Folder AVG Forums » Other topics » Virus Removal, Tools for Removing » Trojan Horse Generic29.AHHS
Page 1 of 2 12››
April 10, 2013 01:13 Trojan Horse Generic29.AHHS #227545
Reply with Quote | Quick Reply | Top
shem0426

Avatar

Novice
Join Date: 10.4.2013
Posts: 3
Just caught the virus called Trojan Horse Generic29.AHHS. The AVG detects it but cannot remove (access denied.) I tried to use the information on the Internet to try to remove the threat, but it was not very relevant, because, except for a very few registry entries, I haven't found anything: no files associated with this virus.
My computer seems to work normally, just as it did before the infection. I just have this AVG Resident shield window popping up from time to time saying that this virus found in two locations.
Any thoughts about this or any experience anyone has had with this virus?
Thank you.
April 10, 2013 10:16 Re: Trojan Horse Generic29.AHHS #227558
Reply with Quote | Quick Reply | Top
BIG AL 43

Avatar

Moderator
Join Date: 19.6.2014
Posts: 0
@ shem0426

In order to analyze your issue please provide more information (AVG scan result export, Msinfo output, GMER scan result).


AVG Forums Volunteer ModeratorAVG Forum member since - Nov. 27, 2004My total posts on the Old AVG Free Forum - 27,063
Alan
How-To Articles | FAQ | Free Support
April 11, 2013 13:03 Re: Trojan Horse Generic29.AHHS #227621
Reply with Quote | Quick Reply | Top
shem0426

Avatar

Novice
Join Date: 10.4.2013
Posts: 3
I created a .csv file but can't attach it to the message. Pressing the button "Browse" is not opening Explorer to choose it. What do I do wrong?
April 12, 2013 04:21 Re: Trojan Horse Generic29.AHHS #227678
Reply with Quote | Quick Reply | Top
shem0426

Avatar

Novice
Join Date: 10.4.2013
Posts: 3
OK, I've done everything.
I'm attaching two files. I saved the GMER scan result, but I cannot find where it is saved on the computer.
April 17, 2013 03:56 Re: Trojan Horse Generic29.AHHS #227933
Reply with Quote | Quick Reply | Top
brianh71

Avatar

Novice
Join Date: 17.4.2013
Posts: 2
Same problem here. I'm attaching the AVG scan results, the gmer scan results, and my msinfo.

Sorry - I just noticed that I was supposed to zip these up. I don't see a way to delete and re-do this post. I'll be sure to follow the recommendations next time.
April 19, 2013 14:28 Re: Trojan Horse Generic29.AHHS #228076
Reply with Quote | Quick Reply | Top
Pokornyz

Avatar

Administrator
Join Date: 29.11.2010
Posts: 8245
Hello all,

Please use AVG Rescue CD and restore your MBR as described here (refer to Offline mode using AVG Rescue CD). Then, scan the system using AVG Rescue CD and remove detected threats.

Should the infection be still present after restart, please provide us with new GMER anti-rootkit scan result and new AVG full computer scan result export. Also, please provide us with a screenshot of your partition table listing as follows:
1. Run the AVG Rescue CD.
2. Switch to the linux terminal by the left ALT + F2 key combination.
3. Login as the root user.
4. Execute the fdisk -l command.
5. Take a picture of your screen and attach it to your reply.
6. Use the left ALT + F1 key combination to switch back to the AVG Rescue CD menu.

Thank you.



AVG Team
How-To articles | FAQ | Free Support
April 19, 2013 15:24 Re: Trojan Horse Generic29.AHHS #228083
Reply with Quote | Quick Reply | Top
brianh71

Avatar

Novice
Join Date: 17.4.2013
Posts: 2
I think I've managed to remove the virus. If I get another detection, I'll follow the steps above.

I used a tool called RogueKiller, which is available on CNET.

I followed instructions posted by "Cameron" in the second comment on http://www.avgthreatlabs.com/webthreats/content/trojan-horse/

Here's a quote of what Cameron posted that helped me:

alright, here's what you're gonna do. first, go to your control panel. set your view to large icons, and click on folder options. go over to the 'View' tab, and make sure that the option to 'show all hidden files, folders and drives' is checked. then, download a program called RogueKiller from here:

http: //download. cnet. com/RogueKiller/3000-8022_4-75764640. html

open the program, wait for it to prescan, and then click scan and let it do its job. after it's done, make sure everything it found is checked, and then click delete.
you can close the program after that. now, go to your temp folder (you can just click on your username, click on AppData, local, and then temp), and delete everything in it (if it has anything in it), as you are supposed to do this at least once a month anyway.
if your computer still cannot delete a .exe because it is running, then look through whichever folder it's in and maybe do some more research on it.
I hope I've helped.
April 26, 2013 08:46 Re: Trojan Horse Generic29.AHHS #228347
Reply with Quote | Quick Reply | Top
Pokornyz

Avatar

Administrator
Join Date: 29.11.2010
Posts: 8245
Hello brianh71,

We are happy to see that your issue is resolved.

Thank you for posting back.



AVG Team
How-To articles | FAQ | Free Support
May 13, 2013 08:45 Re: Trojan Horse Generic29.AHHS #229019
Reply with Quote | Quick Reply | Top
karhar

Avatar

Novice
Join Date: 13.5.2013
Posts: 1
Does Rogue Killer contain a virus?..

My win7 laptop has this virus and I'm trying to follow Cameron's advice in Brianh71 reply. When I try to download the Rogue Killer file I get a message from Windows Update (?) saying 'ARo2013_bt.exe contained a virus and was deleted'. Now what do I do?????
May 17, 2013 12:38 Re: Trojan Horse Generic29.AHHS #229231
Reply with Quote | Quick Reply | Top
Pokornyz

Avatar

Administrator
Join Date: 29.11.2010
Posts: 8245
Hello karhar,

In order to analyze your issue please provide us with more information (AVG scan result export, Msinfo output, GMER scan result).

Thank you.



AVG Team
How-To articles | FAQ | Free Support
Page 1 of 2 12››