nukchebi0
Пушкин, наше всё
+387|6584|New Haven, CT
So our XP computer has a virus, with the following message returned by AVG:

    Multiple Threat Detection

    Windows\system32\venelumi.dll    Trojan Horse Vundo.IH
    Windows\system32\rinihuye.dll    Trojan Horse Injector.GJ
    Windows\system32\hatasefa.dll    Trojan Horse Generic15.AFNU

    Each dll and virus occurred at least 5 times.

I then clicked the remove all unhealed infections which provided the following dialog box:

    Do you want to force the threat removal?

    Forced removal can cause system unstability or even crash.  (This was in red, bold font.)


What does this mean and what should I do? As a note, I am currently 2700 miles from the computer, so I can't fiddle with it. I don't want to tell my parent's to do something that would royally mess it up without me being there, which is why I would like someone more knowledgeable to tell me what is going on.
AussieReaper
( ͡° ͜ʖ ͡°)
+5,761|6413|what

Because the .dll files are located in your system32 folder AVG is urging you to be cautious about the next step you take.

Say no to the force and it will try to heal the infections, if it can't remove them try running some other scans on the files (or your whole pc for that matter) and see if they can.
https://i.imgur.com/maVpUMN.png
Kmar
Truth is my Bitch
+5,695|6861|132 and Bush

Nasty stuff. I once saw a virus attached to a system .dll file. I eventually got it clean by doing a sys restore and then running the scan. I think there was a bit of luck involved tbh.
Xbone Stormsurgezz
Catbox
forgiveness
+505|6976
If you have tried everything... and it's not fixed...
Use combofix         this is a free tool but very powerful... I have used it to fix quite a few really infested computers
http://www.bleepingcomputer.com/combofi … e-combofix
Love is the answer
Benzin
Member
+576|6258

[TUF]Catbox wrote:

If you have tried everything... and it's not fixed...
Use combofix         this is a free tool but very powerful... I have used it to fix quite a few really infested computers
http://www.bleepingcomputer.com/combofi … e-combofix
NO NO NO!!!! Why do you always recommend ComboFix? STOP DOING THAT!

Whatever you do, DO NOT RUN CF! You should not touch CF until you've done everything else you can to remove the virus. CF is the LAST tool you use, because that program can royally screw your computer up if you are unsure about what you are doing. DO NOT TOUCH IT!

OK ... that being said: Try what Aussie said. As an alternative virus scanner, take a look at Malware Bytes' Anti Malware. MBAM is a good program. Make sure your parents update the program once they install it. Once that is done, do a full scan. Follow instructions to remove the viruses from the computer. After a reboot (chances are it will reboot), then you need to have them do a quick scan. If that scan comes back clean, your computer is fine.

But DO NOT use CF until you've done everything else.

After the computer has been cleaned, have your parents install COMODO Firewall for Windows. Then make sure they are running an anti-virus program with active protection. Symantec 2009 is quite good. They can also buy a copy of MBAM if they want and that will turn on active protection on the program.
Catbox
forgiveness
+505|6976
Thats what i said ...lmao   
my quote...
"If you have tried everything... and it's not fixed..."      meaning... if you have tried everything and it's not fixed...

has your computer been screwed up by running combofix?   Do you know what you are doing with it?
I have fixed quite a few computers with Combofix...

Last edited by [TUF]Catbox (2009-11-11 01:00:28)

Love is the answer
Benzin
Member
+576|6258
My mistake. I missed that.

I've not messed up my own two computers while running ComboFix, but while reading forums for hours researching how to remove the viruses that I had, I found multiple stories of people running ComboFix and being forced to completely reformat and reinstall.

Sorry again, my mistake.
Catbox
forgiveness
+505|6976
lol... it's all good...  I have fixed a few computers that had the antivirus 2009 issue among others with combofix.... it is definitely a last resort...
Love is the answer
nukchebi0
Пушкин, наше всё
+387|6584|New Haven, CT
MBAM doesn't work. The install is corrupted, and I can't force it through a simple reinstall.
steelie34
pub hero!
+603|6641|the land of bourbon
wait!  didnt your anti-virus software stop you from getting a virus?  NO as usual....

those three files are bogus virus files.  you can safely delete them.
https://bf3s.com/sigs/36e1d9e36ae924048a933db90fb05bb247fe315e.png
Benzin
Member
+576|6258
Install corrupted? That means the viruses are probably blocking the install file from running.

Redownload the MBAM install file and rename the file to something like iexplorer.exe. Rename it however, BEFORE you save it. You'll want to make sure you have it set in FF or IE that you can save and rename your files before doing a download to a predesignated folder. Do that and come back.

Any chance of getting a Hijack This log?

Steelie - gtfo
Benzin
Member
+576|6258
If MBAM doesn't work, try IOBits. They've been stealing MBAM's database as of late, so it SHOULD work pretty much just as good. Maybe the virus will let that one through after a rename of the install exe.
steelie34
pub hero!
+603|6641|the land of bourbon
dude, this is a plain vanilla spyware infection.  those three files are just randomly generated files that run during startup and live in the system32 folder.  they are not legitimate... the only difficulty is removing them, and getting rid of the associated registry junk that keeps putting them back.  there are so many undocumented locations in the registry where files can run during boot, its sometimes tough to track them all down. 

my favorite spyware removal method is changing the ntfs permissions on the virus files to deny the system account full control.  the next time you reboot, the virus won't be able to run, and you can delete the files.  sneaky sneaky.

@nismo, i will not gtfo, since i'm certain i have seen, written, and removed more viruses than you can imagine.  these kinds of fights are the reason i stay away from these threads usually.
https://bf3s.com/sigs/36e1d9e36ae924048a933db90fb05bb247fe315e.png
King_County_Downy
shitfaced
+2,791|6857|Seattle

Malwarebytes will install in safe mode.

The only way I've been able to get rid of that virus was with a combo of Webroot and malwarebytes run in safe mode.

Besides that, there should now be a fix available from Microsoft updates.

If you have all of your updates, Start--> Run--> mrt <enter> Run a full scan. That might fix it.
Sober enough to know what I'm doing, drunk enough to really enjoy doing it
steelie34
pub hero!
+603|6641|the land of bourbon
the saddest part of my day is when i spend hours devising a way to manually remove spyware (by hand, deleting files and reg keys) only to see someone has released a package to do it for me.  fml
https://bf3s.com/sigs/36e1d9e36ae924048a933db90fb05bb247fe315e.png
King_County_Downy
shitfaced
+2,791|6857|Seattle

The worst part of my day is when my company won't let me even try to remove a virus because we can re-image the computer faster than the scan takes. I enjoy a good virus fight every once in a while.
Sober enough to know what I'm doing, drunk enough to really enjoy doing it
nukchebi0
Пушкин, наше всё
+387|6584|New Haven, CT
I'm quite glad I've been paranoid enough to tell my parents not to use the internet on it at all (nor have the connection enabled.)

With that said, the computer will not start in safe mode. It crashes as it exits the safe mode "splash" screen, invariably.

Last edited by nukchebi0 (2009-11-11 10:18:53)

steelie34
pub hero!
+603|6641|the land of bourbon
hijack-this will provide some good info... are you unable to run it?

it will list alot of the 'hidden' startup entries in the registry.
https://bf3s.com/sigs/36e1d9e36ae924048a933db90fb05bb247fe315e.png
Benzin
Member
+576|6258

steelie34 wrote:

hijack-this will provide some good info... are you unable to run it?

it will list alot of the 'hidden' startup entries in the registry.
I'm curious if he'll be able to at all. I honestly don't think he will, but it would be nice to be surprised.
King_County_Downy
shitfaced
+2,791|6857|Seattle

nukchebi0 wrote:

I'm quite glad I've been paranoid enough to tell my parents not to use the internet on it at all (nor have the connection enabled.)

With that said, the computer will not start in safe mode. It crashes as it exits the safe mode "splash" screen, invariably.
Start--> Run--> SFC /scannow <enter>
Sober enough to know what I'm doing, drunk enough to really enjoy doing it
steelie34
pub hero!
+603|6641|the land of bourbon
i always look at it as a trade-off of time.  if it would take more time to wrestle with this virus than it would to just do a windows repair, i would go for the repair.  you can never be 100% sure of complete removal especially with an annoying one like this.
https://bf3s.com/sigs/36e1d9e36ae924048a933db90fb05bb247fe315e.png
Catbox
forgiveness
+505|6976
If you have given up and are going to reformat...
try the combofix program like i said in a post above
http://www.bleepingcomputer.com/combofi … e-combofix

When you d/l combofix.... choose save as and rename it to   combo-fix.exe and save...  (this should help the corrupt .exe problem)
then when it d/l    click on the combo-fix.exe and let it run and it should clear up your issue....after combofix
you can run malwarebytes and get rid of any other lingering spyware... 
http://www.malwarebytes.org/

combofix is very powerful and a last resort ....
but if you are going to
reformat.... it's free and worth a shot

Last edited by [TUF]Catbox (2009-11-11 23:00:11)

Love is the answer
Benzin
Member
+576|6258

[TUF]Catbox wrote:

If you have given up and are going to reformat...
try the combofix program like i said in a post above
http://www.bleepingcomputer.com/combofi … e-combofix

When you d/l combofix.... choose save as and rename it to   combo-fix.exe and save...  (this should help the corrupt .exe problem)
then when it d/l    click on the combo-fix.exe and let it run and it should clear up your issue....after combofix
you can run malwarebytes and get rid of any other lingering spyware... 
http://www.malwarebytes.org/

combofix is very powerful and a last resort ....
but if you are going to
reformat.... it's free and worth a shot
yea, if reformat is your last option, always good to run CF and see if that fixes anything. Just make sure you do not touch the computer at all when it's running. Turn CF on and walk away for a while.

You should be able to back up any data from the computer first, though. Doubtful the trojan will latch onto your photos and mp3s and whatnot. Though I would be careful nonetheless.
nukchebi0
Пушкин, наше всё
+387|6584|New Haven, CT
So I got MBAM to work, and had it remove things along with AVG. Scan of those two, along with Adaware, come back clean. Is the computer usable, or should I run something else to ensure it is safe?
steelie34
pub hero!
+603|6641|the land of bourbon

nukchebi0 wrote:

So I got MBAM to work, and had it remove things along with AVG. Scan of those two, along with Adaware, come back clean. Is the computer usable, or should I run something else to ensure it is safe?
sounds like u'r ok.  i'd put a condom around my modem to make sure this stuff doesnt happen again.
https://bf3s.com/sigs/36e1d9e36ae924048a933db90fb05bb247fe315e.png

Board footer

Privacy Policy - © 2025 Jeff Minard