please download and run the updated version.

bagdet46

  • Guest
Re: Trojan.Ransom.Gend
« Reply #6 on: May 14, 2014, 06:47:22 PM »
1. Open notepad and copy/paste the text present inside the code box below.
To do this highlight the contents of the box and right click on it. Paste this into the open notepad.
NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to the operating system

Code: [Select]
>>> FIX <<<
2. Save notepad as fixlist.txt to your Desktop.
NOTE: => It's important that both files, FRST and fixlist.txt are in the same location or the fix will not work.


3. Run FRST/FRST64 and press the Fix button just once and wait.
If the tool needed a restart please make sure you let the system to restart normally and let the tool completes its run after restart.

The tool will make a log on the Desktop (Fixlog.txt). Please attach it to your reply.
Note: If the tool warned you about the outdated version please download and run the updated version.

That right?

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: Trojan.Ransom.Gend
« Reply #7 on: May 14, 2014, 07:26:15 PM »
Sorry. Wait for Argus
« Last Edit: May 14, 2014, 07:28:28 PM by Michael (alan1998) »
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

argus

  • Guest
Re: Trojan.Ransom.Gend
« Reply #8 on: May 15, 2014, 07:57:02 PM »
Not fit, so I had to give a fix so.
« Last Edit: May 15, 2014, 08:00:10 PM by argus »

bagdet46

  • Guest
Re: Trojan.Ransom.Gend
« Reply #9 on: May 15, 2014, 09:38:35 PM »
Not fit, so I had to give a fix so.

Sorry for my question as I am not sure.
Do I need to use your fixlist attachment in my FRST and then post my log here?

argus

  • Guest
Re: Trojan.Ransom.Gend
« Reply #10 on: May 17, 2014, 06:41:02 PM »
Yes,

I'm sorry I'm sick.

bagdet46

  • Guest
Re: Trojan.Ransom.Gend
« Reply #11 on: May 22, 2014, 01:18:53 PM »
Yes,

I'm sorry I'm sick.

Sorry for the long delay.
Hope you got better.

argus

  • Guest
Re: Trojan.Ransom.Gend
« Reply #12 on: May 23, 2014, 10:51:15 AM »
How's your computer behaving now?

bagdet46

  • Guest
Re: Trojan.Ransom.Gend
« Reply #13 on: May 23, 2014, 05:18:45 PM »
How's your computer behaving now?

Without any problems.
Thanks for your kind help!

argus

  • Guest
Re: Trojan.Ransom.Gend
« Reply #14 on: May 24, 2014, 12:04:24 PM »

The following will implement some post-cleanup procedures:

=> Please download DelFix by Xplode to your Desktop.

Run the tool and check the following boxes below;
Remove disinfection tools
Create registry backup
Purge System Restore

Click Run button and wait a few seconds for the programme completes his work.
At this point all the tools we used here should be gone. Tool will create an report for you (C:\DelFix.txt)

The tool will also record healthy state of registry and make a backup using ERUNT program in %windir%\ERUNT\DelFix
Tool deletes old system restore points and create a fresh system restore point after cleaning.