Spyware, Viruses, & Security forum

General discussion

Trojan Horse Generic 18.DUE

by jerrywh1 / August 5, 2010 2:55 AM PDT

XP HOME, AVG 8.5, AD-ware, 2 times during the past week my computer has been under attack by this. When it pops up I get a message from a program called "Antivir" stating that my computer is under attack. When it happens it won't let me run any application programs such as AVG and Register Mechanic. I can't get the Task Manager to stay up so I can stop processes from running. I must restart the computer, and boot up in safe mode, then I can use system restore to a earlier date to get going again. Then I can update and run AVG. The result is that AVG tells me I have "Trojan Horse Generic 18.DUE" It also says that it can't heal the virus. When I "goggle" it I get no results. Thanks for the help. I can't detect anything in my start up directory that would affect this. Thanks in advance for the help.

Discussion is locked
You are posting a reply to: Trojan Horse Generic 18.DUE
The posting of advertisements, profanity, or personal attacks is prohibited. Please refer to our CNET Forums policies for details. All submitted content is subject to our Terms of Use.
Track this discussion and email me when there are updates

If you're asking for technical help, please be sure to include all your system info, including operating system, model number, and any other specifics related to the problem. Also please exercise your best judgment when posting in the forums--revealing personal information such as your e-mail address, telephone number, and address is not recommended.

You are reporting the following post: Trojan Horse Generic 18.DUE
This post has been flagged and will be reviewed by our staff. Thank you for helping us maintain CNET's great community.
Sorry, there was a problem flagging this post. Please try again now or at a later time.
If you believe this post is offensive or violates the CNET Forums' Usage policies, you can report it below (this will not automatically remove the post). Once reported, our moderators will be notified and the post will be reviewed.
Collapse -
Please Try This
by Grif Thomas Forum moderator / August 5, 2010 5:57 AM PDT

If you can download the tools below on your current computer, and get them to work, then fine, but frequently the problem malware prevents the programs from running correctly. If that's the case, the download ALL of the tools below on a friend or family member's, CLEAN computer and copy them to a CD or flash drive, then transfer them to the problem machine.

First, after transferring it to the problem machine, run the following tool to help allow the removal programs below to run. (courtesy of Grinler at BleepingComputer.com)
There are 4 different versions. If one of them won't run then try to run the other one. Be patient.... as a black window should open, then close after finding all the background programs.
Vista and Win7 users need to right click and choose Run as Admin
You only need to get one of them to run, not all of them.

Rkill.exe http://download.bleepingcomputer.com/grinler/rkill.exe
Rkill.com http://download.bleepingcomputer.com/grinler/rkill.com
Rkill.scr http://download.bleepingcomputer.com/grinler/rkill.scr
Rkill.pif http://download.bleepingcomputer.com/grinler/rkill.pif
_____________________

IMMEDIATELY after running the "Rkill" tool above, run/install the Malwarebytes and SuperAntispyware installer and update files from the links below which you've also copied to a CD or flash drive, and transfered to the problem machine. Do NOT restart the computer after running Rkill.

Once downloaded and before transferring Malwarebytes and SuperAntispyware to the problem machine, rename the program installer "mbam-setup.exe" file to something else like "Gogetum.exe", then copy the installer file and the update file to a CD or flash drive.. Transfer the file to the problem machine, then install the "Gogetum.exe" file, then run the update to get the program current.. After that, run a full system scan and delete anything it finds.

Malwarebytes Installer Download Link (Clicking on the links below will immediately start the download dialogue window.)
http://www.besttechie.net/tools/mbam-setup.exe

Malwarebytes Manual Updater link
http://data.mbamupdates.com/tools/mbam-rules.exe

Next, install and run a full system scan with the SuperAntispyware program and the manual updater from the links below. As before, you may need to rename the installer file to get the program to install.:

SuperAntispyware
http://www.superantispyware.com/

SuperAntispyware Manual Updater
http://www.superantispyware.com/definitions.html
____________

In a few situations, in order for the program to run, it was also necessary to rename the main "mbam.exe" file also after installing it.. It resides in the C:\Programs Files\Malwarebytes Antimalware folder....
_____________________


Hope this helps.......

Grif

Collapse -
Trojan Horse Generic 18.3DUE
by jerrywh1 / August 5, 2010 9:32 PM PDT
In reply to: Please Try This

I'm grateful for your help. I was able to get the virus out of the "restore" function by resetting the restore point. I'm going to follow your advice to make sure this thing is gone. You have been most helpful.
Jerry

Popular Forums
icon
Computer Help 51,912 discussions
icon
Computer Newbies 10,498 discussions
icon
Laptops 20,411 discussions
icon
Security 30,882 discussions
icon
TVs & Home Theaters 21,253 discussions
icon
Windows 10 1,672 discussions
icon
Phones 16,494 discussions
icon
Windows 7 7,855 discussions
icon
Networking & Wireless 15,504 discussions

REVIEW

Meet the drop-resistant Moto Z2 Force

The Moto Z2 Force is really thin, with a fast processor and great battery life. It can survive drops without shattering.