Folder AVG Forums » Other topics » Virus Removal, Tools for Removing » Virus Problem - Trojan Horse Hider.MPR
Page 1 of 2 12››
August 12, 2011 09:30 Virus Problem - Trojan Horse Hider.MPR #170544
Reply with Quote | Quick Reply | Top
willxgu

Avatar

Novice
Join Date: 12.8.2011
Posts: 1
Hi,

I have turned my laptop on today and it has come up with a Threat Detected box. The file is a Trojan horse Hider.MPR.

Filepath is C:\Documents and Settings\---------\Local Settings\Temp\vrximntq.sys

(The ------ is my name)

The resident shield says that the "Object is inaccessible" so cant delete it. I started a full computer scan and it started then finished immediatley after scanning 0 files. The laptop wont connect to the wireless network connection (or if it does, it drops out straight away) and thus cannot update AVG.

I am using AVG Version 10.0.1392
Virus database version: 1520/3827

Any help will be very much appreciated. I looked at the "read before posting" thread about screenshots etc but as above, cant connect it to internet to upload.

The laptop is running windows XP Professional.

Thanks,

willxgu

UPDATE: The laptop now says it is connected to the wireless internet connection, but when i try to update AVG it keeps saying it was unable to connect with the update server.

AVG has now removed 9 Win32/Zbot.G from dll files (application data files for Java and spotify)
August 12, 2011 12:25 Re: Virus Problem - Trojan Horse Hider.MPR #170553
Reply with Quote | Quick Reply | Top
Pokornyz

Avatar

Administrator
Join Date: 29.11.2010
Posts: 8235
Hello willxgu,

please provide us with GMER scan results and Msinfo output to better analyze.

Thank you
___________________AVG TeamHow-To articles | FAQ
August 12, 2011 16:17 Re: Virus Problem - Trojan Horse Hider.MPR #170565
Reply with Quote | Quick Reply | Top
fahadhasin96

Avatar

Hacker
Join Date: 22.5.2011
Posts: 445
Dear moderators and manager,

Have a look @ this:


willxgu wrote
UPDATE: The laptop now says it is connected to the wireless internet connection, but when i try to update AVG it keeps saying it was unable to connect with the update server.

AVG has now removed 9 Win32/Zbot.G from dll files (application data files for Java and spotify)


August 12, 2011 16:41 Re: Virus Problem - Trojan Horse Hider.MPR #170566
Reply with Quote | Quick Reply | Top
BIG AL 43

Avatar

Moderator
Join Date: 18.6.2009
Posts: 23813
@ fahadhasin96

The 'update statement' was actually featuring in the original user willxgu thread posting even before Pokornyz posted!


AVG Free Volunteer ModeratorAVG Free Forum member since - Nov. 27, 2004My total posts on the Old AVG Free Forum - 27,063
Alan
How-To articles | FAQ
August 13, 2011 05:30 Re: Virus Problem - Trojan Horse Hider.MPR #170586
Reply with Quote | Quick Reply | Top
fahadhasin96

Avatar

Hacker
Join Date: 22.5.2011
Posts: 445
BIG AL 43 wrote
The 'update statement' was actually featuring in the original user willxgu thread posting even before Pokornyz posted!

I am sorry....
March 13, 2012 09:24 Re: Virus Problem - Trojan Horse Hider.MPR #195258
Reply with Quote | Quick Reply | Top
yaquaholic

Avatar

Novice
Join Date: 13.3.2012
Posts: 1
I too have this problem. :(

The trojan re-appears after every reboot and has blocked internet traffic to the AVG sites and forums, and every other mainstream virus removal site. I managed to get out onto the internet by using a webproxy, but have so far failed to remove the trojan. The hosts file appears untouched, so it must be doing something in the registry.

Also the AVG Whole system scan, finishes after scanning no files at all. I have tried to alter the scan, but it always results in 0 files scanned.

Attached is a zip file of the gmer output, msinfo32 and the resident/scan csv files. Hopefully you can help me.

Thanks.
March 13, 2012 13:25 Re: Virus Problem - Trojan Horse Hider.MPR #195292
Reply with Quote | Quick Reply | Top
nemethste

Avatar

Administrator
Join Date: 1.11.2011
Posts: 1730
Hello yaquaholic,

The virus may be hiding in system volume infromation folder according to the analysis of attached logs. In order to successfully remove virus residing there, please follow this how to article.

Also please provide us also with Gmer anti-rootkit scan results so we can analyse the issue further.

Thank you.
___________________AVG TeamHow-To articles | FAQ | Free SupportWe Protect Us
March 28, 2012 22:10 Re: Virus Problem - Trojan Horse Hider.MPR #196304
Reply with Quote | Quick Reply | Top
brianfantana

Avatar

Novice
Join Date: 28.3.2012
Posts: 1
Help..

I am having the same problem

when turning on my computer is comes up with a "windows command processor" promt, i try to cancel this but its keeps coming back up. When i select continue it comes up with threat found "trojan horse hider.mpr"
i have run numerous avg scans and downloaded your recommended malware sofware. i have also tried what has been said in this thread but nothing is working.

Any suggestions?
March 29, 2012 07:31 Re: Virus Problem - Trojan Horse Hider.MPR #196321
Reply with Quote | Quick Reply | Top
nemethste

Avatar

Administrator
Join Date: 1.11.2011
Posts: 1730
Hello brianfantana,

We need more information and data to suggest proper troubleshooting steps.

Please provide us with both Gmer scan results, Msinfo output and AVG Anti-Virus scan results for further analysis.¨

Thank you

EDIT BIG AL 43.. 'provide us' link amended.


AVG Team
How-To articles | FAQ | Free Support
March 30, 2012 02:23 Trojon Hourse Hider.MPR #196396
Reply with Quote | Quick Reply | Top
user2244

Avatar

Novice
Join Date: 30.3.2012
Posts: 1
HI,

I've got the exact same problem as the initial post by willxgu

c:\Users\-----\AppData\Local\Temp\xawcwdxv.sys

see attached the msinfo file and anti-rootkit scan.

I could not start the autostart scan, even after following all the instructions.

Thanks for your help.
Page 1 of 2 12››