This is a read-only archive of malwareremoval.com. No new posts or registrations. Privacy Page
Malware Removal Forums

Trojan horse removal!! AAAHHH

2 min read

This thread's last reply is from February 3, 2008, 8:30 AM UTC. Software, malware, and removal-tool advice below may be out of date — treat specific steps and download links with caution.

Hi there Folks,got a big pop-up problem, AVG pops up every couple of seconds and tells me I`ve got a virus, I`ve scanned the life out of it and it wont go away.
the file is located here: C:\WINDOWS\system32\rdriv.sys
Trojan horse Generic.GM

Please could someone have a look at the HJT File. thanx again
stevie
Good morning. I'm sorry that you've been kept waiting. I'm looking through your log and will post again shortly.
Hi stevie.

I'm afraid that you have a serious infection on the computer. It is a worm that has backdoor/Trojan functionality to steal information. This means that someone has had access to your computer and has possibly gathered personal information from it.

You are strongly advised to change all your online passwords, but do not do it using this computer - use another, clean one. If you use the computer for any financial transactions (online banking, credit card payments, PayPal or any other financial accounts), then call your banks, credit card companies etc and inform them that you may be a victim of identity theft. Ask them to put a watch on the accounts or change all of the account/card numbers.

------------------------------------------------

Download and Install SDFix

Download SDFix and save it to your Desktop.

Double click SDFix.exe and it will extract the files to %systemdrive%
(This is the drive that contains the Windows Directory, typically C:\SDFix)

--------------------------------------------------------------

Reboot to Safe Mode

Important: If you have an 'always on' connection to the internet, physically disconnect that connection until you are finished with Safe Mode and have rebooted back into normal mode. I suggest that you print these instructions, as you will not have access to them once you have disconnected from the internet.
  • Restart your computer.
  • Continually tap the F8 button as your computer is booting a menu appears.
  • Use up-arrow key to select Safe Mode and press Enter.


--------------------------------------------------------

Run SDFix
  • Open the extracted SDFix folder and double click RunThis.bat to start the script.
  • Type Y to begin the cleanup process.
  • It will remove any Trojan Services and Registry Entries that it finds, then prompt you to press any key to Reboot.
  • Press any key and it will restart the PC.
  • When the PC restarts, the Fixtool will run again and complete the removal process and then display Finished.
  • Press any key to end the script and load your desktop icons.
  • Once the desktop icons load, the SDFix report will open on screen and also save into the SDFix folder as Report.txt
    (Report.txt will also be copied to Clipboard ready for posting back on the forum).


------------------------------------------------------

Please post the following, as a reply to this thread:
  • The SDFix report
  • A new HijackThis log
Due to a lack of response this topic is now closed.

If you still require help, please open a new thread in the Malware Removal forum and wait
for a new helper.

If you have been helped and wish to donate to help with the costs of this volunteer site,
please read
Donations For Malware Removal