[Resolved] Win32:Trojan-gen found

how do I tell what problems I have?

I’ve re-scanned avast and MBAM and both are negative, although the virus’s are still in the chest in avast

By problems - is the computer booting properly, is the speed of the system OK, do programmes start correctly etc…

As for the file in the chest they can be safely deleted now

Just re-booted and the only differences i’ve noticed is that Firefox opens in ‘safe mode’ and there are two .ini notepad files on my desk top, which I can’t attach as the system won’t let me, so have pasted the text below.

[.ShellClassInfo] LocalizedResourceName=@%SystemRoot%\system32\shell32.dll,-21799 [LocalizedFileNames] Microsoft Office - 60 Day Trial.lnk=@C:\PROGRA~1\MICROS~4\mui\oaa.dll,-103
[.ShellClassInfo] LocalizedResourceName=@%SystemRoot%\system32\shell32.dll,-21769 IconResource=%SystemRoot%\system32\imageres.dll,-183

Those are system files which we will now return to their hidden status ;D

I will remove my tools now and give some recommendations, but I would like you to run for 24 hours or so and come back if you have any problems

Now the best part of the day ----- Your log now appears clean :thumbsup:

A good workman always cleans up after himself so…The following will implement some cleanup procedures as well as reset System Restore points:

Run OTL

[*]Under the Custom Scans/Fixes box at the bottom, paste in the following

:Commands [resethosts] [purity] [emptytemp] [EMPTYFLASH] [Reboot]

[*]Then click the Run Fix button at the top
[*]Let the program run unhindered, reboot the PC when it is done

Run OTL and hit the cleanup button. It will remove all the programmes we have used plus itself. MBAM can be uninstalled via control panel add/remove along with ERUNT. But they may be useful tools to keep

We will now confirm that your hidden files are set to that, as some of the tools I use will change that

[*]Click Start.
[*]Open My Computer.
[*]Select the Tools menu and click Folder Options.
[*]Select the View Tab.
[*]Under the Hidden files and folders heading select Do not show hidden files and folders.
[]Click Yes to confirm.
[
]Click OK.

SPRING CLEAN

To manually create a new Restore Point

[*]Go to Control Panel and select System and Maintenance
[*]Select System
[*]On the left select Advance System Settings and accept the warning if you get one
[*]Select System Protection Tab
[*]Select Create at the bottom
[*]Type in a name i.e. Clean
[*]Select Create

Now we can purge the infected ones

[*]Go back to the System and Maintenance page
[*]Select Performance Information and Tools
[*]On the left select Open Disk Cleanup
[*]Select Files from all users and accept the warning if you get one
[*]In the drop down box select your main drive i.e. C
[*]For a few moments the system will make some calculations
[*]Select the More Options tab
[*]In the System Restore and Shadow Backups select Clean up
[*]Select Delete on the pop up
[]Select OK
[
]Select Delete

You are now done

Download and run Puran Disc Defragmenter

Now that you are clean, to help protect your computer in the future I recommend that you get the following free programmes:
[*]SpywareBlaster to help prevent spyware from installing in the first place.

http://img233.imageshack.us/img233/7729/mbamicontw5.gif
Malwarebytes. Run weekly to keep your system clean

It is critical to have both a firewall and anti virus to protect your system and to keep them updated.

To keep your operating system up to date visit
[*]Microsoft Windows Update

To learn more about how to protect yourself while on the internet read our little guide How did I get infected in the first place ?
Keep safe :wave:

Ok will do all that tomorrow, thank you so much for your help.

Is MBAM Malwarebytes? (sorry ???)

We currently use Avast and Malwarebytes (both free versions) in this house. I’ve had no problems with infection on this computer (touch wood), but the other one seemed to pick the infection up. It’s as though Avast & Malwarebytes didn’t update automatically and then the versions became out of date.

Are you suggesting below not to use Avast?

Is MBAM Malwarebytes? (sorry )
Yes
Malwarebytes didn't update automatically
The free version does not have autoupdate, but the new 1.50 (in beta) does have a warning popup if the database is to old

No…you will be keeping Avast Free and MBAM. Essexboy needs to remove tools he put on your machine that he used to remove malware on your machine. Follow the directions in his last post. Then report back on how your machine is running. Keep your machine on for at least 24 - 48 hour for a good test. While your machine is running during this “test” period, I will give you some other tips as well, but I will wait for Essexboy to finish up his part.

Sounds to me like it is the other system that should be checked out ;D

Got to this bit

Now we can purge the infected ones
* Go back to the System and Maintenance page
* Select Performance Information and Tools
* On the left select Open Disk Cleanup</blockquote>

But can’t find performance and tools?

Sorry, found this, but can’t find this

Select Files from all users and accept the warning if you get one

When I click the Open Disc Cleanup another box comes up with a few things ticked, but I can’t see anything that says Select Files from all Users?

Oops I gave you vista not win 7

When the dialogue opens select the more options tab
Ander under system restore and shadow copies select clean up and accept the warning

There isn’t a more options tab?

Did you right click and select run as administrator ?

Right click on what?

Here is a screenshot from my windows 7

I think we’re looking at different screens! When I go to control panel etc etc, I get a different view which doesn’t allow me to right click. I’ve taken a screen shot, but how do I show it on here?

Go start > All programs > accesories > system tools > right click disc cleanup

When you click the Reply button, there is an Additional Options link, this expands the options to attach a file, that can be an image file or a text file (.log or .txt). Also see How to post an Image.

Wow, I think i’ve arrived!!

Have to say, if you’d said a few days ago i’d be removing viruses with your help, I wouldn’t have believed it!!

Thank you so much for your help.

Should I download spyware blaster on top the of the MBAM and avast i’ve already got?

Actually I am thinking of removing that from my list for all users with IE8 and above, as that area is now well covered by IE

Learning is fun isn’t it ;D